Questions

Short answers on privacy, offline use and strength.

Does SecurePass send or store my passwords?
No. Everything runs in your browser and nothing is sent, saved or logged. The only outside request is the optional breach check, which sends five characters of a hash.
How can I check that for myself?
Open developer tools, choose the Network tab, and use the tools: no requests appear. Or go offline after one visit; it keeps working. The network counter shows the same live.
Does it work offline?
Yes, after your first visit. Only the breach check needs a connection.
Is the breach check private?
Yes. Only the first five characters of the password's SHA-1 hash are sent, and your device finds the match itself. How it works.
What can't SecurePass protect against?
Anything already on your device or watching your screen: malicious extensions, malware, clipboard history or sync, or someone looking over your shoulder. That's why you can hide the password.
Why does the checker rate a long password as weak?
Length only helps when it's unpredictable. Common words, names, dates, keyboard runs like qwerty and swaps like @ for a are tried first, so a long password made of them can fall in seconds.
Should I use a password or a passphrase?
Both are strong when random. Passwords suit a password manager; six or more random words are easier to type and remember, like your password manager's own password.
How random is it?
Every character comes from crypto.getRandomValues, the browser's cryptographic random generator, with no bias: every password is equally likely.
Is it really free?
Yes. No ads, accounts or tracking, and the source code is MIT licensed.