Privacy Policy

2026-08-11

Effective date: August 11, 2026

This Privacy Policy explains what data PassGenerate ("we", "the site") processes when you use passgenerate.com, and what choices you have.

The short version

  • Generated passwords are never sent to us. Password generation happens entirely in your browser using the Web Crypto API. We have no server-side password generation, no database, and no way to see the passwords you create.
  • We don't require an account. There is no sign-up, no login, and no user profile.
  • We store almost nothing. The only thing our own code saves is your cookie-consent choice itself (so we don't ask again every visit). Your language isn't stored anywhere β€” switching languages just navigates to a different URL.
  • We show ads (Google AdSense) to keep the tool free. This is the only real third-party data processing on this site β€” details below.

What we do not collect

We do not collect, store, or transmit:

  • Passwords or passphrases you generate
  • The character-set or length settings you choose
  • Any account credentials (we have no accounts)

Password generation runs client-side via crypto.getRandomValues() (a cryptographically secure random number generator built into your browser). Nothing about the password itself is transmitted to any server, including ours.

Local storage and cookies

The "πŸ”’ Privacy Settings" panel available on every page lets you manage three categories, for transparency and to prepare for possible future features. Here's exactly what each one does today:

CategoryWhat it actually does today
NecessaryStores your cookie-consent choice itself, in your browser's local storage, so we don't ask again every visit. That's the only thing this category stores.
FunctionalNot currently used to collect or store anything. Toggling it on does not enable any feature yet.
AnalyticsNot currently used. We don't run any analytics, tracking, or A/B testing service on this site.

The one exception is advertising: if you turn on Functional or Analytics, it also allows Google AdSense to serve personalized (rather than non-personalized) ads β€” see the next section. You can accept all, reject all, or customize these categories at any time from the same panel.

Advertising (Google AdSense)

PassGenerate displays ads served by Google AdSense to support running this tool for free. When ads are shown:

  • If you have not consented to functional/analytics cookies, we request non-personalized ads from Google (requestNonPersonalizedAds), which use less data and rely on contextual rather than behavioral targeting.
  • If you consent to functional/analytics cookies, ads may be personalized based on Google's own data practices.
  • Google may set its own cookies and process data according to its policies, not ours. See How Google uses information from sites or apps that use our services and Google's Privacy Policy. You can control ad personalization directly at Google Ads Settings.

Other third parties

  • Hosting/CDN (Cloudflare): Like any website, requests to passgenerate.com pass through our hosting provider, which processes standard technical data (such as IP address) to deliver the page and provide security protections (e.g., DDoS mitigation). This is inherent to operating any website over HTTPS and is not used by us for tracking.
  • We do not sell personal data, and we do not share data with third parties beyond what's described above.

Your choices and rights

Because we store so little, exercising control is straightforward:

  • Change or withdraw cookie consent anytime via the "πŸ”’ Privacy Settings" panel (accept all / reject all / customize).
  • Clear the stored consent choice through your browser's own site-data or cookie settings (there's only one entry to clear).
  • Opt out of personalized ads via Google Ads Settings or aboutads.info.
  • If you are covered by a statutory data-protection framework (such as the EU GDPR, UK GDPR, or another applicable data protection law), you can contact us using the details below with any data-subject request; given we hold minimal personal data server-side, most requests can typically be resolved by clearing your local browser data.

Children's privacy

PassGenerate is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to a third-party service used on this site (such as Google AdSense), please contact the relevant third party directly using the links above, and let us know so we can review the situation.

Security

The site is served over HTTPS, and standard security headers (including Content-Security-Policy-adjacent protections, X-Frame-Options, X-Content-Type-Options, and a restrictive Permissions-Policy) are applied to reduce common web risks. Since password generation and storage happen entirely client-side, there is no central database of generated credentials to secure or that could be breached.

Changes to this policy

We may update this Privacy Policy as the site or the services it uses change (for example, if advertising or analytics providers change). We'll update the effective date above when we do. Continued use of the site after changes means you accept the revised policy.

Contact

Questions about this policy can be sent via the "Contact Us" link in the site footer.