Check the source of randomness

The random-number source matters more than whether a result looks complicated. In the browser, Crypto.getRandomValues() supplies random values intended for cryptographic use. Ordinary Math.random() is not designed for choosing account secrets.

ComplexPass v2 uses Web Crypto and rejection sampling. With rules such as requiring each selected character type, it selects from valid completions so that the permitted passwords are equally likely. Its random passphrases use the same cryptographic source to select words. The original Classic v1 is preserved for memories; v2 is the version to use for modern generation.

Understand generation and visit tracking separately

ComplexPass creates passwords and passphrases on your device. The generated secret and your custom generator input are not sent to our analytics endpoint. The site does collect first-party visit and feature-use statistics, such as a traffic source, browser category, or a count of Copy clicks. Do Not Track and Global Privacy Control are respected.

If Cloudflare CAPTCHA is enabled, Cloudflare verifies browser access to the generator. The password is generated afterward in your browser. “Generated locally” describes how the secret is created; it does not mean the entire website makes no network requests.

Technical readers can inspect the page’s browser JavaScript and the Network panel in developer tools. A Copy event contains an event name and counts, rather than the copied password. Do not paste an actual account password into an unrelated website to investigate its safety.

Know which copies remain on your device

The recent-generations list stays in the current page’s memory and disappears when the page is refreshed or closed. Remember my settings saves non-secret preferences. ComplexPass does not keep a password vault for you.

Copying places the secret in your device’s clipboard. Downloading a batch creates an ordinary text file, which is not encrypted by the generator. Those copies deserve the same care as any other password. Hide/show changes what appears on screen; it does not remove the secret from the open page’s memory.

Use a generator as part of a good account routine

Keep your browser and device updated, use a new result for each account, and save the result in a password manager. A random password does not identify a fake sign-in page for you. Check the service you are signing into before entering it.

Start with the strong-password walkthrough or read how to generate and handle a batch. Both explain the actual controls without asking you to provide an existing password.