No passwords, ever
There is no password field. The tool tracks dates and nothing else.
Track when you last changed the password on each account and how often it should be rotated — without ever typing a password into this page.
Everything you add is saved in this browser only — no account, no server, no sync.
There is no password field. The tool tracks dates and nothing else.
Set whatever rotation interval your workplace or your judgement requires.
Press Changed today after updating a password and the countdown restarts.
Record the account and the date, never the credential.
Forced password rotation is one of the most widely mandated and most widely criticised security practices in use. The criticism is well founded: when people are made to change passwords on a schedule, they choose predictable variations that are easier to guess than the password they replaced. Many organisations nevertheless still require it, and if you are subject to such a policy, missing the deadline usually means a locked account.
NIST SP 800-63B and the UK NCSC both recommend against arbitrary periodic expiry, advising rotation on evidence of compromise instead.
Password1! becomes Password2! Predictable increments are trivially guessable and give an attacker most of the work for free.
Length, uniqueness per site, a password manager and multi-factor authentication. Those four together outperform any schedule.
If your employer mandates a 90-day cycle, tracking the date is sensible. Tracking the password itself never is.
Questions about rotation policy, best practice and what is stored.
No, and there is nowhere to enter one. It records only an account name, the date you last changed its password and how often you want to rotate it. Use a password manager for the passwords themselves.
Modern guidance from NIST and the UK NCSC advises against routine forced rotation for personal accounts, because it pushes people toward weak, predictable variations. Change a password when there is a reason: a breach, a shared device, or a suspicion. Many workplaces still mandate a schedule, and this tool tracks whichever policy applies to you.
After any breach notification for that service, after sharing it with anyone, if you have reused it elsewhere, or if you ever entered it on a page you later suspected was a phishing site.
A unique long password per account stored in a password manager, plus two-factor authentication on anything that supports it. That combination does far more than any rotation schedule.
Yes. Account names and dates stay in this browser's local storage. Even so, avoid recording anything that identifies a login beyond a name you recognise.