Password managers that keep the vault on your phone
There are two shapes of password manager. One stores an encrypted vault on a company's servers and syncs it for you. The other stores an encrypted file that you keep and sync yourself. Both are far better than reusing passwords. They fail differently, which is the part worth understanding before you commit several hundred logins to one of them.
The two models
- Sync just works, on every device
- Password sharing with family
- Recovery options if you forget the master password
- Breach monitoring and similar extras
- You choose where the file lives
- Nothing to breach centrally
- Works with no connection at all
- No subscription, ever
Werbung
Local vault managers
These use the KeePass format, which is a single encrypted file you can sync however you like or not at all.
Open source, actively maintained, supports biometric unlock and Android autofill properly. The most complete free KeePass client on Android.
Can run entirely against a server you host yourself, which puts it between the two models. The client is open source and the free hosted tier is genuinely usable.
- Create the vault on a computer or the phone One file, one strong master password. Write that password down and store it physically.
- Put it in whatever sync you already use Any file sync works. The file is encrypted before it leaves the device.
- Turn on Android autofill Settings, passwords and accounts, autofill service. Without this you will be copying and pasting, and you will give up within a week.
- Keep a second copy A vault file lost to a broken phone is every account at once. Two locations, minimum.
Hosted managers worth considering
Polished, strong autofill, free tier limited to one device, which is a real constraint for most people.
The free tier syncs across unlimited devices, which is unusual and the reason it appears twice in this article.
Keep the second factor separate
A password manager that also stores your two-factor codes is convenient and it collapses two factors into one. If someone gets the vault open, they have both halves. For important accounts, keep the codes in a separate app.
Open source, encrypted, and it exports, which matters enormously when you change phones. The best of the free authenticators.
Simple and everywhere. Transfer between phones works now, which was the historical complaint.
Necessary if your work uses Microsoft accounts, and fine for standard codes as well.
Any manager beats reused passwords. Choose local if you will back up, hosted if you will not, and keep two-factor codes in a separate app.
Frequently asked questions
Is a local vault safer than a hosted one?
It removes a central target and adds a personal one. If you back up reliably, local is excellent. If you do not, hosted is safer in practice.
What happens if I forget the master password?
With a local vault, nothing can be recovered. That is the trade. Write it down and keep it physically somewhere safe.
Does Android autofill work with these?
Yes, all of the above register as autofill services. You have to enable it once in settings.
Read next
This is not a rivalry. Each does something the other cannot.
You are not buying encryption. You are buying an operator whose income does not depend on you.
For a plain ZIP either works. For a split, password-protected archive, only one does.

