How to Store Passwords Safely: Best Practices

How to Store Passwords Safely: Best Practices

Creating a password is only the first part of account security. The password also needs to be stored somewhere it can be accessed when needed without leaving readable copies in emails, spreadsheets, notes, or chat messages.

A password manager is designed for this purpose. It keeps login details organized and makes it easier to use a different password for every account without memorizing all of them.

Where Can Passwords Be Stored?

Several password-management tools can store website and app credentials. Common options include Google Password Manager, Apple Passwords, Bitwarden, 1Password, and Proton Pass.

Each service has its own interface, but the basic idea is similar. A login is saved as an entry containing information such as the website, username, and password.

The important part is knowing where those saved credentials can be found later.

Google Password Manager

Google Password Manager works with Chrome and Android and can save passwords and passkeys.

On Android, saved credentials can be found through:

Chrome → Settings → Google Password Manager

After opening a saved website entry and completing the required device or account verification, the saved username and password can be viewed or edited.

The saved password is not stored inside Gmail. Google Password Manager and Gmail are separate services.

Apple Passwords

On supported Apple devices, saved credentials are managed through the Passwords app.

The basic path is:

Passwords → Unlock with Face ID, Touch ID, or passcode → Select the website or app

The saved login details can then be viewed or updated.

Bitwarden

Bitwarden stores credentials as Login items inside the Vault.

The usual flow is:

Bitwarden → Vault → Login

After selecting a saved login, the stored website, username, password, and other available details can be viewed.

When the matching website is opened, the browser extension can also offer the saved login for autofill.

1Password

1Password stores credentials as login items inside a selected vault.

A saved login can be opened from the vault to view the stored information. When the related website is opened, the browser extension can offer the saved login for autofill.

Proton Pass

Proton Pass stores credentials as login items inside a vault.

A login entry can contain the website, username, password, and other related information. The saved entry can be opened from the vault when the credentials are needed.

The main point is simple: passwords should be stored in a system designed for password management rather than inside ordinary documents or messages.

Why Passwords Should Not Be Stored in Gmail

Gmail is an email service, not a password vault.

Suppose an email contains:

Website: example.com
Username: account@email.com
Password: Example123!

The password is now sitting in a readable email.

That message may remain in the inbox, archive, Sent folder, backups, or another signed-in device. It can also be forwarded or copied.

Saving the same credential inside a password manager is different because the password is stored as a login entry rather than as an ordinary message.

Why Excel Is Not a Good Password Vault

An Excel file can make a password list look organized, but the passwords remain directly visible inside the document.

For example:

AccountUsernamePassword
Gmailaccount@email.comExample123!
WordPressadminWP123456!
Amazonaccount@email.comShop2026!

The file can later be copied to another computer, uploaded to cloud storage, attached to an email, or opened on a shared device.

One spreadsheet can therefore contain access information for many important accounts.

A dedicated password manager is better suited to this job because the credentials are managed as password entries instead of being kept in a plain list.

Why Phone Notes and Chat Messages Should Be Avoided

A normal notes app can leave the original password visible.

For example:

WordPress Password: Example123!

Anyone who gains access to the note may be able to read the password directly.

The same problem can happen when a password is sent through WhatsApp, Telegram, email, or another messaging service.

A message can remain in conversation history, backups, screenshots, notifications, or another person’s device.

This creates extra copies of the same credential that are difficult to control.

Use a Different Password for Every Account

Every important account should have its own password.

For example:

  1. Email: One unique password
  2. WordPress: A different unique password
  3. Shopping account: Another unique password
  4. Social media: Another unique password
  5. Work account: Another unique password

The reason is simple: if one password is exposed and someone gets access to that account, the same password cannot be used to directly access the other accounts.

This keeps the accounts separated instead of connecting them through one shared credential.

A password manager makes this practical because every account can have a different password without requiring every password to be memorized.

Generate the Password Before Saving It

A new password should be created first and then saved in the password manager.

Manually creating every password can lead to repeated words, dates, symbols, and familiar patterns.

A Password Generator tool can create a password based on the selected length and character types.

After generation, the password can be saved as the login entry for the relevant account.

Protect the Device Used to Access Passwords

Password storage does not end with the password manager.

The phone or computer used to access saved credentials should also be protected.

Useful protections include:

  1. Screen lock: Prevents casual access when the device is unattended.
  2. Device PIN or password: Protects the main device account.
  3. Automatic locking: Reduces the time an unlocked device stays accessible.
  4. Biometric authentication: Provides convenient protection on supported devices.

For example, a password manager on an unlocked laptop may still be accessible to someone who gets physical access to the computer.

The device and the password manager should therefore be protected together.

Protect the Password Manager Account

A password manager can contain credentials for email, work, shopping, social media, and many other services.

The account controlling the password vault therefore needs strong protection.

Where supported, multi-factor authentication can add another verification step.

Recovery information should also be protected because it may be needed to regain access to the vault.

The goal is to avoid creating one weak point that could expose many stored credentials.

Use Passkeys When Available

Some websites and apps now support passkeys instead of traditional passwords.

A passkey can be unlocked using a device method such as:

  • fingerprint
  • face recognition
  • device PIN
  • screen lock

This removes the need to type a traditional password for that particular sign-in.

Passkeys can also be stored in supported password-management systems alongside traditional passwords.

They are not available everywhere yet, but they can be useful when a service supports them.

Keep Recovery Information Secure

Recovery information can provide access to an account when the normal sign-in method is unavailable.

For example, an email account may be used to reset access to another service.

Recovery codes can also be needed after losing a device or another authentication method.

These codes should not be kept in an ordinary spreadsheet, phone note, or chat message.

The storage location should be protected while still being accessible when recovery is actually needed.

How Websites Should Store Passwords

Password storage also matters on the website side.

A properly designed website should not keep the original password as readable text.

Instead, the password is normally processed using a password-hashing method before being stored.

During a later login, the submitted password can be processed again and compared with the stored result.

The website can therefore verify the password without keeping a readable copy of the original credential.

Hashing and Encryption Are Different

Hashing and encryption are not the same process.

Encryption protects information in a form that can later be decrypted with the correct key.

Hashing transforms the original password into another value that can be used for verification.

Password storage normally uses password hashing because the website needs to check whether the submitted password is correct rather than retrieve and display the original password.

Why Password Salts Are Used

A salt is a unique random value used during password hashing.

Suppose two accounts use the same password.

With different salts, their stored hash values can still be different.

This makes it harder to compare stored values and identify accounts using the same password.

A salt is an important part of password-storage design, but it does not make a weak password strong on its own.

What Happens When a Password Is Exposed?

A password can become exposed through accidental sharing, a leaked file, or a data breach.

When that happens, the password should be replaced with a new one.

If the same password was used on another account, that account should also receive a different password.

The replacement should be genuinely new rather than a small change to the previous password.

For example, changing:

ExamplePassword1

to:

ExamplePassword2

does not create a completely different credential.

After changing the password, active sessions and account-recovery settings should also be reviewed when those controls are available.

Keep Saved Passwords Updated

A password manager needs to contain the current password.

Suppose a website password is changed but the old password remains saved in the password manager.

The password manager may continue offering the old credential during autofill.

Whenever a password changes, the saved login entry should also be updated.

This keeps the stored information matched with the actual account password.

Be Careful With Password Backups

Some password managers allow credentials to be exported or backed up.

Depending on the format, an exported file may contain many passwords in one place.

That makes the backup highly sensitive.

A password export should not be left permanently in a Downloads folder, attached to an email, or stored on a shared computer.

Temporary exports should be protected and removed when they are no longer needed.

Keep Shared Accounts Under Control

Some services allow multiple people to have separate user accounts.

That is better than giving several people the same password because access can be managed separately.

For example, a business platform might provide separate accounts for an administrator, developer, designer, and manager.

When one person’s access needs to be removed, that account can be disabled without changing a password used by everyone else.

When a shared login is unavoidable, secure password-sharing features are preferable to sending the password through ordinary chat.

Check Saved Credentials Regularly

Password managers can help identify problems with stored credentials.

Depending on the service, password checks may identify:

  • Reused passwords: The same password is used on more than one account.
  • Weak passwords: The password does not provide enough variation or length.
  • Exposed credentials: The password has been connected with known breach information.

These checks can help identify accounts that need attention.

When a password is flagged, replacing it with a unique new password is more useful than continuing to use the same credential.

A Simple Password Storage Routine

A practical routine can stay simple:

  1. Create: Generate a new password.
  2. Store: Save it in a password manager.
  3. Separate: Use a different password for every important account.
  4. Protect: Secure both the device and the password manager.
  5. Update: Change the saved entry whenever the account password changes.
  6. Review: Replace passwords that become exposed or reused.
  7. Recover: Keep recovery information protected and accessible.

This keeps password creation, storage, and recovery organized without relying on spreadsheets, email, notes, or chat messages.

Frequently Asked Questions

Why should every account have a different password?

Separate passwords keep accounts independent. If one password is exposed, the same credential cannot be used directly to access the other accounts.

Where can saved passwords be viewed?

The location depends on the password manager. Google Password Manager has its own password-management area, Apple uses the Passwords app, while Bitwarden and 1Password keep saved credentials inside their vaults.

What happens when a password manager shows an old password?

The saved login should be updated with the current password. Otherwise, autofill may continue entering the old credential.

Where should recovery codes be kept?

Recovery codes should be stored in a protected location that remains accessible when the main account or device cannot be used. An ordinary chat, public note, or unprotected document is not a suitable place.

What should happen to a password-manager export after it is no longer needed?

The temporary export should be removed from the computer and other locations where it may remain accessible. An exported file can contain many sensitive credentials.

Why are separate user accounts useful for shared work systems?

Separate accounts allow access to be managed for each person. When someone leaves the team, that person’s access can be removed without changing a password used by everyone else.

What should happen when autofill keeps entering an old password?

The saved login should be edited in the password manager so it contains the current password. The outdated entry should not remain active.

Can passkeys and passwords be stored together?

Yes. Modern password-management systems can support both traditional passwords and passkeys, allowing different sign-in methods to be managed in the same place.

Is a password manager better than an Excel file?

Yes. A password manager is designed specifically to store and use credentials, while an Excel file keeps the actual passwords inside a document that can be copied, shared, or opened separately.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top