First, the part that matters most: use a password manager. Which one is a detail. Using none is the real problem, and the built-in ones cost nothing, are already on your phone, and work well.
If you are choosing, though, understand the choice, because this vault opens all the others.
Who can open the box?
People use the word “encryption” loosely. The difference that matters is simple: who holds the key.
If the provider holds it, your data is scrambled on their disks. That’s useful if a drive is stolen or a data centre is broken into. But they can still open the box: for support, for scanning, or if the law forces them to.
If only you hold the key, they are storing a sealed box they can’t open. Nobody can be forced to hand over contents they don’t have.
they hold the key
Encrypted on their disks
Genuinely useful. Protects you if a drive is stolen.
They can open it
For support, for scanning, or if the law forces them to.
A break-in reaches the contents
Because the key is kept in the same place as the box.
only you hold the key
They store a sealed box
And have no way of seeing what is inside it.
Nobody can be made to open it
You cannot hand over contents you do not have.
Lose the key, lose the contents
This is the real trade, and it falls entirely on you.
For password managers, the good news is that all the serious options, including Google’s and Apple’s, are built so the provider can’t read your passwords. This is one area the industry got right.
So the real question isn’t “can they read it”. It’s everything around that.
What the built-in options cost you
They tie you to one company. Apple’s works beautifully on Apple devices and awkwardly everywhere else. Google’s works best in Chrome. In a mixed household, as most are, you’ll keep hitting snags, and that pushes people back to bad habits.
Your vault also depends on that one account. If your Google or Apple account is locked, disabled or lost, the thing that opens everything else goes with it. Account lockouts are rare, but a disaster when they happen, and often there’s no person you can appeal to.
You also have to live with their decisions: features, sharing, and what happens on a device they stop supporting. That’s fine until it isn’t. And sharing between Apple and Google barely works, which is where a lot of households give up and start messaging passwords to each other. That’s worse than anything else on this page.
What a self-hosted vault changes
Running your own changes three things. Vaultwarden is the usual choice, and it works with the standard Bitwarden apps on every device.
The vault is yours. It runs on a machine you chose, in a country you chose. No outside company can lock you out of it, because no outside company is involved.
It works the same everywhere. There are apps for every phone and browser, and none of them care whether you use Apple, Google or something else. In a mixed household that’s often the real reason people switch.
And sharing actually works: household vaults and shared logins for shared accounts, without anyone texting a password around.
Because it’s open source (the code is public), anyone can check how it works. That’s a weaker point than people sometimes make, since most of us will never read the code. But a great many people have, and problems get found and made public rather than kept quiet.
The part that should worry you
You are now the recovery process.
Lose the master password and the recovery details, and the vault is gone. Not “gone until support helps”: gone for good, by design. That’s the same feature that stops anyone else opening it. Lose the server with no backup and the result is the same.
This is the whole trade, and anyone who glosses over it is trying to sell you something. Complete control means complete responsibility, and for some households the honest answer is that a big company’s recovery process is worth more than the independence.
If you do run your own, do these
- Write the master password on paper and keep it with your important documents. Not in a file. On paper. It sounds wrong but it’s right: the realistic risk to your vault is you forgetting, not a burglar searching your filing cabinet for a password.
- Save the recovery details the same way, in a separate place.
- Back up the vault automatically, somewhere other than the machine it runs on.
- Test a restore. Until you’ve restored from a backup, you don’t know it works.
- Tell one other person where those things are, in case anyone ever needs to deal with your accounts for you.
The straight answer
Using nothing is the real emergency. Fix that today with whatever’s already on your phone.
Google’s or Apple’s built-in manager is a good choice if your household uses one company’s devices and you’d rather someone else handled recovery. That’s a sensible, reasonable choice.
Your own vault is the better answer if you use a mix of devices, want household sharing that actually works, or are genuinely uneasy that one account you don’t control holds the keys to everything else.
The deciding question isn’t really about security, since all three encrypt properly. It’s who you want to have the power to lock you out: a company, or only you. Both answers are reasonable. Just make sure it’s a choice you’ve actually made.