Skip to content
pseudononymous
ES

What we know about you

Most privacy policies are long because they have a lot to justify. This one is short for the opposite reason.

Last updated:

The short version

We collect no personal data. There are no accounts, no signup forms, no cookies, and no server that receives your files, your passwords or your messages. Every tool runs inside your browser. We do count how many visits each page gets, using a tool of our own that sets no cookies and cannot identify you — explained in full below.

We do count visits, and here is exactly how

We want to know which tools are actually useful, because a tool nobody opens is better fixed or removed than left sitting there. For that we run Umami on a server of our own — not Google Analytics, and not any service that resells data.

  • Recorded: which page you viewed, the link you arrived from, your screen size, your language and your country.
  • Not recorded: any cookie, or any identifier that follows you from one visit to the next. We cannot tell whether you are the same person who came yesterday.
  • Nothing that happens inside a tool is recorded: not your filename, not your password, not the URL you pasted, not the message you encrypted. None of that ever leaves your browser.
  • If your browser sends the Do Not Track signal, nothing is counted at all.

That is why there is no cookie banner: there is nothing to consent to. And one technical detail matters more than it sounds: the program that counts visits is served from this domain, not from the analytics server. So that server can receive the fact that a page was viewed, but it cannot execute a single line of code on this site even if it wanted to.

The only thing stored on your device

We keep two preferences in your browser's local storage — not in cookies, and not on our servers:

  • Which theme you chose, light or dark.
  • Nothing else. No identifiers, no history, no tool contents.

You can clear it any time by clearing this site's data in your browser. You will lose nothing, because there is nothing to lose.

The other request that leaves this site

The password auditor can check whether your password appears in known breaches, and that requires asking somebody. It happens only when you press the button, never automatically, and it works like this: your browser computes the SHA-1 fingerprint of the password and sends only the first five characters of that fingerprint to the public Have I Been Pwned API. Hundreds of fingerprints starting the same way come back, and the final comparison happens on your device.

Have I Been Pwned receives neither your password, nor its full fingerprint, nor any way to tell which of the hundreds of results you were asking about. Together with the visit counter, those are the only two external domains this site is permitted to connect to, and that permission is written into the Content-Security-Policy you can inspect for yourself. Neither is permitted to execute code here.

What the network does see

This is where most sites go quiet, so we will be direct: to serve you this page, your request passes through Cloudflare, which acts as our content delivery network. Like every web server in the world, Cloudflare sees the IP address you connect from and which page you asked for, because without that it could not send you anything.

  • We have not enabled Cloudflare analytics. Ours is the one described above, and it builds no profile of anybody.
  • We add no cookies, identifiers or tracking tags to any response.
  • The Referrer-Policy header is set to no-referrer, so if you leave here for another site, that site will not learn you came from a privacy tool.
  • What Cloudflare sees is ordinary web traffic. What it will never see is the contents of your files, because they never leave your browser.

Children

This site is built for anyone to use, children included. Since we collect no data from anybody, we collect no data from minors either. There is no registration to fill in and no parental consent to manage.

Your rights

The GDPR gives you the right to access, correct and delete your data. We can satisfy all three instantly: we hold none. If you would rather verify that yourself, the security page explains how to check all of this in two minutes with tools your browser already has.

If this policy changes, the date at the top of this page changes with it. And since everything we claim here is checkable from your own browser, you do not have to take our word for any of it: you can verify it whenever you like.