Pwdz← Back to website

Your space. Your data.

Pwdz stores your name, email address, a password hash managed by the authentication library, and your account sessions. Session cookies are required to sign in and access your private workspace. Accounts are created by administrators; public registration is disabled.

Checks and history

Input that you explicitly submit is sent to the configured verification provider through our backend. History stores the minimum input needed, normalized results, timestamps, and status. Raw provider payloads and full browser context are not stored in history. Only the account owner can view or delete their check history.

The default retention period is 30 days and can be changed in server configuration. Expired history is hidden immediately and deleted by the scheduled purge job. You can delete your own history from your account settings.

Provider-reported name matches are shown only for permitted checks and are not retained in history. Address details can be retrieved for a specific record you confirm as your own or your company’s. Only the selected record is returned, and address details are not stored in history. To avoid another provider request, selected address data is served from an encrypted temporary result cache that expires after 60 minutes. Expired cache data is removed by the purge job. Demographic details are excluded.

API keys and administration

User API secrets are displayed once and stored as cryptographic verifier hashes. Provider credentials stay in private backend configuration. Only administrators can create users, manage provider settings, and view integration health. Administrative changes are audited without passwords or secrets.

Name search returns candidate names and broad locality. Detailed self-profile verification uses information you provide and explicitly confirm as your own. Sensitive identifiers are restricted by server authorization and are not retained in history. Relevance scores and reported profile information are not proof of identity.

Requests and provider usage

Pwdz does not impose an application request rate limit. Requests still use the configured provider’s account quota and are subject to the provider’s own limits. Creating an API key does not change the provider subscription or quota.

Your choices

Public artwork is illustrative. Browser checks do not run automatically. No third-party marketing analytics tracker has been installed. Authentication may store session information such as browser details and a connection address when available through a trusted proxy. Appearance preferences are stored locally in your browser and, within the workspace, in your account settings.

Password-reset email is sent through the configured email service only when email delivery has been set up. Contact your workspace administrator for account access or data management requests.