Contact

Contact us

Whether you need help with the generator, want to report a security or privacy issue, have an accessibility concern, or need to exercise a data-protection right, you can reach the PassZen team using the details below. Messages are read by a human, but please never send us a real password, PIN, or any other secret; we do not need it and you should not share it with any website by email.

We build PassZen as a free, client-side tool, and that same philosophy applies to how we communicate: no ticket numbers to memorize, no chat widgets tracking you around the page, and no web form that quietly posts your message to a third-party endpoint. You write the email, your own mail client sends it, and it arrives in our inbox. Simple, transparent, and easy to audit, just like the generator itself.

The simplest way to reach us is by email. Include a clear subject line (for example “Security report” or “Privacy request”) so your message can be routed quickly. If your mail client is not configured, copy the address into any webmail service: Gmail, Outlook, ProtonMail, and similar providers all work fine.

We read every message during business days. Security reports and privacy requests are prioritized over general feedback, but we aim to reply to everything. If your request is urgent (for example an actively exploited vulnerability), put [URGENT] at the start of the subject line and we will triage it first.

What you can contact us about

Product support

Bugs, odd strength readings, feature requests, or anything that does not work as described: tell us what happened and which browser and device you used.

Security reports

Found a vulnerability or a privacy issue? Email us with steps to reproduce. Please do not publicly disclose details before we have had a chance to respond.

Privacy requests

GDPR, UK GDPR, and CCPA/CPRA requests (access, deletion, opt-out) can be sent here. Because the generator stores no account data, most requests only involve consent records stored in your own browser.

Accessibility & feedback

Screen-reader problems, keyboard traps, contrast issues, or general suggestions for improving the tool are all appreciated.

Advertising questions

Media kits, sponsorship ideas, and questions about our ad placements are welcome. Ads are clearly labelled and never receive generated passwords.

Press & partnerships

Writing about client-side security tools or interested in collaboration? Tell us about your audience, timeline, and what you have in mind.

Before you write

Your question may already be covered here; checking first is faster than waiting for a reply:

  • Usage questions may already be answered in the FAQ.
  • How the tool works, what it stores, and what it does not, see About.
  • Practical advice on length, entropy, managers, and 2FA, read the password security guide.
  • Cookie and consent questions are covered in the Privacy Policy (section 4); you can also reopen the consent panel with the “Update consent” button in the footer.
  • Liability, warranty, and strength-meter limits are described in the terms.

What to include in your message

A little context up front helps us answer correctly on the first reply:

  • What you were trying to do: e.g. “generate a 32-character PIN” or “update my consent choices”.
  • What happened instead: error text, unexpected strength labels, or a screenshot (with any secrets blurred out).
  • Your environment: browser and version, operating system, device type (phone, tablet, desktop), and whether you were using the installed PWA.
  • Steps to reproduce: for bugs and security reports, the exact sequence of clicks or key presses that triggers the issue.
  • Whether you are signed in to any account: you should not be: PassZen has no accounts, so if something asks you to log in, treat it as suspicious and tell us.

Never paste a real password, PIN, recovery code, or API key into your message, not even a “test” one you believe is unused. Emails transit multiple servers, and the safest habit is to treat email as a postcard, not a sealed envelope.

Response times

We are a small team, so response times vary with volume. As a guideline: security reports and privacy requests are typically acknowledged within a few business days; accessibility issues and bug reports within one week; feature requests and general feedback may take longer, especially if we need to discuss design trade-offs. If we have not replied within ten business days, send a short follow-up, sometimes messages land in spam filters on both ends.

GDPR and CCPA requests carry statutory deadlines (one month under the GDPR, 45 days under the CCPA, with possible extensions for complex requests). We start the clock when we can verify your request, so include enough detail for us to confirm it relates to data we actually hold, which, for most people, is only the consent choice stored in your own browser.

Security disclosures

Responsible disclosure keeps everyone safe. If you find a vulnerability, a way to leak generated secrets, bypass consent controls, inject scripts, or otherwise undermine the privacy promises on this site, email us privately before publishing details. Include the affected page, steps to reproduce, impact, and any suggested fix. We will acknowledge receipt, keep you updated as we patch, and credit you in the release notes if you want the recognition.

We do not run a paid bug-bounty program at this time, but we genuinely appreciate high-quality reports and will always prefer a quiet fix over a public exploit. Tests should target this site only: do not scan, stress, or attack third-party services, ad networks, or infrastructure you do not own.

Privacy & data-protection requests

Because PassZen has no user accounts and generated passwords never reach our servers, there is usually no personal profile for us to export or delete. Your consent choice lives in your own browser's localStorage, and you can change or clear it at any time with the “Update consent” button in the footer or by clearing site data in your browser settings. If you still want to exercise a formal right, access, deletion, objection, portability, or opt-out of sale/sharing, email us with the subject line “Privacy request” and your jurisdiction (EU/EEA, UK, California, or another US state).

We respond within the deadlines described in our Privacy Policy. You may also lodge a complaint with your local supervisory authority (for example the ICO in the UK or your EU data-protection authority) at any time; you do not need to contact us first.