>Do not send any password you actively us to a third-party service - even this one.
So I can only test password that I am not using (and by extension that I am not going to use in the future).
>oh no - pwned!
>This password has previously appeared in a data breach and should never be used. If you've ever used it anywhere before, change it immediately!
If I cannot (shouldn't) submit any password I am actively using, what does it matter if I used it before? Now I already changed it.