The key is generated and instantly outputted over SSL. Nothing is ever stored nor would I want that liability. Would it better if I did the private key generation on the client side so that your browser generates it? The only issue with that is that it's a lot slower and browser compatibility isn't great.