Privacy
WoolKey was designed around a single principle: your passwords are yours alone.
What we collect
Nothing. WoolKey has no database, no user accounts, and no analytics.
There is exactly one thing written anywhere, and it belongs to the opt-in API rather than this website: a per-caller request counter used to enforce the rate limit. It is described in full under Rate limiting on the API below, because "nothing" is the kind of claim that deserves its own footnote.
Local generation only
Every password and passphrase you generate on this website is generated entirely inside your browser using the Web Crypto API. The generated values never leave your device — not to our servers, not to any third party, not anywhere.
The separate, opt-in HTTP API for scripts and AI agents is the one exception, and only for those who deliberately use it: there, generation happens on the server because that is what the caller asked for. Even then nothing is retained — the value is returned and forgotten, with no database and no record of what was generated. Using this website never touches that endpoint.
No storage
WoolKey does not store generated passwords in:
localStoragesessionStorageIndexedDB- Cookies
- URLs
- Server logs
When you close or navigate away from the page, the generated password is gone.
No external resources
WoolKey loads no external scripts, fonts, stylesheets, analytics, or tracking pixels. The
Content Security Policy enforces connect-src 'none', which means the browser
cannot make any outbound network connections from WoolKey's JavaScript.
Service worker
WoolKey includes a service worker for offline support. It caches only static assets (HTML, CSS, JavaScript, the word list). Generated passwords are never cached.
Server logs
Your web server (Apache) may record standard HTTP access logs including your IP address and the pages you visit. These are standard server-level logs and are not related to password generation.
Rate limiting on the API
The HTTP API — never this website — allows 20 requests per minute per caller, and it has to remember something to count. That counter is the only thing WoolKey writes anywhere.
What it holds: a short list of request timestamps, in a file named after a SHA-256 hash of the caller's IP address, in the server's temporary directory, deleted automatically once it goes stale. No credential is in it, and nothing records which passwords were generated or what options produced them. A generated value is never written to disk at any point.
To be exact rather than flattering: hashing an IP address is not anonymisation. The IPv4 address space is small enough to work backwards through by brute force, so treat it as a pseudonym, not a disguise. It exists so one caller cannot exhaust the service for everyone else, and it is never linked to anything you generated.
Contact
Questions? CoolerSheep
