Privacy & Terms
The short version: we take one thing from you, an email address, and use it to send your API key and service updates. Passwords you check never reach us in readable form. No cookies, no ad tech, no data sales. Analytics are cookieless and aggregate-only. Email us and we delete you.
Privacy Policy
Who we are
knownPass is operated by KnownPass s.r.o., a Czech company (the "operator"), founded and run by Šimon Podlesný. Contact: privacy@knownpass.com.
What we collect, and why
- Email address: when you request an API key or apply as a design partner. Used to deliver the key, service notices (breaking changes, security issues) and occasional product updates. Legal basis: performance of the service you requested (Art. 6(1)(b) GDPR) and legitimate interest for updates, with opt-out in every email.
- API request metadata: key ID, timestamp, response code and latency, kept for rate limiting, abuse prevention and debugging. Logs rotate; we keep no long-term per-user request history.
- Passwords: never. The API receives a 6-character prefix of a salted hash. It cannot be reversed into the password and cannot be replayed against other services. The "Try it" demo on the landing page hashes in your browser and sends only that same prefix, with a shared demo key; the password itself is never transmitted. Details in the threat model.
- The dataset itself: the passwords we check against are stored as salted hashes with category tags. The dataset contains no email addresses, usernames, user IDs or source sites; those are discarded when raw material is processed, and the raw material is deleted within [N] days. We cannot identify anyone from the dataset, which is why access and erasure requests cannot be applied to it (GDPR Article 11). How it is built, where it comes from and what we refuse to ingest: data & provenance.
Analytics
We use (or will use, from launch) Plausible Analytics, an EU-based, EU-hosted, cookieless service. It gives us aggregate counts (page views, referrers, country) with no cookies, no persistent identifiers, no cross-site tracking and no personal profiles. That's the point.
Cookies
None. No cookie banner because there is nothing to consent to. The theme switch is remembered in your browser's local storage, which stays on your device.
Sharing
We never sell or rent your data. It is shared only with the processors needed to run the service, under data-processing agreements: [hosting provider] for hosting in [region], [email delivery provider] for key delivery and service notices, and Plausible Analytics (EU) for cookieless site statistics. Beyond that, only if the law compels us. Processing happens in the EU; no transfers outside the EU. [confirm]
Retention & your rights
We keep your email while your key is active or until you ask us to remove it. Under GDPR you can request access, correction, export or deletion of your data at any time: privacy@knownpass.com. You may also lodge a complaint with your local supervisory authority.
Early-Access Terms
The service
knownPass is an MVP in early access. It is provided "as is", without warranty or uptime SLA. Design your integration to fail open: if knownPass is unreachable, let your login flow proceed without the check.
Pricing and limits
The Free tier is 100 requests a day per API key, includes bulk download of the base dataset, and stays free. Paid tiers (Team, Tailored) cover language packs, audit evidence, organization-specific datasets and fair-use volume; current prices are on the pricing section. Prices are early-access prices and may change. Existing keys get 90 days' notice before any limit or price change affects them, with time to migrate, choose a plan or self-host once the core is open.
Acceptable use
- Use the API to screen passwords in your own products and services.
- Don't use it to test credentials you are not authorized to handle, resell raw access, or attempt to reconstruct the underlying dataset.
- We may suspend keys that break these rules or threaten service stability, with notice where practical.
Liability
To the maximum extent permitted by law, the operator's liability for any claim arising from the early-access service is limited to the amount you paid for it in the preceding twelve months. Nothing here limits liability that cannot lawfully be limited.
Changes
We'll update this page as the service evolves and note material changes to key holders by email. Continued use after a change means acceptance.