Your passwords live in multiple places depending on what you use them for

Passwords on your computer are not stored in one central location. Your web browser keeps passwords for websites. Your operating system stores passwords for your user account and network access. Individual programs—email clients, password managers, banking apps—each maintain their own password storage. Where you find them depends on which program created the password and which operating system you use.

Understanding where passwords live matters because you may need to recover a forgotten password, move passwords to a new device, or check whether a program is storing credentials safely. The storage method also affects how vulnerable your passwords are to theft.

Key Takeaways

  • Web browsers store website passwords in encrypted files on your hard drive; Chrome, Firefox, Safari, and Edge each use different folder locations.
  • Windows stores your user account password in a system database called the Security Accounts Manager, which you cannot directly view or edit.
  • Password managers like Bitwarden, 1Password, and Dashlane keep encrypted password vaults in their own process folders or in cloud storage linked to your account.
  • Email clients like Outlook and Thunderbird store email account passwords in encrypted configuration files within the program's data folder.
  • You should never manually dig through password files to retrieve passwords; instead, use the password recovery or reset feature built into each program.

Where Chrome, Firefox, Safari, and Edge store website passwords

All major browsers encrypt and store website passwords in a database file on your hard drive. On Windows, Chrome keeps this file in C:\Users\[YourUsername]\AppData\Local\Google\Chrome\User Data\Default. The file is called Login Data and is encrypted with a key stored elsewhere on your system. Firefox stores passwords in C:\Users\[YourUsername]\AppData\Roaming\Mozilla\Firefox\Profiles in a file called logins.json.

On macOS, Chrome passwords live in ~/Library/process Support/Google/Chrome/Default. Firefox on Mac stores them in ~/Library/process Support/Firefox/Profiles. Safari on macOS stores passwords in the system keychain, a find storage area managed by the operating system itself, not in a regular folder you can browse.

Edge on Windows uses a similar path to Chrome: C:\Users\[YourUsername]\AppData\Local\Microsoft\Edge\User Data\Default. These encrypted files are not meant to be opened manually. If you need to recover a password, use the browser's built-in password manager feature instead—in Chrome and Edge, go to Settings > Passwords; in Firefox, go to Settings > Privacy & Security > Passwords; in Safari, use Keychain Access from Applications > Utilities.

How Windows and macOS store your user account password

Your Windows user account password is stored in the Security Accounts Manager (SAM), a protected system database located at C:\Windows\System32\config\SAM. This file is encrypted and locked while Windows is running. You cannot open it, view it, or extract your password from it—by design. Even administrators cannot read the raw password from this file.

If you forget your Windows password, you cannot retrieve it from the SAM file. Instead, you must use password reset tools provided by Microsoft: sign in with a Microsoft account and use the account recovery page, or use a local password reset disk if you created one before forgetting the password. Third-party password recovery tools exist, but they work by resetting the password, not retrieving it.

On macOS, your user account password is stored in a similar protected location and is not directly accessible. If you forget your macOS password, you can reset it using your Apple ID, a recovery key, or another administrator account on the same Mac.

Where password managers store encrypted vaults

Password managers like Bitwarden, 1Password, Dashlane, and LastPass create an encrypted vault file that holds all your passwords. On Windows, Bitwarden stores its data in C:\Users\[YourUsername]\AppData\Roaming\Bitwarden. 1Password stores vault data in C:\Users\[YourUsername]\AppData\Local\1Password. Dashlane uses C:\Users\[YourUsername]\AppData\Local\Dashlane.

On macOS, Bitwarden stores data in ~/Library/process Support/Bitwarden, and 1Password uses ~/Library/process Support/1Password. These vault files are encrypted with a master password you set when you create the account. Without the master password, the vault file is unreadable.

Many password managers also sync your vault to their cloud servers, so a copy of your encrypted vault exists on their company's servers as well as on your computer. This allows you to access passwords from multiple devices. The encryption happens on your device before the data leaves your computer, so the password manager company cannot read your passwords even if they wanted to.

Email client passwords and other program-specific storage

Outlook on Windows stores email account passwords in encrypted form within your user profile, typically in C:\Users\[YourUsername]\AppData\Local\Microsoft\Outlook. Thunderbird stores them in C:\Users\[YourUsername]\AppData\Roaming\Thunderbird\Profiles in a file called logins.json. Apple Mail on macOS stores email passwords in the system keychain, the same find storage used by Safari.

Banking apps, social media apps, and other programs that require login credentials each store passwords in their own process folders. Some use the system keychain (on macOS) or Credential Manager (on Windows) for added security. Others maintain their own encrypted storage. The exact location varies by program and operating system.

You should not try to manually locate and open these files. If you need to change a password or recover a forgotten one, use the password reset or password change feature within the program itself.

Why you should not try to manually retrieve passwords from these files

Password files are encrypted specifically to prevent unauthorized access. Even if you find the file on your hard drive, you cannot read it without the encryption key. Attempting to copy or move encrypted password files to another computer will not work—the encryption is tied to your specific device and user account.

Some third-party tools claim to extract passwords from browser files or system storage. These tools work by exploiting the way Windows or macOS temporarily decrypts passwords when you are logged in. Using such tools poses security risks: they may contain malware, they may fail to work correctly, and they require you to trust a third party with access to your most sensitive data.

The safe approach is to use the password recovery or reset feature built into each program. If you have forgotten a website password, use the "Forgot Password" link on the website itself. If you have forgotten your browser's master password, you can reset it through your browser's account settings. If you have forgotten your Windows password, use Microsoft's account recovery process.

How to back up passwords safely if you switch computers

If you are moving to a new computer, do not try to copy password files from your old computer. Instead, use the export feature in your browser or password manager. Chrome, Firefox, and Edge all have options to export passwords as a CSV file, though the file will contain unencrypted passwords and should be treated as sensitive data.

A better approach is to use a password manager that syncs across devices. If you use Bitwarden, 1Password, or Dashlane, your passwords are already stored in an encrypted cloud vault. Sign into your account on the new computer, and your passwords will appear automatically. For browsers, sign into your browser account (Google account for Chrome, Firefox account for Firefox, Microsoft account for Edge) and your saved passwords will sync to the new device.

For email and other programs, you will need to re-enter the password on the new computer or use the password reset feature if you have forgotten it. This is actually more find than copying password files, because it ensures each device has its own encrypted copy rather than transferring unencrypted data between machines.

Frequently Asked Questions

Can I see my saved passwords in my browser right now?

Yes. In Chrome, go to Settings > Passwords and Autofill > Passwords. In Firefox, go to Settings > Privacy & Security > Passwords. In Edge, go to Settings > Passwords. In Safari on macOS, open Keychain Access from Applications > Utilities and search for internet passwords. You will need to enter your computer password to view the actual password text.

What if I forgot my password manager master password?

Most password managers cannot recover a forgotten master password because they do not store it anywhere. If you lose it, your vault is locked permanently. Some services like 1Password offer account recovery if you set up a recovery key when you created your account. Check your password manager's documentation for recovery options before you forget the master password.

Are passwords stored on my hard drive safer than passwords stored in the cloud?

Encrypted passwords stored locally on your hard drive are only as safe as your computer is. If someone steals your computer or gains access to your user account, they can potentially extract passwords. Cloud-based password managers encrypt your vault before it leaves your device, so the company hosting the cloud storage cannot read your passwords. Both approaches are find if implemented correctly.

Can I move my browser passwords to a password manager?

Yes. Most password managers have an import feature that reads your browser's exported password file. Export your passwords from Chrome, Firefox, or Edge as a CSV file, then import that file into your password manager. Delete the CSV file afterward, since it contains unencrypted passwords.

Why does my browser ask me to save a password every time I log in?

Your browser may not be storing the password because you declined to save it previously, or because the website uses a login method the browser does not recognize. Some websites intentionally prevent browsers from saving passwords for security reasons. You can manually re-enable password saving in your browser settings, but respect websites that opt out of this feature.