1. Scope and acceptance
These terms apply to public pages and tools under the domain usepwd.com and its language directories (such as /en/). The operating display name is UsePwd.
Opening or continuing to use this site means you have read and accept these terms. If you do not agree, stop using it. These terms do not replace the technical notes on each tool page on each tool page, and they are not a guarantee of a particular result.
2. What the service is
UsePwd is a browser-local encryption and privacy toolkit. Every tool works immediately — no sign-up. Sign-up and sign-in are not required, and there is no user account or vault.
The current public tools include:
- Password Generator: create 6–128 character random strings or a readable passphrase in the current tab with Web Crypto
- Password Audit: estimate strength locally and check a public leaked-password list shipped with the page
- Privacy Cleanup: strip tracking parameters from links locally, and redact common sensitive formats
- Burn-Link: encrypt locally with AES-256-GCM, submit ciphertext to the server, and create a one-time read link
- File Encryption Box: stream AES-256-GCM encrypt/decrypt locally, one file up to 5 GB
Except for Burn-Link, which stores ciphertext when you choose to create a link, plaintext, keys, and files from the tools above are not sent to UsePwd as a request body by default. The data-handling boundary is in the Privacy Policy.
3. No accounts
The site does not offer sign-up, sign-in, user profiles, or a vault, so it does not issue login sessions and does not store generated results, test secrets, cleanup source text, or encrypted files for you.
After you close or refresh the tab, content you did not copy, export, or download yourself will not appear on the server, and we cannot look it up, export it, or restore it as “a user.” If you need to keep it, put it on a device you control or in a password manager you own.
4. What you are responsible for
You are responsible for what you type, generate, download, and send from this site, including without limitation:
- How you store a generated password, and which systems you use it on
- Whether you send a Burn-Link to the right person, and screenshots, copies, or forwards on their device
- Whether a file passphrase is strong enough, whether it is sent separately from the ciphertext, and the consequence that a forgotten passphrase cannot be decrypted
- Whether a redaction result still needs a human review before you send it
- Whether your browser, operating system, and clipboard are in an environment you trust
These tools do not replace access authorization, compliance review, or a professional security assessment of a target system. Before you use a result on a work account, in production, or on someone else’s system, confirm you have the right to do so.
5. Acceptable use
When using this site, you must not:
- Use Burn-Link or other APIs to spread secrets you have no right to share, illegal content, or to defraud or harass others
- Try to bypass Burn-Link read counts, TTLs, or ciphertext deletion
- Send bulk requests, automated writes, or denial-of-service traffic against the site or
/api/secretsbeyond normal use - Interfere with others’ use, or probe or disrupt hosting and protection systems
- Present this site as a service you operate, or redistribute it after removing marks needed to identify UsePwd
We may throttle abnormal requests (for example, return a rate limit) or delete Burn-Link ciphertext that violates this section. That is not monitoring plaintext—the server cannot see the key fragment and cannot decrypt for you.
6. Tool limits
Each tool works as implemented on the current page. The following are not promises of this site:
| Tool | What it does | What it does not guarantee |
|---|---|---|
| Password Generator | Draws random characters or a readable passphrase with browser Web Crypto; below 8 characters you get a weaker-password warning | Does not guarantee a password fits a target site’s policy, and does not store or recover it for you |
| Password Audit | Estimates entropy and crack-time scale locally, and checks a built-in public leaked-password list | Not a web-wide lookup, and it does not query an external breach API; missing the list does not mean a password was never leaked |
| Privacy Cleanup | Strips tracking parameters in common formats, and masks phones, ID numbers, emails, API keys, and similar fields | Cannot catch everything; review important outbound text yourself. No certification or compliance endorsement is claimed |
| File Encryption Box | Streaming AES-256-GCM encrypt/decrypt, written as .lock / .enc; the file and passphrase are not uploaded |
A lost passphrase cannot be recovered. How you store or transmit the encrypted file after that is your decision |
| Burn-Link | Encrypts locally, then uploads ciphertext; the key stays in the address # fragment. Ciphertext is deleted after the count or time is reached |
Plaintext cannot be recovered from the server. After a screenshot or copy, burning cannot take back what was already seen |
7. Special terms for Burn-Link
When you create a link, the text is encrypted in the current tab first. Plaintext is at most 32 KB. The only fields sent to the server are ciphertext, ttl_hours, and max_reads (1–10 reads). The decryption key is appended in the fragment of s.html?id={id}#{key} and is not sent with the HTTP request.
The read page is public to the recipient; they need no account. After the count you set or after the TTL, ciphertext on the server is deleted and cannot be read again. If you choose “burn after read only,” ciphertext waits until it has been read, but it is still bound by the read count.
You decide whom you send the full link to. Once the link leaves this page, copies, screenshots, or forwards on the other device are outside our control. A lost link also cannot require us to restore a plaintext backup.
8. Intellectual property
Rights in page copy, layout, brand marks (including the USEPWD wordmark), and site source code on usepwd.com belong to the operator, except as otherwise provided by law. You may open the tools for personal use and copy results you generated.
Rights in content you type or generate in a tool remain with you or the original rights holder. You grant us a limited license to host ciphertext only as needed to provide Burn-Link: keep ciphertext for the TTL and read count, then delete it on expiry or after the last read. That license does not include viewing plaintext or using ciphertext for any other purpose.
9. Disclaimer and availability
The tools are provided “as is.” Encryption and randomness depend on the Web Crypto implementation in your current browser; different browsers, extensions, or enterprise policies may affect whether a feature works. We do not guarantee that you can open a page, create a link, or read unexpired ciphertext at any given moment.
These terms do not promise an uptime percentage, response time, staffed support, or compensation terms. The site does not show a support email or a ticket inbox. Loss from poor custody, a mis-sent link, a forgotten passphrase, an untrusted browser environment, or a third party intercepting something you already copied is yours to bear.
To the extent permitted by law, UsePwd is not liable for indirect loss, expected profit, or unrestorable data. Because there is no account, we could not recover a local result for you in the first place.
10. How these terms are updated
When the tool set, Burn-Link fields, or use limits change, we will rewrite this page and update the “Last updated” date above. Continued use of the site means you understand the conditions as written in the updated text.
Data handling is in the Privacy Policy. To check on the spot whether a password, file, or key left the browser, open the notes on the matching tool page.