Create cryptographically secure passwords using your browser's own random number generator. Choose the length and whether to include uppercase, lowercase, digits and symbols. Nothing leaves your device — the password is never transmitted, logged or stored.
Yes. Passwords are generated in your browser with the Web Crypto API (crypto.getRandomValues) and are never sent to our servers.
Use at least 16 characters for important accounts. Length matters more than complexity — each extra character multiplies the number of guesses an attacker needs.
Mixing upper and lower case letters, numbers and symbols increases strength, but some sites limit which symbols they accept; turn options off if a site rejects a password.
Don't — use a password manager to store a unique password for every site, and protect it with one long passphrase plus two-factor authentication.