Privacy Policy
Your password never leaves your device. The strength score and crack-time estimates are computed entirely in your browser and are never transmitted to, logged by, or stored on our servers. The only optional network request is an anonymized breach check, described below. This page explains exactly what data, if any, leaves your browser.
Everything runs in your browser
The checker is a static site. When you type a password, all analysis — the zxcvbn strength model and both crack-time estimates — happens locally in your browser using JavaScript on your own machine. We have no server-side component that receives, processes, or saves the passwords you test. Closing the tab discards everything.
The breach check (Have I Been Pwned)
To tell you whether a password has appeared in a known breach, the tool can query the Have I Been Pwned range API using k-anonymity. Your password is hashed with SHA-1 in your browser, and only the first five characters of that hash (a partial prefix) are sent to the API. Have I Been Pwned returns a list of matching hash suffixes, and your browser compares them locally. Your actual password and its full hash are never transmitted, so the service never learns what you searched for.
No analytics, no ads, no tracking
This site runs no analytics, sets no advertising cookies, and embeds no third-party trackers. There is no cookie banner because there are no tracking cookies to consent to. We do not profile you, and there is no advertising on the site.
Contact
Questions about this policy? Reach MICKAEL GOMES CONSULTING at ismypasswordquantumproof.contact@proton.me.