Emergency guide

What to do when you cannot get in.

Zero-knowledge encryption means nobody at ZZPass can open your vault for you, however politely you ask. That is the point, and it puts the planning in your hands. Ten minutes of preparation now covers almost everything that can go wrong later.

Before you need it

Ten minutes, once.

Everything below can be done today, and most of it is free. Do the first two at minimum.

Turn on biometric recovery

With it enabled, you can set a new primary password using Face ID or Touch ID on a trusted device. It is one account-level setting, so enabling it once covers the account, and recovery runs entirely on hardware you already have.

This is the only thing that replaces a forgotten primary password without a printed document. ZZPass still cannot reset it for you.

Print your Account Emergency Kit

One page carrying your account email, your Secret Key, your primary password, and a QR code that encodes all three so a new device can read them in one scan. Generated on your device and printed through your own printer.

How printing works →

Give it somewhere to liveMOST SKIPPED

That page restores your entire vault, so it belongs in a safe, a bank deposit box, or a locked drawer. Not a desk tray, not a photo library, not an email to yourself.

Tell one person it exists and where it is. A perfectly stored document nobody knows about helps nobody.

Name a trusted contactPREMIUM

Emergency Access lets someone you choose request your vault. They wait out a delay you set, 14 days by default, and you can reject the request at any point during it. Nothing happens silently.

How Emergency Access works →

If it has already happened

Find your situation.

Five things that actually go wrong, and what gets you out of each.

You forgot your primary password

If biometric recovery is on: open ZZPass on a trusted device and use Face ID or Touch ID to set a new primary password. Do this before deleting or resetting anything, because the recovery depends on that device.

If it is not: your printed Emergency Kit has the password on page 1. That is what it is for.

Your Secret Key alone will not help here. It is one of two halves and needs the password alongside it. Full recovery guide →

You lost every device but still know your password

This is the straightforward case. Install ZZPass on a new device, choose Recover Account, and enter your Secret Key followed by your primary password. Your vault decrypts and syncs.

Scanning the QR code on your Emergency Kit fills in all of it at once.

You are travelling and need one password now

If you carry a copy of the Premium Emergency Kit, look the account up and type the password by hand. If the account uses two-factor codes, the printed TOTP secret can be entered into any authenticator app to generate working codes.

Otherwise, recover the account on a borrowed device with your Secret Key and password, then sign out of ZZPass before you hand it back.

Someone else needs access and you cannot give it

This is what Emergency Access is for, and it only works if you set it up beforehand. Your trusted contact requests access, waits out the delay, and then receives your vault. You are notified the moment they ask, so a request made while you are simply on holiday can be turned down.

Access covers everything in your vault rather than a chosen subset, and you decide whether they get read-only or read and write. Set it up →

You want to leave something behind

A TimeCapsule holds encrypted notes that open on a date you choose, or after a period of silence from you. Instructions for your family, an explanation, a letter to your own future self.

It is not a substitute for Emergency Access. One delivers a message, the other delivers your vault. How TimeCapsules work →

How you are protected

Nothing here runs on trust.

Every route back into your account is designed so that ZZPass cannot walk it on your behalf, and cannot be compelled to.

Your key never leaves your device

Your encryption key is derived on your device from your primary password and your Secret Key. We store neither. There is no copy to hand over, subpoena, or leak.

Recovery runs on your hardware

Biometric recovery uses Face ID or Touch ID on a device you already control. It gives ZZPass no new ability to reset your password or read your vault.

Printing needs your password

Your primary password is required and verified before every print. Biometric unlock alone will not do it, and there is no remember for 24 hours.

Access requests are never silent

When a trusted contact asks for access, you are notified immediately and the delay you configured has to elapse. You can reject the request throughout.

Your kit is generated locally

The Emergency Kit is built on your device and sent to your own printer. Nothing is uploaded to ZZPass or to anyone else along the way.

Open to inspection

The server components are open source, so the claims on this page can be checked rather than taken at face value. Read the security model →

Honest limits

What we cannot do for you.

A password manager that could rescue you from anything would also be one that could be forced to hand your vault to somebody else. These are the trade-offs, stated plainly.

  • We cannot reset your primary password. No backdoor, no master key, no support override. Biometric recovery and your printed kit are the two things that stand in for it, and both are yours.
  • We cannot read or recover your vault. If you forget your primary password with neither biometric recovery enabled nor a printed kit, the data is unrecoverable by design.
  • We cannot release Emergency Access early. The delay you set is the delay, and the feature has to exist before the emergency does.
  • A printed kit is a physical object. It can be found, photographed, or burned. Storage is the part you own, which is why a safe matters more than it sounds.
  • Attachments and passkeys are not printable. They live in your vault and sync between devices, but they do not appear on paper.
What costs what

Most of this is free.

The two things that matter most, biometric recovery and a printed account kit, cost nothing.

Free

$0
  • Biometric recovery
  • Account Emergency Kit: email, Secret Key, primary password, QR code
  • Unlimited reprints
  • TimeCapsule sharing
  • Emergency Access
  • Emergency Kit with your passwords and notes

Premium

$2.99 / MONTH OR $29.99 / YEAR
  • Everything in Free
  • Emergency Access with trusted contacts
  • Emergency Kit including every password and note
  • Printed TOTP secrets for two-factor accounts
  • Unlimited shared groups and attachments
FAQ

Questions, answered.

What is the single most important thing to do?
Turn on biometric recovery, then print your Account Emergency Kit and put it somewhere safe. Both are free, both take minutes, and between them they cover a forgotten password and the loss of every device you own.
Can ZZPass help me if I forget my primary password?
Not directly, because we never hold your key. What we can do is make sure you have your own routes back in: biometric recovery on a trusted device, and a printed kit that carries your password and Secret Key. Support can guide you through either, but cannot perform a reset.
Is my Secret Key enough on its own?
No. It encodes your encryption salt and pairs with your primary password. Together they restore your vault on a new device; on its own the key opens nothing. That is also why it is reasonably safe to keep as a printed document.
Does my Secret Key change if I change my password?
Only if you ask it to. When you change your primary password there is a checkbox to generate a new Secret Key at the same time. Leave it unticked and your existing key keeps working. Tick it and you should reprint your kit, because the old one stops working.
What if someone finds my printed kit?
Treat it as a full compromise, because page 1 carries both halves of your recovery material. Change your primary password, tick the box to generate a new Secret Key so the found copy is dead, then print a fresh kit and store it better. Change the passwords for your most critical accounts as well.
Can I set up Emergency Access after something has happened?
No. It has to be configured while you still have access to your vault, because your trusted contact's ability to open it is established cryptographically at setup. This is the main reason to spend the ten minutes now.
How often should I revisit any of this?
Once a year is enough for most people, plus any time you change your primary password or add accounts you would hate to lose. Check that your printed kit is still where you think it is and still matches what the app shows.
Does any of this need a ZZPass server?
Recovery does not. Biometric recovery and the printed kit both work entirely on your own devices, offline if need be. Emergency Access and shared TimeCapsule releases use our escrow, which holds only a sealed key and a release condition, never your content. A capsule you keep to yourself never goes near it.

RELATED HELPAccount recoveryEmergency Kit helpEnd-to-end encryption