Legal
Privacy Policy
Last updated: 13 August 2026
This page describes what PassAfer (passafer.com) actually processes. It answers whether plaintext leaves your device — not how to strip tracking parameters. That tool lives on the remove tracking parameters page.
Scope
This policy covers public pages on passafer.com, in-browser tools, and signed-in features: account, vault, and Burn-Link create. Using the site means you understand the processing below.
What stays in the browser
These jobs run on your device. PassAfer does not upload their plaintext, keys, or original files as product data:
- Passwords from the generator (random characters and passphrases), including copy and export
- The password under test in the password strength checker, plus strength and local denylist checks
- Original URLs and text in Clean Link and Data Redaction, and their results
- File contents and passphrases when you encrypt a file, including
.lock/.encoutput
Encryption uses AES-256-GCM via the Web Crypto API. You can verify sensitive traffic in the browser Network panel.
Privacy-tool originals are not written into analytics. Audit and File Box also keep tested passwords and filenames out of event parameters.
What the server receives
Account
Sign-in uses a username + password (the username is not an email). Usernames are 3–32 characters, start with a letter, and may contain letters, digits, or underscores. The server stores the username and a password hash. After sign-in the browser keeps a session token locally.
Vault
Signed-in users may save generated passwords to the vault. Entries are stored as ciphertext, not plaintext in the database. Labels may be stored so you can recognize items. This path is separate from generator, audit, and File Box, where computation does not leave the browser.
Zero-Knowledge Burn-Link
On create, the browser encrypts locally, then uploads ciphertext and non-sensitive metadata (expiry, max reads). The decryption key sits in the URL # fragment and is not sent with the HTTP request. After the first read the blob is destroyed. The server cannot recover plaintext from ciphertext alone.
Static assets and operational logs
Page visits request HTML, CSS, and scripts. Infrastructure may keep ordinary request logs (time, path, coarse network data) without tool plaintext.
Local storage in the browser
passafer_lang— interface languagepassafer_session— sign-in session (username and token)
Sign-out clears the session. Clearing site data or using a private window removes these items.
Analytics
Production uses self-hosted Matomo for page views and interaction events (for example opening a tool or finishing a generate). Events describe actions only — not password plaintext, Burn-Link secrets, tested passwords, redaction source text, or file contents.
If you are signed in, analytics may use the username as a visit identifier to tell guest use from signed-in use. It is not a channel for reading secrets you type into tools.
The tracker is not loaded on localhost previews.
What we do not do with this data
- We do not sell tool plaintext or use it for advertising profiles
- We do not send tested passwords to third-party breach APIs (the denylist is local)
- We do not claim the server can read Burn-Link plaintext or File Box files
Retention
Account and vault items last while you keep the account. Burn-Link ciphertext is held until the configured reads or expiry, then deleted. Analytics follow the stats system’s ordinary retention.
Your choices
- The generator works without an account; other tools unlock after sign-in
- You may sign out, delete vault items, or stop using the site
- Burn-Link reading pages are public for recipients — no account required
Changes
If the processing scope changes, we will update this page and the “last updated” date. Continued use means you have seen the revised description.
Related: Terms of Service · FAQ