Privacy Policy
Version 1.2 · Effective 30 August 2026 · Password Generator
This notice explains who operates Password Generator, what personal data is processed when you use the public site, and what never leaves your device.
English is the operative language of the Service. Sari la varianta în limba română.
1. Who we are
The controller for personal data processed in connection with this Service is Jungean-Herman Marius-Alexandru, acting under the public name Alexandru Jungean. The operator is a natural person established in Romania.
- Service: Password Generator at https://password.alexjungean.com
- Default host URL: https://password-alexjungean.netlify.app
- Contact: alex.jungean@gmail.com
- Portfolio: https://alexjungean.com
- See also the Legal Notice and the Terms of Use.
2. Scope
This Privacy Policy applies to the public information-society service at https://password.alexjungean.com and to the same static artifact served from https://password-alexjungean.netlify.app. It covers personal data processed when you visit the pages, when you write to the contact address, and when public search tools index the pages.
It does not cover https://alexjungean.com, GitHub, Netlify’s own platform accounts, or any other website. Those services have their own notices.
Under Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018, the operator is the controller of the limited personal data described here. The operator is not a controller or a processor of passwords or passphrases you generate, because those values are not transmitted to the operator.
3. Generated secrets stay in this browser
Password Generator generates passwords and passphrases with the browser’s cryptographic random number generator. The current secret, the policy you choose, and the clipboard copy stay in local memory for this page session. There is no account and no vault.
The published tool routes do not:
- send a generated password or passphrase to a server;
- expose a /api route that accepts or returns a secret;
- send analytics, telemetry, or error reports that include the secret;
- write first-party cookies, localStorage, sessionStorage, or IndexedDB keys for the tool.
If you click Check known breaches, this browser hashes the current secret with SHA-1 and sends only the first five hexadecimal characters to Have I Been Pwned (typically with padding). The password itself, the full hash, and the rest of the hash never leave the device.
The operator does not receive that request or its response. Have I Been Pwned is an independent controller for the lookup. Their notice applies: https://haveibeenpwned.com/Privacy. We do not rely on GDPR Art. 6(1)(b) for that processing, because we do not carry it out.
4. Categories of personal data
| Category | Examples | Source | Do we receive the secret? |
|---|---|---|---|
| Connection data | IP address, date and time, requested URL, HTTP status, user-agent, referrer if sent | Created automatically when your browser requests the static pages and assets | No |
| Search-property data | Crawl, impression, and query data about the public pages | Search Console for the password subdomain | No |
| Correspondence | Your email address, message text, and attachments you choose to send | You, if you write to the contact address | Only if you paste a secret into the message |
| Generated passwords and passphrases | The current secret and the selected policy | Your device only | No. These stay in the browser session. |
| Optional breach-check prefix | The first five characters of a local SHA-1 hash | Your browser, only after you click Check known breaches | No. The operator never sees the prefix. Have I Been Pwned receives only that prefix, as an independent controller. |
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver the static site and assets you requested | Connection data | GDPR Art. 6(1)(b) — steps requested by you to use the information-society service; Art. 6(1)(f) — delivering a public site without accounts |
| Keep the host available and resist abuse | Connection data | GDPR Art. 6(1)(f) — security, fault diagnosis, and prevention of overload or fraud |
| Make the public pages discoverable | Search-property data | GDPR Art. 6(1)(f) — operating an indexable public tool |
| Answer a message you send | Correspondence | GDPR Art. 6(1)(b) and/or Art. 6(1)(f) — responding to a request; Art. 6(1)(c) where the message is a legal demand we must meet |
Where Art. 6(1)(f) is used, the legitimate interests are: providing a free public tool, keeping the host secure, making the pages findable, and answering people who write to us. Those interests are balanced against your right to a private visit. Generated secrets are not part of that balance because they are not received.
The optional breach check is not a processing purpose of this operator. Your browser contacts Have I Been Pwned directly. See section 3.
7. Recipients
- Netlify — static hosting for https://password.alexjungean.com and https://password-alexjungean.netlify.app. See https://www.netlify.com/privacy/.
- Google LLC — Search Console for the password subdomain, and public crawl.
- Google LLC (Gmail) — if you write to alex.jungean@gmail.com.
- Have I Been Pwned — only if you click Check known breaches. Independent controller, not our processor. https://haveibeenpwned.com/Privacy.
- Competent authorities, if a legal obligation requires disclosure.
8. International transfers
The operator is established in Romania. Hosting, Search Console, and email may involve processing in the United States or on other servers outside the European Economic Area. The optional Have I Been Pwned range API on api.pwnedpasswords.com may also involve processing outside the EEA. That transfer is initiated by your browser, not by us.
Where a transfer is not covered by an adequacy decision of the European Commission, we rely on the transfer tools used by those providers — typically Standard Contractual Clauses — and on their published supplementary measures. You may ask for more detail at alex.jungean@gmail.com.
9. Retention
- Generated secrets and policy choices: not received. They remain only in your browser until you leave or regenerate.
- Connection data: retained according to the host’s default logs. We do not export those logs into a private archive.
- Search-property data: retained in Search Console according to Google’s product retention.
- Correspondence: kept as long as needed to handle your request and any related legal obligation.
- Have I Been Pwned prefix: not received by us. Have I Been Pwned applies its own retention.
10. Your rights
If GDPR applies to you, you may request:
- access to personal data we hold about you;
- rectification of inaccurate data;
- erasure, where the legal conditions are met;
- restriction of processing;
- data portability, where processing is automated and based on contract or consent;
- objection to processing based on legitimate interests;
- a complaint to a supervisory authority.
Because we do not receive generated secrets, we cannot access or delete a password that exists only on your device. We do not sell personal data and we do not use it for automated decisions that produce legal or similarly significant effects.
11. How to exercise your rights
Write to alex.jungean@gmail.com. Describe the right you want to exercise and enough information for us to find any correspondence or to understand a hosting-log request. We may ask you to confirm that the request comes from the email address concerned.
We answer within one month of receipt. That period may be extended by two further months for a complex or numerous request; if so, we will tell you why.
You may also lodge a complaint with Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, România, anspdcp@dataprotection.ro, https://www.dataprotection.ro, or with the supervisory authority of your EU/EEA country of residence or work.
12. Children
The Service is not directed at children under 16. Romanian law sets 16 as the age for a child’s own consent to information-society services. We do not knowingly collect personal data from children. If you believe a child has sent us personal data by email, contact us and we will delete it unless we must keep it.
13. Security
- HTTPS for the published site;
- a Content Security Policy limited to this origin plus api.pwnedpasswords.com for the optional breach check, and related browser headers;
- generation only via crypto.getRandomValues, never Math.random;
- no API that accepts or returns the generated secret;
- optional breach check uses k-anonymity: only a five-character hash prefix is sent, and only after you ask.
These measures reduce accidental disclosure. They cannot protect a compromised device, a malicious extension, or a person who can see your screen.
14. Changes
The current version of this notice is always this page. The effective date and version number appear at the top. We will change the date when the notice changes. If a change is material, we will also state what changed here.
Version 1.2 clarifies that Have I Been Pwned is an independent controller, that Art. 6(1)(f) is the interest used for hosting, search, and security, how to exercise rights, children, and that both host URLs are in scope.
15. Contact
Privacy requests: alex.jungean@gmail.com
Politica de confidențialitate
Aceasta este o versiune rezumată în limba română, nu o traducere articol-cu-articol. Dacă textele diferă, varianta în limba engleză este textul operativ al Serviciului, cu excepția cazului în care legea română sau dreptul Uniunii Europene impune altfel.
Versiunea 1.2 · În vigoare din 30 august 2026 · Password Generator
1. Cine suntem
Operatorul datelor este Jungean-Herman Marius-Alexandru, sub numele public Alexandru Jungean, persoană fizică stabilită în România. Serviciu: Password Generator, https://password.alexjungean.com. URL implicit de hosting: https://password-alexjungean.netlify.app. Contact: alex.jungean@gmail.com.
2. Domeniu
Politica se aplică serviciului de la https://password.alexjungean.com și aceluiași artifact de la https://password-alexjungean.netlify.app. Nu acoperă https://alexjungean.com, GitHub sau conturile de platformă Netlify.
În temeiul GDPR și al Legii nr. 190/2018, operatorul este operator de date pentru datele limitate de aici. Nu este operator sau persoană împuternicită pentru parolele generate, deoarece nu îi sunt transmise.
3. Secretele rămân în acest browser
Parolele și frazele generate nu sunt trimise către operator, nu apar în analitică și nu sunt stocate de noi. Nu există cont sau seif. Dacă apeși „Check known breaches”, browserul trimite către Have I Been Pwned doar primele cinci caractere ale unui hash SHA-1 (de regulă cu padding), nu parola. Operatorul nu primește acea cerere. Have I Been Pwned este operator independent. https://haveibeenpwned.com/Privacy. Nu folosim art. 6(1)(b) GDPR pentru acea prelucrare, pentru că nu o efectuăm noi.
4. Categorii de date
| Categorie | Exemple | Sursă | Primim secretul? |
|---|---|---|---|
| Date de conexiune | IP, dată și oră, URL, status HTTP, user-agent, referrer dacă este trimis | Cererea automată a paginilor statice | Nu |
| Date ale proprietății de căutare | Crawl, afișări și interogări despre paginile publice | Search Console pentru subdomeniul password | Nu |
| Corespondență | E-mail, text și atașamente pe care le trimiți | Tu, dacă scrii la contact | Doar dacă lipești un secret în mesaj |
| Parole și fraze generate | Secretul curent și politica aleasă | Doar dispozitivul tău | Nu. Rămân în sesiunea browserului. |
| Prefix opțional de verificare | Primele cinci caractere ale unui hash SHA-1 local | Browserul tău, doar după click pe Check known breaches | Nu. Have I Been Pwned este operator independent. |
5. Scopuri și temeiuri
| Scop | Date | Temei |
|---|---|---|
| Livrarea site-ului static | Date de conexiune | Art. 6(1)(b) și art. 6(1)(f) GDPR |
| Disponibilitate și prevenirea abuzului | Date de conexiune | Art. 6(1)(f) GDPR — securitate și diagnosticare |
| Descoperirea paginilor publice | Date Search Console | Art. 6(1)(f) GDPR |
| Răspuns la un mesaj | Corespondență | Art. 6(1)(b) și/sau 6(1)(f); art. 6(1)(c) dacă e o cerere legală |
La art. 6(1)(f), interesele legitime sunt: instrumentul public gratuit, securitatea gazdei, găsirea paginilor și răspunsul la mesaje. Secretele generate nu fac parte din această ponderare, deoarece nu sunt primite. Verificarea de breșe nu este un scop al acestui operator.
6. Destinatari
- Netlify — hosting static. https://www.netlify.com/privacy/
- Google LLC — Search Console pentru subdomeniul password și crawl public.
- Google LLC (Gmail) — dacă scrii la alex.jungean@gmail.com.
- Have I Been Pwned — doar dacă apeși Check known breaches. Operator independent. https://haveibeenpwned.com/Privacy
- Autorități competente, dacă legea impune divulgarea.
7. Transferuri
Hostingul, Search Console și e-mailul pot implica prelucrare în afara SEE. API-ul Have I Been Pwned poate fi tot în afara SEE; transferul îl inițiază browserul tău. Dacă nu există decizie de adecvare, ne bazăm pe clauzele contractuale standard ale furnizorilor.
8. Drepturile tale
Dacă ți se aplică GDPR, poți cere acces, rectificare, ștergere, restricționare, portabilitate acolo unde este cazul, opoziție la interese legitime și o plângere la o autoritate de supraveghere. Nu putem accesa o parolă care există doar pe dispozitivul tău. Nu vindem date și nu facem decizii automate cu efecte juridice.
Scrie la alex.jungean@gmail.com. Răspundem în termen de o lună de la primire, cu posibilitatea de prelungire cu două luni pentru o cerere complexă. Poți depune plângere la Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, România, anspdcp@dataprotection.ro, https://www.dataprotection.ro, sau la autoritatea din statul tău de reședință ori de muncă din UE/SEE.
9. Copii
Serviciul nu se adresează copiilor sub 16 ani. În România, vârsta pentru consimțământul propriu la serviciile societății informaționale este 16 ani. Nu colectăm în cunoștință de cauză date de la copii.
10. Modificări
Versiunea curentă este această pagină. Versiunea 1.2 clarifică rolul Have I Been Pwned, art. 6(1)(f), exercițiul drepturilor, copiii și ambele URL-uri de hosting.
