Skip to content
Passwordify
Privacy

Privacy is a design constraint, not an afterthought.

A password security tool that mishandles passwords isn't a tool worth using. Here is exactly what we see, what we store, and what never leaves your device — no legalese, no ambiguity.

Our privacy stance

  • The free browser tools run 100% client-side. Your password is never transmitted, logged, or stored.
  • Breach checks use k-anonymity — only a 5-character, padded SHA-1 hash prefix ever reaches our servers.
  • The API processes passwords in memory only. Never logged. Never persisted. Never seen by a human.
In your browser

The browser tools

The strength analyzer, breach checker, and generator at /tools require no account and transmit no password. There is nothing to opt out of, because there is nothing being collected: no form submission carries your input to a server, and no analytics script observes what you type into a password field.

How k-anonymity protects a breach check

Checking a password against 900M+ breached credentials without ever sending the password itself relies on one property of cryptographic hashes: you can match a fragment of one without reconstructing the rest.

  1. 1 Your browser hashes the password locally with SHA-1. The plaintext never leaves memory, let alone the device.
  2. 2 Only the first 5 hex characters of that 40-character hash are sent to the API — never the password, never the full hash.
  3. 3 The API returns every breach record whose hash shares that 5-character prefix, typically a few hundred candidates.
  4. 4 Your browser compares the full local hash against that list and discards everything else. The match happens on-device.

The result: we never receive enough of the hash to identify — let alone reverse — the password you checked.

For developers

The API

Integrating strength, breach, or validation checks into your own signup flow means sending us a password over the wire, so we hold ourselves to a stricter standard than "we promise not to look."

Every request travels over TLS. On arrival, the password exists only in process memory for the duration of that single request — it is never written to disk, never included in logs or error traces, and never persisted in a database, cache, or backup, on any plan, including self-hosted Enterprise deployments.

The only thing we retain per request is metadata needed to run the service: a timestamp and a request count tied to your API key, used for billing and rate-limiting. That metadata is never linked back to the password or username you sent — only to the key that made the call.

Data

What we collect

We keep this list short on purpose. If it isn't needed to run the product or the business, we don't collect it.

For API accounts

Your account email, for authentication and billing, and per-key usage counts, for rate-limiting and invoicing. That's the entire list — we don't profile usage patterns or resell account data.

For passwordify.xyz

Privacy-respecting, cookieless analytics for aggregate traffic only — page views and referrers, not individuals. No password content, form input, or keystroke is ever collected on the marketing site or the tools.

Cookies & storage

Cookies

We set essential cookies only — the kind needed to keep you signed in to the developer dashboard. There is no advertising or cross-site tracking cookie anywhere on passwordify.xyz.

Your light/dark theme preference is saved to localStorage on your device. It never reaches our servers and never leaves your browser.

Requests

Data requests & contact

Under GDPR and CCPA, you have the right to access, correct, export, or delete the personal data we hold about you. Since that data is limited to your account email and usage counts, most requests take minutes, not weeks — email hello@passwordify.xyz and we'll act on it, typically within 30 days at the outside.

Changelog

Changes to this policy

If this policy changes in a way that affects what we collect or how we use it, we'll update the date below and, for material changes, notify account holders by email before the change takes effect.

Last updated: September 2026