Skip to main content

Privacy Policy

Last updated: October 31, 2025

100% Private & Secure

PassCheck Pro is a privacy-first password strength checker. All password analysis happens entirely in your browser. Your passwords never leave your device and are never sent to any server.

Overview

PassCheck Pro is a privacy-first password strength checker that performs all analysis locally in your browser.

If you also review AI-assisted documentation, ContentGuard helps ensure sensitive wording stays policy-compliant before it ever leaves your secure workspace.

Data Collection & Processing

What We Collect

None. We do not collect, store, or transmit any personal information or user data to our servers.

How Password Analysis Works

  • 100% Client-Side: All password strength analysis happens entirely in your browser using JavaScript
  • No Server Transmission: Your passwords never leave your device
  • No Logging: We do not log, record, or store any passwords you test
  • Privacy-Focused Analytics: We use anonymous, cookieless web analytics to understand site usage (see Web Analytics section below)

Breach Checking (Optional Feature)

When you use the breach checking feature:

  • Your password is hashed locally in your browser using SHA-1
  • Only the first 5 characters of the hash are sent to the Have I Been Pwned API (k-anonymity protocol)
  • The API cannot reverse-engineer your password from this partial hash
  • Your browser checks if your complete hash matches any in the returned list
  • This is an optional feature you can choose to use

Local Storage (Browser Only)

  • Password History: If you use the history feature, previous passwords analyzed are stored in IndexedDB in YOUR browser only
  • User Settings: Any preferences you set are stored in localStorage in YOUR browser only
  • No Cloud Sync: This data never leaves your device and is under your complete control

Third-Party Services

Have I Been Pwned API (Optional)

Web Analytics

We use privacy-focused web analytics to understand site usage and improve the service:

Vercel Analytics

  • Collects anonymous page views and performance metrics
  • No personal information or cookies
  • No cross-site tracking
  • Privacy policy: Vercel Analytics Privacy

Ahrefs Web Analytics

  • Collects anonymous page views and navigation data
  • No personal information or cookies
  • Respects Do Not Track (DNT) headers
  • Privacy policy: Ahrefs Privacy Policy

Important: These analytics services do NOT have access to:

  • Any passwords you test
  • Content you enter into forms
  • Your password history or settings
  • Any personally identifiable information

No Other Third-Party Services

  • No advertising networks
  • No social media trackers
  • No marketing tools

Data Retention

We retain nothing because we collect nothing. All data stays in your browser under your control.

To clear your local data:

  • History: Use the "Clear History" button in the app
  • All Data: Clear your browser's cache and local storage for passcheck.io

Your Rights

Since we don't collect data, there's no data to request access to, deletion of, correction of, or portability of. Your data lives entirely on your device and you have complete control over it through your browser settings.

Security Measures

  • Client-Side Processing: All sensitive operations happen in your browser
  • HTTPS Only: All connections to our site use encrypted HTTPS
  • No Backend Database: We don't have a database storing user information
  • Open Source: Our analysis algorithms are transparent and auditable

Changes to This Privacy Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.

Last Updated: October 31, 2025

Contact

If you have questions about this privacy policy, you can reach out through the website's contact information.


In Summary: PassCheck Pro is designed with privacy as the top priority. Your passwords are yours alone - they stay on your device and are never transmitted to us or any third party (except optionally the k-anonymity breach check protocol).