The client-side software is built on top of Helloblock.io and uses BitcoinJS-lib. All wallets and transactions originate on the client and never on our servers using the same mechanisms found in any other hierarchical deterministic brain wallet. So if you add a passphrase and then promptly forget it there's nothing we can do! This is both a feature and a bug and we are interested in exploring other mechanisms that keep our users in control of their funds while also being very easy and convenient to use. We don't want you to store your life savings in this wallet. Think of it like your real wallet. Just put enough for the day in there. There is a time and place for cold wallets and tight restrictions but that can be less convenient for day-to-day use.
When you first sign up your passphrase is supplied by our servers. This mechanism is similar to how most Bitcoin and Dogecoin tip bots work. It lets people send to a friend's address before they've signed up for the service. This has some dangers. If our servers are compromised these passphrases can be used to gain access to the wallets, but only if the users haven't gone through the "upgrade your security" process and created a new deterministic wallet. We are busy working on multi-factor authorizations based on multiple identity providers including SMS, Twitter, email and more. We think there are ways to keep users fully in control of their own funds, safe from attackers as well as being convenient. It is a tall order but we're ready to take on the challenge.
William Cotton - CTO QuickCoin