Last updated: July 18, 2026
Email address — used for account identification and transactional emails.
Password (securely hashed) — stored using industry-standard password hashing. We never see or store your plain password.
Payment data — processed by Stripe. We never store your card details. Stripe receives and processes all payment information.
Usage data — we log basic API requests for security and debugging. No tracking cookies, no analytics, no third-party ad scripts.
Account data is stored in an encrypted database on a secured cloud server (Hetzner Cloud, EU). The server uses SSH key authentication only — no password login is permitted. Passwords are hashed using industry-standard one-way hashing algorithms and cannot be reversed. The database is not backed up externally.
Password generation runs entirely client-side. Your formula, base words, and generated passwords never leave your browser unless you explicitly export them. We don't log or transmit generated passwords.
We do not sell, trade, or share your data with third parties except:
No other third parties have access to your data.
Your account persists until you delete it or we terminate it. Upon deletion, all associated data is removed from our database. Session tokens expire after 7 days.
You have the right to:
To exercise any right, email support@mojaholdings.net
We use HTTPS for all connections. Passwords are hashed using industry-standard algorithms. Authentication tokens are signed with a server secret. The database runs locally on the server (no remote access). Despite these measures, no system is 100% secure.
PassForge is not directed to children under 13. We don't knowingly collect data from children.
We may update this policy. Material changes will be communicated via email.
Questions? Email support@mojaholdings.net
← Back to PassForge