PrivacyPick
Google Password Manager logo

Google Password Manager

5.3
out of 10
Visit Google Password Manager →
EncryptionGoogle-held key by default
HostingCloud
Free TierFree tier
OwnerGoogle LLC
PasskeysStores + unlocks
Telemetryopt-out
Established2015
WindowsmacOSLinuxAndroidiOS

Published October 7, 2026By Juan Martinez

In This Article

Google Password Manager is the password and passkey store built into Chrome, Android and every Google Account, which means most people already have it running before they ever choose a password manager. Its standout trait is reach: it fills passwords in Chrome on every desktop and mobile platform and in Android apps, it costs nothing, and the passkeys it holds are end-to-end encrypted. The trade-off sits in the default setup for passwords, where the encryption key lives in your Google Account, and in the company running the service, whose privacy policy covers activity data across all of its products. It is reviewed here on the same scale as the rest of the section, as a baseline for comparison rather than a recommendation.

Security

Passwords and passkeys follow two different models, and the difference matters. For passwords, Google’s help pages say they are stored behind Google’s security with encryption, but by default the key that unlocks them is held in your Google Account. Google offers an opt-in layer called on-device encryption: once it is set up, passwords can only be unlocked on your own device with your Google password or the device’s screen lock, and Google states that no one besides you can access them. Google says it will eventually set this up for everyone, but today it is optional.

On-device encryption has a hard edge. Once it is turned on, it cannot be removed. If you lose access to the key, the only way back is a reset that deletes every saved password, and Google’s own page warns that “you could lose your passwords and passkeys too.” That is the cost of holding your own key: nobody else can unlock the vault, and nobody else can recover it.

Passkeys do not depend on that switch. Google’s developer documentation states that passkeys created in Google Password Manager are synchronized and end-to-end encrypted, and its iOS launch post says they “can’t be accessed by anyone. Not even Google.” Unlocking synced passkeys on a new device takes the Google Account sign-in plus either the screen lock of an Android device or a Google Password Manager PIN that Chrome asks you to create on desktop. That is a separate mechanism from the default for passwords, so the same vault can hold passkeys Google cannot read alongside passwords whose key Google holds.

Password Checkup, the breach check, encrypts your credentials on the device with a secret key known only to that device before comparing them against an encrypted list of breached data. Google states that it never learns your usernames or passwords during the check.

There is no separate unlock factor for the manager itself: access rides on the Google Account and the device. The one reliability failure on record is from July 2024. Google’s incident dashboard logs a Chrome incident from 22:36 UTC on 24 July to 16:27 UTC on 25 July. Roughly 2% of Windows users who upgraded to Chrome 127 could not reach their saved passwords for about 17 hours and 51 minutes, according to reports; Google gave the cause as “a change in product behavior without proper feature guard”, and said user data was not lost. That was an outage, not a breach.

Privacy & Trust

The controller named in Google’s privacy policy is Google LLC of Mountain View, California. The password manager is a feature of the Google Account rather than a separate product, so it sits under the same policy as everything else Google runs. That policy lists the activity data Google collects across its services, including Chrome browsing history synced with your Google Account. The vault contents are one question; what the surrounding account reports about you is another, and the second is where the score is lost. The wider argument is in our explainer on relying on Chrome’s built-in manager.

The code is partly open source. The password-manager component is part of the public Chromium source tree, but the sync service behind it and the builds Google actually ships are not published. We found no public independent audit of the vault or its sync service.

Chrome sends usage statistics and crash reports by default; Google’s help page says this telemetry can be turned off in settings. The Google Play listing’s data-safety section reports no data collected or shared, but that label describes the shortcut app, not the service it opens.

Features

The core set covers passwords and passkeys: creating, storing, syncing and autofilling both, with a prompt to create a passkey when you sign in to a site with a saved password. Password Checkup flags passwords exposed in a data breach and those that are weak, and compromise warnings appear on Android, ChromeOS, iOS, Windows, macOS and Linux.

You can add passwords by hand, export them from settings, and require Windows Hello or the device screen lock before a password is filled. Sharing works only with members of a Google family group. On Android 14 and later, you can choose a different passkey provider entirely. Everything syncs across devices signed in to the same Google Account.

Usability & Platforms

For most users there is nothing to install. Google describes the manager as built into Chrome on all platforms and into every Android app, and sync follows the Google Account you are already signed in to. On iPhone and iPad, Chrome has to be set as the autofill provider, and passkeys in Chrome need iOS 17 or later. In other browsers the vault is reachable at passwords.google.com, which works but means visiting a web page rather than getting autofill. If you use Chrome without signing in, passwords stay local on that device and do not sync.

The Google Play listing shows a 4.4 rating from about 16,000 reviews, a reputation signal rather than a measure of security.

Price & Value

It is free. Google documents no cap on items or devices, and there is no paid tier. Price & Value is scored on money alone; the cost in data is counted under Privacy & Trust.

Pros and Cons

  • Free, with no item or device cap documented
  • Already built into Chrome on every platform and into Android apps, with sync through an existing Google Account
  • Passkeys are end-to-end encrypted and sync across Windows, macOS, Linux, ChromeOS, Android and iOS
  • Password Checkup encrypts credentials on the device before comparing them with breach data
  • Optional on-device encryption keeps password keys with you only
  • By default the key for saved passwords is held in your Google Account
  • On-device encryption is opt-in, cannot be removed, and losing the key means deleting every saved password
  • Google's privacy policy covers activity data across its products, including synced Chrome history
  • Sync service and shipped builds are not published, and no public independent audit was found
  • Sharing limited to a Google family group; outside Chrome and Android the vault is a web page
  • A Chrome 127 bug in July 2024 left some Windows users without their passwords for about 18 hours

Our Rating

  • Security5.5/10

    Passkeys are end-to-end encrypted by default, and on-device encryption is available for passwords, but for passwords it is opt-in and the default key sits in the Google Account; no vault-unlock factor of its own, and a 2024 Chrome bug made saved passwords inaccessible for about 18 hours for some Windows users.

  • Privacy & Trust1.5/10

    No public independent audit was found, the sync service is unpublished, and Google's privacy policy covers synced Chrome history among the activity data collected across its products; the optional on-device encryption and the end-to-end passkeys are the only offsets.

  • Features5.5/10

    Passwords, passkeys, breach and weak-password checks and sharing within a Google family group, but sharing is limited to a Google family group and the whole experience is centred on Chrome and Android.

  • Usability & Platforms8.5/10

    Already built into Chrome and Android with sync through an existing Google Account, but outside Chrome and Android it means signing in at passwords.google.com, and on iOS it works best with Chrome set as the autofill provider.

  • Price & Value9.0/10

    Scored on money only: free, with no item or device cap. The cost in data is carried by Privacy & Trust, not counted twice here.

Overall5.3/10

Security 30% · Privacy & Trust 25% · Features 20% · Usability 15% · Price 10%

See our rating methodology →

Ready to try Google Password Manager?

Visit Google Password Manager →

Last updated: October 7, 2026By Juan Martinez