How to store passwords safely on your phone
Published October 1, 2026
The safest way to store passwords on your phone is a password manager — on iPhone the built-in Passwords app (iCloud Keychain), on Android Google Password Manager, or a dedicated password manager app — combined with a unique password for every account and two-factor authentication on the important ones. Passwords should not live in a plain note, a screenshot or a chat with yourself.
This guide shows how to set up the built-in options step by step, how to fix the passwords you already have, and where a separate encrypted vault fits in.
Why not just keep passwords in Notes or a screenshot?
Because those places are open to anyone holding your unlocked phone, and they get copied around. A screenshot of a login page sits in your photo library, syncs to iCloud or Google Photos and shows up when you hand someone the phone to look at holiday pictures. An unlocked note is searchable by anyone who picks up the phone. A message you sent to yourself in a chat app lives on that service too.
A password manager is built for the opposite: it encrypts what it stores, asks for Face ID or your passcode before showing anything, and can fill passwords in for you so you never need to copy them around.
How do I use the built-in password manager on iPhone?
From iOS 18, iPhone has a dedicated Passwords app; on iOS 17 and earlier the same data is under Settings → Passwords.
- 1Make sure your passwords sync: Settings → your name → iCloud → Passwords (called Passwords and Keychain on older versions) and turn it on. This keeps them end-to-end encrypted across your Apple devices.
- 2Turn on AutoFill: Settings → General → AutoFill & Passwords → AutoFill Passwords and Passkeys.
- 3Open the Passwords app. It requires Face ID, Touch ID or your passcode before showing anything.
- 4Tap the Security section (or Security Recommendations on older versions) to see passwords that are reused, weak or have appeared in a known data leak. Change those first.
- 5When you create a new account in Safari or an app, accept the suggested strong password — iPhone saves it automatically.
And on Android?
Most Android phones use Google Password Manager, which is tied to your Google account.
- 1Open Settings → Google → Autofill → Autofill with Google and make sure it is on (the exact path varies slightly by phone maker).
- 2Open Google Password Manager from that screen, or from Chrome's settings under Password Manager.
- 3Run Password Checkup to find compromised, reused and weak passwords, and change the ones it flags.
- 4Protect the Google account itself with a strong password and 2-Step Verification, since it now guards everything else.
What makes the passwords themselves safe?
The tool matters less than these habits:
- One password per account. When one site leaks, a reused password lets attackers into every other account that shares it.
- Long and random. Let the password manager generate them; you do not need to remember them.
- Turn on two-factor authentication for email, banking, social media and your Apple or Google account. An authenticator app or passkey is stronger than an SMS code.
- Save the backup codes those accounts give you when you turn on 2FA. Store them as carefully as the password itself.
- Never type a password or code into a page someone sent you in a message, and never read one out to a caller, whoever they say they are.
What about the one password I have to remember?
Every password manager is protected by something you have to remember: your phone passcode, your Apple Account or Google password, or a master password. Make that one long — a passphrase of several unrelated words works well — and do not use it anywhere else.
Write it down on paper and keep it somewhere safe at home. That sounds old-fashioned, but a piece of paper in a drawer is out of reach of anyone online. For crypto wallets the same idea applies with higher stakes — see how to store a seed phrase safely.
If you prefer to keep a short list of non-login secrets in Notes — a door code, a Wi-Fi password — at least lock that note with a separate password: see how to lock notes on iPhone.
Where Lockboxy helps
Lockboxy is not a replacement for your phone's password manager: it does not fill passwords into apps or websites. What its Wallet does is give you an encrypted place, behind its own passcode, for the things that do not fit neatly in a password manager.
- Bank cards, passwords, Wi-Fi logins, crypto seed phrases and a live 2FA code generator, with every field encrypted individually.
- Breach checks for saved passwords, so you know when one needs changing.
- Everything is encrypted with AES-256 on the device; there is no account and no server holding a copy.
- The Wallet is unlimited on the free plan.
The vault's key is derived from your passcode, so if you forget it, nobody — including us — can open the vault, unless you generated a Recovery Key (Premium) in advance. If you are about to hand your phone in for repair, this checklist covers what to do with saved passwords first. More answers are in the Lockboxy FAQ.
Want a private place with its own passcode?
Lockboxy encrypts photos, videos, files and notes on your device, behind a passcode separate from your phone's. No account, no server.
Get Lockboxy on the App StoreMore guides
- How to store a seed phrase safely (and what not to do)
- How to lock notes on iPhone with a password or Face ID
- What to do before sending your iPhone for repair
- How to hide photos on iPhone (and what “hidden” really protects)
- How to lock apps on iPhone: Face ID lock, hidden apps and older-iOS workarounds
- How to store photos of your ID safely on your phone
- How to permanently delete photos on iPhone (and every copy you forgot)
- How to lend your iPhone without exposing your photos
Questions about how Lockboxy works? Read the FAQ