Home Password Strength Clean URL One-time Encrypt

FAQ: uploads, accounts, and leaked-list checks

Does the password generator upload data? Do you need an account? Is the strength checker a live HIBP lookup? Four answers, written the way the product works.

Four facts, written the way the product actually behaves. No login wall. No silent upload.

No. The password generator, strength checker, UTM cleaner, text redaction, and file encryption all run in the browser. A one-time secret only stores ciphertext; the decryption key stays in the URL fragment after #.

No. Every tool opens and works without registration or a password vault.

No. Creating and reading both work without an account. The first successful read burns the note; opening it again shows that it has already been destroyed.

The password under test is not sent to an external API. We compute entropy locally and compare against a built-in public top leaked-password list. That catches common weak passwords. It is not a live HIBP lookup.