Privacy Policy

Last Updated: July 27, 2026 · Effective Date: July 27, 2026

The short version: Passwords you generate are created in your browser and never sent to us. We do not use Google Analytics, advertising pixels, New Relic, Kit, or other third-party trackers. Our host keeps standard server logs. If you subscribe to the newsletter, your email is stored in our AWS account so we can email you. Details below.

1. Your passwords: what we never see

Every password and passphrase is generated locally in your browser using the Web Crypto API (crypto.getRandomValues), the same cryptographic randomness used by banks and secure systems. Your generated passwords are never transmitted to us, never stored on our servers, and never logged. We could not retrieve one if we tried. You can verify this in our open-source code or by watching your browser's network activity while generating.

2. Analytics

We do not use Google Analytics, Google Tag Manager, Facebook Pixel, New Relic, or similar third-party analytics or RUM products on this site.

3. Server logs

The site is hosted on Amazon Web Services and delivered through Amazon CloudFront. As part of normal operation, these record standard technical data such as IP addresses, timestamps, requested URLs, and browser type, used for security and reliability.

4. Cookies

We do not set advertising or cross-site tracking cookies. Theme preference may be stored in your browser's local storage so the site remembers light/dark mode. The generator works fully without cookies.

5. Newsletter

If you submit your email to our newsletter form, it is sent to our API Gateway endpoint and stored in Amazon DynamoDB in our AWS account, with notification/confirmation email via Amazon SES. We do not use Kit, ConvertKit, or other third-party email-marketing embeds. You can unsubscribe via the link in newsletter emails.

6. Password breach checks (optional tool)

Our password checker may send a truncated password hash prefix to Have I Been Pwned's Pwned Passwords API (api.pwnedpasswords.com) using k-anonymity. The full password never leaves your browser for that check.

7. Purchases

If you buy a digital product from us, checkout is processed by Stripe, with Link acting as merchant of record. Stripe/Link collect the payment details and, at our configuration, your name and email; we receive your name, email, and order details in our Stripe dashboard (never your full card number). We use them to deliver the product, honor refunds, and send corrections or updates to what you bought. Stripe's own privacy policy governs the payment itself. Outbound links on this site (for example, buy buttons and partner links) may route through short redirect paths on our own domain before leaving the site; those clicks appear in our server logs like any other request.

8. Affiliate links

We keep the site free through affiliate partnerships. Some links to password managers and security products (such as NordPass, Proton Pass, and RoboForm) are affiliate links. If you click one and buy, we may earn a commission at no extra cost to you. Those partners run their own sites with their own tracking and policies, which we don't control.

9. Third parties we rely on

Amazon Web Services and CloudFront (hosting, delivery, newsletter storage/email); Have I Been Pwned (optional breach range API when you use the password checker); YouTube nocookie embeds only after you click a video facade on certain posts; and affiliate partners linked from our pages. We do not use Google Analytics, Kit/ConvertKit, New Relic, Facebook Pixel, or third-party font CDNs.

10. What we don't do

We don't sell your personal information. We don't have user accounts, so we don't collect names or account passwords. We don't run advertising or social-media tracking pixels. If you email us or subscribe to the newsletter, we receive only the address and message you choose to send.

11. International visitors

Our servers process data in the United States. If you visit from the EU, UK, or elsewhere, your information may be transferred to and processed in the US. Amazon, as our service provider, relies on standard contractual safeguards for these international transfers.

12. Your rights

Depending on where you live, you may have rights over your data.

EU/UK residents (GDPR): access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to complain to your data protection authority.

California residents (CCPA/CPRA): the right to know, delete, and opt out of sale (we don't sell), without discrimination.

To exercise any of these, email admin@safepasswordgenerator.net. For newsletter deletion, include the subscribed address.

13. Children

Our tools are not directed at children, and we don't knowingly collect personal information from anyone under 16.

14. Data retention

Server logs are retained for 90 days and then deleted automatically. Newsletter emails remain until you unsubscribe or request deletion. We do not retain analytics profiles because we do not run third-party analytics.

15. Changes

We may update this policy. Material changes will be posted here with a new "Last Updated" date.

16. Contact

Questions: admin@safepasswordgenerator.net