What these terms cover
These terms govern your access to and use of the tools, explainer pages, and blog on the FastPwd site (fastpwd.com and its language directories). FastPwd is a browser-local-first encryption and privacy toolkit. It does not offer user accounts, login sessions, or a password vault.
Opening and continuing to use this site means you have read and accept this page as it stands. If you do not agree, stop using features that send requests to FastPwd—especially creating or opening a Burn-Link. Purely static tool pages can still be opened on this device, but Burn-Link cannot be created or read.
This page answers “how you may use the site, who is responsible for results, and what is not allowed.” What the server receives and how long it is kept is governed by the Privacy Policy. The two pages have different jobs; do not treat one as a substitute for the other.
What this site provides
FastPwd provides a set of tools that run in the browser: password generation, Password Audit, the privacy cleaner, Burn-Link, and File Encryption Box. Encryption uses the browser Web Crypto API with AES-256-GCM. Aside from Burn-Link temporarily storing ciphertext, plaintext, keys, and files are not uploaded as business data by default.
This site does not provide the following, and these terms do not treat them as part of the service:
- User signup, login, a profile, or a password vault;
- Uptime metrics, incident response windows, or any form of SLA;
- A public support inbox, tickets, or phone support;
- A guarantee that a given password is “safe enough,” that a Burn-Link will “definitely be delivered,” or that a given ciphertext will “definitely decrypt.”
Whether a tool runs depends on whether your current browser supports the required Web APIs. We provide the features as the page actually presents them; we make no extra verbal or off-site promises.
The following conditions match the product pages. You may use these tools, but you must stay within the limits and purposes stated on each page.
| Tool |
Conditions of use |
Still your responsibility |
| Password generator |
Random characters or a readable passphrase, length 6–128; below 8 you are warned that security is weaker |
Where you paste the result, and whether that password fits the target system |
| Password Audit |
A local entropy estimate and a check against a built-in public leaked weak-password list; not a full-web lookup |
Whether you keep using a password marked weak, and how you interpret the result |
| Privacy cleaner |
Strip tracking parameters on this device, and mask phone numbers, ID numbers, emails, and similar fields |
Who you send the cleaned link or text to, and whether redaction covers the fields you need |
| File Encryption Box |
AES-256-GCM streaming encrypt/decrypt, one file up to 5 GB, output .lock / .enc |
Custody of the passphrase, ciphertext file, and original file; FastPwd cannot recover a lost passphrase |
| Burn-Link |
Encrypt on this device, then submit ciphertext only; plaintext limit 32 KB; reads 1–10; optional 1 hour, 24 hours, or 7 days |
Who receives the full link (including the # key), and how the recipient stores the plaintext |
The Burn-Link reading page s.html is public to anyone who has the full link; the recipient also does not need to sign up. The key sits only after # in the address, in the form s.html?id={id}#{key}.
What you must decide for yourself
Keeping computation in the browser does not mean FastPwd takes on the consequences of your use. You decide and are responsible for the following:
- Which systems you use a generated password on, whether it meets the other party’s complexity rules, and how you store it after copying.
- Password Audit can only catch common weak passwords and locally computable strength issues. It cannot prove a password “never leaked elsewhere.”
- A cleaned link may still point to a page you do not want public. Redaction is masking, not a legal promise of anonymization.
- If you forget the File Encryption Box passphrase, FastPwd cannot decrypt .lock / .enc files—because the passphrase was never uploaded.
- Anyone who opens a Burn-Link that still has the
# fragment can decrypt it on their device. Do not send it through channels that strip fragments, write access logs, or blast it to people who should not have it.
- Content you submit or share must comply with applicable law. This site does not verify the identity of recipients you choose.
After you send a result to a third party, how they store, forward, or leak it is outside FastPwd’s control and is not assumed by these terms.
Prohibited uses
When using this site, you must not:
- Use Burn-Link to distribute illegal, infringing, or clearly harmful content, or use the ciphertext channel for fraud, extortion, or unauthorized access.
- Automate bulk writes against the create API, bypass short-term rate limits by source IP, or subject the site to denial of service, vulnerability scanning, or unauthorized testing.
- Forge the FastPwd brand, PA mark, or pages so that someone believes a link, script, or ciphertext file was issued by this site.
- Claim that FastPwd’s servers stored your plaintext, keys, audited passwords, or files—that is the opposite of how the site actually works.
- Repeatedly create meaningless ciphertext or occupy storage in order to interfere with others’ use.
Local tools do not go through FastPwd’s business API, so we cannot remotely “close” your browser tab. For Burn-Link, we may refuse creation, rate-limit by IP, or delete ciphertext still in temporary storage that violates these terms or the law.
Burn-Link API
Burn-Link is the only tool on this site that sends business data to the server. Creating and reading both require no account. Text is encrypted first in the browser with AES-256-GCM; the request carries only ciphertext, a TTL, and a read-limit.
API boundaries
- A single plaintext payload may not exceed 32 KB (counted as UTF-8).
- Reads may be 1–10, default 1; ciphertext is deleted after the limit is reached.
- TTL may be 1 hour, 24 hours, 7 days, or deletion only after the read limit is reached.
- The create API reads the source IP for short-term rate limiting, to prevent bulk writes. It is not used to build a user profile.
Actions we may take
To keep the API available, FastPwd may rate-limit, refuse requests, or delete ciphertext that has not yet burned and that violates these terms or applicable law, without prior notice. These measures are not a service commitment to you or the recipient, and they are not monitoring of plaintext—the server does not have the key after #.
Name and page content
The FastPwd name, PA brand mark, page copy, styles, and scripts are provided by this site for you to use the tools here. Without written permission, you may not use whole-site pages or marks on a lookalike site meant to impersonate us.
Passwords you generate on this device, cleaned results, encrypted files, and plaintext you write into Burn-Link remain under your control. FastPwd does not claim copyright in that content, and that does not create a duty to store or recover it for you.
Disclaimers and limitation of liability
Tools are provided “as the current page presents them.” To the extent permitted by applicable law:
- We do not warrant that this site will stay reachable, that a given request will succeed, or that a given browser environment will complete encryption.
- We do not warrant that a generated password meets a given system’s policy, or that Password Audit will catch every weak password.
- We are not liable for loss from your leaking a complete Burn-Link, forgetting a file passphrase, or sending a result to the wrong person.
- We make no compensation promise for indirect loss, data loss, reputational harm, or the cost of substitute tools.
This page sets no damages cap and offers no service tier: this site does not sell uptime packages. If a jurisdiction does not allow exclusion of implied warranties, that part is read as the minimum that jurisdiction will not allow to be excluded; the remaining terms still apply.
How these terms are updated
If conditions of use change—for example, Burn-Link limits or prohibited uses—we will revise this page and update the “Last revised” date. Continued use of this site means you take the rules as they then stand.
This site has no user email addresses, so we will not notify changes by email. Changes to the data-processing scope are written on the Privacy Policy and are not restated here.