Skip to content
VaultPass

VaultPass · Information

Privacy policy

Exactly what happens to what you type on this site, tool by tool and without evasions.

Last updated:

Data controller

Marcos Cebrino · Tax ID 09138666F · Calle Santander, Alcorcón, Madrid (Spain).
Contact: vaultpass.info@gmail.com

The essentials, in three lines

  • The passwords and text you type into the tools are never sent to a VaultPass server, because VaultPass has no server of its own to receive them.
  • There are no accounts, no sign-up and no user profile.
  • The site is funded by Google AdSense advertising, which does use cookies and for which your consent is requested.

What happens in each tool

ToolWhat leaves your device
Password strength checkerNothing. The analysis is JavaScript running in your browser.
Password generatorNothing. It uses the browser's cryptography API.
Passphrases (Diceware)Nothing. The word list ships with the page.
AI prompt sanitiserNothing. Pattern detection is local.
PIN, UUID and Wi-Fi QRNothing. The QR is drawn on your device.
Breach checkFive characters of a SHA-1 hash. See below.

The only external query

The breach checker needs to compare against a database that cannot fit in your browser. To do that without revealing what you are looking for, it works like this:

  1. Your browser computes a SHA-1 hash of the password.
  2. Only the first five characters of that hash are sent to the Have I Been Pwned service.
  3. The service returns every hash beginning with those five characters, several hundred of them.
  4. The final comparison happens on your machine.

The service receives neither your password nor the complete hash, and the fragment it does receive corresponds to hundreds of different passwords, so it cannot deduce which was yours. This technique is called k-anonymity.

Advertising and cookies

This site displays Google AdSense advertising. Google and its vendors may use cookies and identifiers to serve and measure ads, and in some cases to personalise them.

If you connect from the European Economic Area, the United Kingdom or Switzerland, a consent notice managed by Google's certified platform (Funding Choices) appears before any of that is activated, where you can accept or decline. You can change your decision at any time by clearing the site's cookies in your browser.

Google acts as an independent controller for the data it collects for advertising purposes. Its policy is set out inhow Google uses information from sites that use its services.

Storage in your browser

VaultPass stores one single preference — your chosen language — in your browser's local storage. It does not identify you, it is never sent anywhere, and you can remove it by clearing the site's data. Nothing you generate or check survives closing the tab.

Hosting and logs

The site is a set of static files served by a hosting provider. Like any web server, it may automatically record technical connection data (IP address, date, browser) for security and operational purposes. VaultPass does not exploit those logs or cross them with any other information.

Your rights

You may exercise the rights of access, rectification, erasure, objection, restriction and portability by writing tovaultpass.info@gmail.com. A response is given within one month at the latest.

In practice, since no identifying data is collected through the tools, there is usually no personal information of yours to erase beyond whatever arises from advertising — in which case Google is the controller and you can manage it from your Google account.

If you believe your rights have not been respected, you may complain to theSpanish Data Protection Agencyor to your own national supervisory authority.

Changes to this policy

Any change is published on this page with its update date. If the change affects how data is handled, it will be flagged prominently.