Home Password Strength Clean URL One-time Encrypt

Plaintext, keys, and files stay in your browser by default

This page describes what MyPassGen actually processes. Local tools compute in the browser. One-time links store ciphertext only. There are no accounts, so there is no registration data to collect.

Computation stays in the browser. We do not collect sign-up data.

MyPassGen runs at mypassgen.com as a browser-first encryption and privacy toolkit. Password generation, strength checks, URL cleaning, text redaction, and file encryption happen in the tab you already opened. You can start without signing in.

There is no user account and no password vault. We do not store an email, password, or session for login. Usage rules live in the terms of service. Algorithms and where they run live in the security notes.

It stays on this device, except one-time ciphertext

You can verify this split on the spot: plaintext, keys, and files are not sent as business data by default. The only feature that hands content to the server is a one-time link’s short-lived ciphertext.

What each of the five tools processes, and what it does not upload

Each row can be checked on the matching page. There is no hidden “store a copy on the server” step.

Random strings and passphrases are generated in the browser. After you close the page, those passwords are not sitting on our servers. Copy or export a TXT if you need a copy. Try the password generator.

Scoring and the public weak-password list run on this device. This is not a live web-wide breach lookup, and the candidate is not sent to an external API. Open the password strength checker.

Stripping trackers and masking phone numbers, IDs, and emails happens in the browser. The original text is not uploaded and is not written to analytics. Open Clean URL.

The browser encrypts with AES-256-GCM first, then hands ciphertext to the server for a short stay. The key lives only in the link’s # fragment and is not sent as a query parameter. Create a one-time link.

Streaming encryption and decryption run in the browser. One file can be up to 5 GB and leaves as .lock or .enc. The file and passphrase stay on this machine by default. Open file encryption.

The server only sees ciphertext. The key lives after #.

When you create a one-time link, the browser finishes local encryption first, then hands ciphertext to the server for a short stay. The decryption key lives only in the link’s # fragment and is not sent with the HTTP request.

The read page is public to the recipient. They do not need an account. After a successful read, the ciphertext is destroyed. Opening the link again shows that it has been burned or expired, not the original text. The shape is s.html?id=…#key: the query holds only the id; the key sits after the hash.

On the read page, check the Network panel: the request line should not include the key after #. Fuller constraints are in the security notes.

We count page views, not plaintext, keys, or files

To see which pages are opened, the site records anonymous page visits. Analytics do not write generated passwords, tested passphrases, keys, plaintext, source text, or file contents.

Switching language stores a preference in local localStorage so we can remember the directory you chose. It is not account data and is not used to identify you.

Analytics may write a statistics cookie or a local identifier in the browser. Those exist only for visit counts. They are not a user profile and are not used for cross-site advertising.

No accounts means no email, password, or session

This first release deliberately skips registration. The items below are not collected or hosted as product features.

Three facts about how data is handled

Written from the site’s real behavior. No login wall, and no quiet upload.

Not by default. Password generation, strength checks, URL cleaning, text redaction, and file encryption run in the browser. Plaintext in those flows is not uploaded as business data.

No. The browser encrypts first, then uploads ciphertext. The key lives in the URL’s # fragment and is not sent with the HTTP request. After a successful read, the ciphertext is destroyed.

No. Every tool opens without sign-up. There is no account and no password vault, and we do not store an email or session for login.

The policy follows real product behavior, not a separate slogan

We may update this page so it matches how the tools actually run. Material changes update the date below. Continued use means you are looking at the current version.

Open a tool and check these boundaries, or read the terms