Three words, three eras, and one of them involves handing your coins to a stranger and hoping.
The words get used interchangeably and they should not be, because they describe genuinely different trust models. If you are choosing a tool, this distinction is the choice.
You send coins to an operator. They hold them, shuffle them with other people's, and send different coins back later. It works, right up until it doesn't: the operator has your funds and can simply keep them, and they know exactly which output belongs to which input. Every exit scam in this category worked the same way, and there is nothing in the design that prevents the next one.
Same idea, usually with better operational hygiene — multiple addresses, delays, split payouts. The custody problem is unchanged. If someone has to hold your coins to mix them, they can decide not to give them back, and they can always tell which is which.
No shuffling and no custody. You deposit into a program that has no instruction for sending funds anywhere except to whoever presents a valid zero-knowledge proof. Withdrawing proves you own one of the deposits without saying which. The operator cannot pay themselves your deposit because the contract has no code path that would let them, and they cannot tell your withdrawal from anyone else's because the proof does not carry that information.
TornadoSol is the third kind. The mechanism is documented here in enough detail to check.
Removing the operator's power to steal also removes their power to help. There is no password reset and no support queue. Your note is the only key, it exists only in your browser, and if it is lost the deposit stays in the pool permanently. That is not a policy someone could be persuaded to change — there is no instruction in the program that could act on such a decision.