Privacy and terms

What we collect and why, who helps us run the service, and the terms for using the API during early access.

Applies to
passwordradar.eu and the PasswordRadar API (early access)
Effective
Updated
On this page

Short version

We collect little: your email address, to send your API key, service notices and occasional product updates; a rotating log of API requests; the API’s and this website’s web-server access logs, deleted within 15 days; and daily request counts per key, for invoicing. A design-partner application adds your domain and auth system. Passwords you check never reach us in readable form. No cookies, no analytics, no ad tech, no data sales. Email us and we delete your data.

Privacy policy

Who we are

PasswordRadar (formerly knownPass) is operated by KnownPass s.r.o., a Czech company (the “operator”), founded and run by Šimon Podlesný. Contact: privacy@passwordradar.eu.

What we collect, and why

  • Email address: when you ask for an API key or apply as a design partner (an application also names your organisation’s domain and authentication system). Used to deliver the key, service notices (breaking changes, security issues) and occasional product updates. Legal basis: performance of the service you requested (Art. 6(1)(b) GDPR) and legitimate interest for updates, with an opt-out in every email.
  • API request metadata: key ID, timestamp, response code and latency, kept for rate limiting, abuse prevention and debugging. Logs rotate; we keep no long-term record of individual requests. Per-key daily request counts are kept for invoicing, and each bulk download is recorded with its key, date, file and size, for download quotas. The API’s web server also keeps a standard access log of each request: the caller’s IP address, the time, the request line, which includes the six-character prefix, the referring page and the user agent. It is used to keep the API secure and working (legitimate interest, Art. 6(1)(f) GDPR), rotated daily and deleted within 15 days. For a check your server makes, the IP address is your server’s; for the demo on this website, it is the visitor’s.
  • Visits to this website: like every web server, ours logs each request it answers: your IP address, the time, the page requested, the page that linked to it and your browser’s user agent. Used to keep the site secure and working, on the basis of our legitimate interest (Art. 6(1)(f) GDPR). The log is rotated daily and deleted within 15 days; nothing is built from it, no statistics and no profiles.
  • Passwords: never. The API receives a six-character prefix of a salted hash. It cannot be reversed into the password and cannot be replayed against other services. The demo on the home page hashes in your browser and, each time you press Check, sends only that same prefix, with a shared demo key; the password itself is never transmitted. The first time you use the demo it also sends one health check, with no key and no password data. The status page likewise sends one health check from your browser each time it loads. These requests come from your browser, so the API host receives your IP address, as any website does. Details are in the threat model.
  • The dataset itself: the passwords we check against are stored as salted hashes with category tags. The dataset contains no email addresses, usernames, user IDs or source sites; those are discarded when raw material is processed, and the raw material is deleted after processing. We cannot identify anyone from the dataset, which is why access and erasure requests cannot be applied to it (GDPR Article 11). Article 11(2) lets a person offer extra information that would identify them in the data. A password can’t do that: the same password belongs to everyone who chose it. How it is built, where it comes from and what we refuse to ingest: Data and provenance.

Analytics

None today. If we add site statistics, we will use Plausible Analytics, an EU-based, EU-hosted, cookieless service that gives aggregate counts (page views, referrers, country) with no cookies, no persistent identifiers, no cross-site tracking and no personal profiles, and we will update this page before we switch it on.

Cookies

None. There is no cookie banner because there is nothing to consent to. The theme switch and the radar’s pause button are remembered in your browser’s local storage, which stays on your device.

Sharing

We never sell or rent your data. It is shared only with the processors needed to run the service, under data-processing agreements:

API and dataset
Hetzner Online GmbH, Germany, on servers in Germany.
Website
WEDOS Internet, a.s., Czech Republic, which hosts this website and its access log.
Email
Proton AG, Switzerland, which hosts our mailboxes: key delivery, service notices and your messages to us.

Beyond that, only if the law compels us. Personal data stays in the EU, except email, which Proton AG handles in Switzerland, a country the European Commission recognises as providing adequate data protection.

Retention and your rights

We keep your email while your key is active or until you ask us to remove it. Under GDPR you can request access, correction, export or deletion of your data at any time: privacy@passwordradar.eu. You may also lodge a complaint with your local supervisory authority.


Early-access terms

The service

PasswordRadar is in early access. It is provided “as is”, without warranty or uptime SLA. Design your integration to fail open: if PasswordRadar is unreachable, let your login flow proceed without the check.

Pricing and limits

Every API key includes 1,000 requests a day. Beyond that, each request costs €0.01, paid as you go or from prepaid credit. Without a payment method or credit, requests over 1,000 a day return 429 with a Retry-After header.

The Free plan needs no card and stays free: it includes 1,000 requests a day, community support, the full base dataset and bulk download for self-hosting. The paid plans, Team and Tailored (early access), add language packs, a dated compliance attestation for auditors, email support and organisation-specific datasets under the same metering. Current prices are in the pricing section.

Prices are early-access prices in EUR, excluding VAT, and may change. Holders of existing keys get 90 days’ notice before any limit or price change affects those keys, with time to migrate, choose a plan or self-host the base dataset from the bulk download.

Acceptable use

  • Use the API to screen passwords in your own products and services.
  • Don’t use it to test credentials you are not authorised to handle, resell raw access, or attempt to reconstruct the underlying dataset.
  • The base dataset, bulk download included, is licensed under CC BY-NC 4.0, with one added permission: commercial self-hosting is allowed. In your own systems that includes paid products: you may screen the passwords of your own staff and of your own product’s users. What needs a written exemption from the author, Šimon Podlesný (hello@passwordradar.eu), is selling the screening itself: reselling or redistributing the dataset, running it for other organisations (for example as a managed service provider or an identity-hosting provider), or making it a paid feature of a security product.
  • Tailored and curated datasets are commercial, for paying customers.
  • We may suspend keys that break these rules or threaten service stability, with notice where practical.

Liability

To the maximum extent permitted by law, the operator’s liability for any claim arising from the early-access service is limited to the amount you paid for it in the preceding twelve months. Nothing here limits liability that cannot lawfully be limited.

Changes

We’ll update this page as the service evolves and tell key holders about material changes by email. Continued use after a change means acceptance.