Zero-knowledge encryption means nobody at ZZPass can open your vault for you, however politely you ask. That is the point, and it puts the planning in your hands. Ten minutes of preparation now covers almost everything that can go wrong later.
Everything below can be done today, and most of it is free. Do the first two at minimum.
With it enabled, you can set a new primary password using Face ID or Touch ID on a trusted device. It is one account-level setting, so enabling it once covers the account, and recovery runs entirely on hardware you already have.
This is the only thing that replaces a forgotten primary password without a printed document. ZZPass still cannot reset it for you.
One page carrying your account email, your Secret Key, your primary password, and a QR code that encodes all three so a new device can read them in one scan. Generated on your device and printed through your own printer.
That page restores your entire vault, so it belongs in a safe, a bank deposit box, or a locked drawer. Not a desk tray, not a photo library, not an email to yourself.
Tell one person it exists and where it is. A perfectly stored document nobody knows about helps nobody.
Emergency Access lets someone you choose request your vault. They wait out a delay you set, 14 days by default, and you can reject the request at any point during it. Nothing happens silently.
Five things that actually go wrong, and what gets you out of each.
You forgot your primary password
If biometric recovery is on: open ZZPass on a trusted device and use Face ID or Touch ID to set a new primary password. Do this before deleting or resetting anything, because the recovery depends on that device.
If it is not: your printed Emergency Kit has the password on page 1. That is what it is for.
Your Secret Key alone will not help here. It is one of two halves and needs the password alongside it. Full recovery guide →
You lost every device but still know your password
This is the straightforward case. Install ZZPass on a new device, choose Recover Account, and enter your Secret Key followed by your primary password. Your vault decrypts and syncs.
Scanning the QR code on your Emergency Kit fills in all of it at once.
You are travelling and need one password now
If you carry a copy of the Premium Emergency Kit, look the account up and type the password by hand. If the account uses two-factor codes, the printed TOTP secret can be entered into any authenticator app to generate working codes.
Otherwise, recover the account on a borrowed device with your Secret Key and password, then sign out of ZZPass before you hand it back.
Someone else needs access and you cannot give it
This is what Emergency Access is for, and it only works if you set it up beforehand. Your trusted contact requests access, waits out the delay, and then receives your vault. You are notified the moment they ask, so a request made while you are simply on holiday can be turned down.
Access covers everything in your vault rather than a chosen subset, and you decide whether they get read-only or read and write. Set it up →
You want to leave something behind
A TimeCapsule holds encrypted notes that open on a date you choose, or after a period of silence from you. Instructions for your family, an explanation, a letter to your own future self.
It is not a substitute for Emergency Access. One delivers a message, the other delivers your vault. How TimeCapsules work →
Every route back into your account is designed so that ZZPass cannot walk it on your behalf, and cannot be compelled to.
Your encryption key is derived on your device from your primary password and your Secret Key. We store neither. There is no copy to hand over, subpoena, or leak.
Biometric recovery uses Face ID or Touch ID on a device you already control. It gives ZZPass no new ability to reset your password or read your vault.
Your primary password is required and verified before every print. Biometric unlock alone will not do it, and there is no remember for 24 hours.
When a trusted contact asks for access, you are notified immediately and the delay you configured has to elapse. You can reject the request throughout.
The Emergency Kit is built on your device and sent to your own printer. Nothing is uploaded to ZZPass or to anyone else along the way.
The server components are open source, so the claims on this page can be checked rather than taken at face value. Read the security model →
A password manager that could rescue you from anything would also be one that could be forced to hand your vault to somebody else. These are the trade-offs, stated plainly.
The two things that matter most, biometric recovery and a printed account kit, cost nothing.
RELATED HELPAccount recoveryEmergency Kit helpEnd-to-end encryption