An operator opens Incognito on a café PC or a colleague’s laptop, mints a database password, exports a TXT, and closes the window — assuming the trail is gone. The next person who sits down can still open that plaintext in Downloads. An earlier piece covered who else can read the clipboard after you copy a password. Another covered who can still see a password — and the key after # — in a screenshot or screen share. This one is a more common mix-up: closing an Incognito window does not mean the secret left this computer.
This is not a walkthrough of the password generator, and it is not “how to open Incognito.” The question is one sentence: after every private window is closed, where a password, a key, or an encrypted file can still sit on this machine. MyPassGen’s tools open without an account. Generate, export, encrypt, and decrypt finish in the current tab. The server does not keep a plaintext copy. What Incognito can block is the browser’s own history store. It cannot block the operating system’s Downloads folder.
Split the job first
If you have your own machine, and a password manager can autofill, do not mint a live password on someone else’s computer. When you must use a shared PC, run every step below with a test string that will never unlock a real account. After you close the window, delete the download, delete the bookmark, and overwrite the clipboard. Do not rehearse with a master password.
What Incognito actually clears
Chrome’s help is specific. An Incognito session ends when you close all Incognito windows. After that, Chrome does not keep site data or a record of the sites you visited. During the session, cookies and site data sit in memory so pages can work; they drop only when the last window is gone. The shortcut is Ctrl+Shift+N on Windows and Linux, ⌘+Shift+N on a Mac. A number next to the Incognito icon in the address bar means another Incognito window is still open. Closing one tab does not end the session.
The same page lists what Incognito does not do. It will not sign you into a Google Account on its own. If you then sign into Gmail or any other site inside Incognito, that site can still remember the visit. The sites you open, a school or work network, and your internet provider can still observe the session. Incognito limits “history on this device.” It does not hide you from the rest of the path.
Safari’s wording is almost parallel. Apple’s Safari User Guide says Private Browsing does not save the pages you visit or AutoFill information, and it does not store those open pages in iCloud, so they do not show up in the tab list on other Apple devices. Handoff will not pass a private window to another device. Cookie and website-data changes are not kept. Recent searches from that window do not appear in the Smart Search field. All of that is the browser’s own record layer.
Mozilla’s Private Browsing help lists what it does not save: visited pages stay out of History and the address-bar dropdown, form and search-bar entries are not stored, the download list is cleared when private browsing ends, and cookies and cache drop when the last private window closes. A separate myths page is blunt: private browsing does not hide you from your ISP, does not mask your IP, and does not stop a site from recognizing you. Three vendors are describing the same cut: closing the window clears the browser profile, not the disk, and not the far end of the network.
Microsoft Edge InPrivate follows the same split: this visit is not written into history; a file you saved to the machine stays. The rest of this article does not repeat each brand’s brochure. It only checks the three places you can still open by hand: the Downloads folder, the bookmarks bar, and the system clipboard.
Downloaded files stay on disk
Chrome’s help says it in one line: when you leave Incognito, Chrome retains bookmarks you save and files you download. Downloaded files stay on the device until you delete them. Items you add to the reading list are visible in a regular window too. The browser’s download shelf may no longer list “what this session fetched.” The file itself sits in Downloads, indistinguishable from a file saved in a normal window.
Safari is more direct: downloaded items are not included in the downloads list, but the items remain on your computer. The first cleanup tip Apple gives you when you stop browsing privately is to delete anything you downloaded in a private window. Firefox draws the same line: entries disappear from the download library when the private session ends; files you wrote to disk are kept. Newer Firefox builds also warn, at download time, that the file stays on the device and that anyone who uses this computer can see it after every private window is closed.
On MyPassGen, three paths write a file. The password page can export a TXT named mypassgen-passwords- plus a timestamp; the file lands on your device and is not posted back. The file encryption box runs AES-256-GCM in the browser as a stream, one file up to 5 GB, and writes .lock or .enc. Decrypt downloads the plaintext again under the original name. Clean URL can export cleaned links as a TXT. All three open without an account. Incognito can hide the row in chrome://downloads. It cannot hide the file in Finder or File Explorer.
Decrypt is the easy miss. You open a .lock in Incognito, unlock it, and the browser writes plaintext into the default download folder. After you close the window, ciphertext and plaintext can sit next to each other. Network can show that the encrypt or decrypt request body did not POST the whole file as business data. It cannot show that the disk is clean. How to check “did it upload” is in How to verify that browser encryption did not upload plaintext. How to check “is the file still here” is: open Downloads.
Do not export a live password into someone else’s Downloads folder
On a shared PC, a demo machine, or a conference-room laptop, the default download path is usually visible to the next login, and a cloud-sync client may already be watching that folder. If you must mint a secret on someone else’s machine, look at the screen, read it aloud, or send a one-time text link. Do not click Export TXT, and do not decrypt a live file in Incognito.
A bookmark keeps the full URL
All three official docs agree: a bookmark you create in Incognito or a private window is saved. Chrome also counts the reading list. The bookmark is written into the regular profile. After you close the window it is still on the bookmarks bar and in the bookmark manager. That is not a bug. Bookmarks are treated as something you asked to keep.
A one-time link looks like …/s.html?id={id}#{key}. The key sits after #. By spec it does not ride the HTTP request line, so access logs do not see that slice. An earlier piece covered why the decryption key belongs after # in the URL. A bookmark stores the whole URI, fragment included. Bookmarking that link in Incognito writes the credential into this browser’s long-term store. The next person who opens the bookmarks bar does not need history. They can open the read page. The read page does not require a login.
Address-bar autocomplete is a nearby shortcut. The Incognito session itself usually does not write this visit into history, so after every window is closed the dropdown should not show the one-time link you just opened. Once you add a bookmark, typing the host can still surface the full address, key after # included. That does not contradict “history was cleared.” The match now comes from the bookmark store.
After MyPassGen creates a one-time link, the result panel prints the full URL and Copy uses navigator.clipboard.writeText. Create and read both open without an account. Plaintext is capped at 32 KB. The server parks ciphertext only. What you should check is not “can the server see the key.” It is whether this computer’s bookmarks bar holds a full s.html?id=…#…. If you can read the URL aloud, or have the other person open the read page themselves, do not save the full link in someone else’s bookmarks.
The clipboard does not close with the window
Closing Incognito drops site data inside the browser process. It does not drop the operating system’s clipboard. Copy in a private window writes the string into the shared system buffer. After the window is gone, Notepad will still paste it on Ctrl+V / ⌘+V until a new copy overwrites it. That path does not care whether Incognito was on. The cleanup steps are in Who else can read the clipboard after you copy a password.
Windows clipboard history needs its own line. Win+V holds up to 25 items. Unpinned entries clear on restart; pinned ones stay. Recent Chrome builds on Windows 10 and 11 try not to write an Incognito copy into clipboard history or Cloud Clipboard. That only blocks “one more row in the history list.” It does not clear the current clipboard cell. Paste right after you close the window and the test password is often still there. Android and other platforms do not share that exclusion format. Do not assume a private-window copy stayed off sync.
Apple’s Universal Clipboard rides Handoff: same Apple Account, devices nearby, Bluetooth and Wi-Fi on, and a copy on one machine can paste on another. Closing the Incognito window does not pull back a string that already reached the other device. Password managers treat this as a short exposure window; some clear a copied secret after about 90 seconds. A generator page in the browser usually will not start that timer for you. MyPassGen does not auto-clear after Copy. Overwrite means you copy a junk character, or you clear the system panel yourself.
Extensions stay off — unless you turned them on
Chrome does not run extensions in Incognito by default. Chrome Web Store help puts the switch on the extension’s Details page: Allow in Incognito. You also cannot install a new extension from the store while you are in Incognito or signed in as a guest. An enterprise admin cannot push that switch on for users. The way to stop staff from bypassing a managed extension is to disable Incognito itself.
The default off-state is there so an ad-tracking add-on does not see this visit. An extension you turned on yourself is outside that protection. If Details says it can “read and change all your data on websites you visit,” and Allow in Incognito is on, a visible password on the generator page and a full one-time URL in the result panel look the same to that extension as they would in a regular window. Incognito is not “extensions cannot read the field.” It is “extensions you never enabled for Incognito do not load this time.”
The check is short. In a regular window open chrome://extensions, open Details on each add-on, and see whether Allow in Incognito is on. If you only needed one extension for a demo, turn the switch off when you are done. Do not leave it on. A password-manager extension that must autofill in Incognito has to use that switch — that is an explicit trade: one fewer copy, in exchange for the extension seeing the current page.
Side by side: what is still there
Take the same test password you just minted in Incognito, or a one-time link that only holds a test sentence. After every Incognito window is closed, the leftovers split along the lines below. The difference is not the algorithm name. It is which layer the browser promised to clear, and which layer the operating system still holds.
| Path | After every Incognito window is closed | How you see it on the spot |
|---|---|---|
| History / cookies / forms | Should be cleared, per official help | History page, address-bar dropdown, saved cookies |
Downloaded TXT / .lock / decrypted plaintext |
The file stays on disk | The local Downloads folder; the download list may be empty |
| Bookmarks / reading list | Kept, including the full URL | Bookmarks bar or manager; a one-time link still carries the key after # |
| System clipboard (current cell) | Not cleared with the window | Paste once in Notepad; copy one character to overwrite |
| Extensions allowed in Incognito | Can still read the current page | The switch on Details at chrome://extensions |
A generator that draws with Web Crypto, and a Network panel with no password in the request body, only close the “upload” path. The last four rows in that table stay open. On your own machine you never have to leave an export or a full one-time URL on someone else’s disk. On a shared PC, closing the window is not cleanup. Deleting the file, deleting the bookmark, and overwriting the clipboard is.
Check it on the spot
The steps below do not depend on a vendor slogan. Use a password that will never unlock a real account, and a one-time link that only holds a test sentence. Do not rehearse with a live master password or a secret that has not been burned. First confirm you closed every Incognito window: a number next to Chrome’s Incognito icon means one is still open.
- Open Incognito with Ctrl+Shift+N or ⌘+Shift+N, open the generator, and mint a default 16-character test password. Do not sign in with it. Open DevTools Network, enable Preserve log, and confirm that after Generate the request bodies do not contain that string. How to check uploads is in How to verify that browser encryption did not upload plaintext.
- Click Export TXT. In the local Downloads folder, find a file that starts with
mypassgen-passwords-and open it. Confirm the test password is inside. Do not send this file to anyone. - Create a one-time link that only holds a test sentence, and bookmark the full URL. Close every Incognito window. In a regular window, open the bookmarks bar or the bookmark manager and confirm the full
s.html?id=…#…is still there. Open History and confirm this visit is not listed. - Go back to Downloads: the TXT should still be there. Open the browser’s own downloads page. The list may already omit that row — that is exactly “the list cleared, the file did not.”
- If you clicked Copy, open Notepad and paste once. See whether the current clipboard is the test password. Copy a single character
x, paste again, and confirm overwrite worked. On Windows with clipboard history on, press Win+V. Recent Chrome may have skipped writing the Incognito copy into history. The current cell still needs an overwrite. - In a regular window open
chrome://extensions(or the matching page in another browser), open Details, and note which add-ons have Allow in Incognito on. Turn off the ones you do not need.
MyPassGen’s password generator is built on that boundary. Random mode is 6–128 characters, default 16, with a weaker warning below 8. Results are listed as visible text. Copy uses writeText. Export writes only to this device. Every tool opens without an account and without a password vault. What you should check is Downloads and the bookmarks bar — not the Incognito icon in the corner.
How to clean up after you close
For the one Incognito session you had to finish today, close in this order: shut every Incognito window, then open Downloads and delete the test TXT, any .lock, and any decrypted plaintext; empty the Recycle Bin or Trash; open the bookmark manager and delete the test one-time link that still carries #; overwrite the clipboard. If a cloud-sync client watches Downloads, confirm the copy is gone on the other signed-in device too.
Treat a shared PC, a demo machine, and a conference-room laptop as “the next person who sits down will open Downloads and the bookmarks bar.” Do not export a live password there. Do not decrypt a live file. Do not bookmark a one-time link. When a remote colleague needs a short secret, send the URL as text. The read page does not require a login. Do not expect closing Incognito to take the file back from this shared machine, or from the person on the other end.
Once you have opened Downloads after closing the window, and glanced at the bookmarks bar, you can already answer the article’s question. Who can still see the password after Incognito closes depends on where the file landed, whether a bookmark kept the full URL, and whether the clipboard was overwritten. Clearing history only means the next person who opens History will not see this address. It does not take back what was already written to disk and to the bookmark store.
FAQ
Does Incognito already guarantee the password will not linger?
No. It guarantees this visit is not written into browsing history and cookies. A downloaded file, a new bookmark, the current clipboard, and a site you signed into inside Incognito sit outside that guarantee. Official help puts “retains bookmarks and downloads” on the same page as “does not keep history.”
If I only closed the current tab, has the Incognito session ended?
No. Chrome requires you to close every Incognito window. A number next to the icon means another window is still open. Safari also tells you to close any other private windows that are still open, so someone else cannot keep using those pages. One tab is not the session.
Do I need an account to generate a password or export a TXT? Does Incognito upload the file?
No account. Generate and export should stay in the current tab. Export is the browser writing a Blob into the local Downloads folder. It is not a POST to a server. Open Network: after Export, the request body should not contain that password. The file staying on disk is the operating system’s download behavior, not a site sending the file back.
Is Guest mode cleaner than Incognito?
Chrome’s guest profile is more isolated. It does not bring your bookmarks or extensions along. Downloaded files still land in this computer’s Downloads folder. A different browser identity is not a different disk. Cleanup is still delete the file and overwrite the clipboard.