Disclosure — read this one, it matters here: our top recommendation on this page is Bitwarden, and Bitwarden pays affiliates nothing at all, by policy. We knew that before we wrote a word, and it is still the default answer for most people reading this. Every other link on this page — Proton Pass, 1Password, NordPass — is also a plain link that earns us nothing today; we have no affiliate relationship with any password manager as of this writing. Elsewhere on this site we do use affiliate links (for Beehiiv and systeme.io) and we label them every time. Here, there is nothing to label.
Privacy & security tools
Password Managers Compared (2026): Proton Pass vs Bitwarden vs 1Password vs NordPass
Most "best password manager" pages have a tell: the tool at the top is the one with the biggest affiliate payout, and the free open-source option that would serve most readers perfectly well is either missing or filed under "budget pick" near the bottom. So let's start where an honest version has to start. Bitwarden is the answer for most people, it has a free tier that is genuinely sufficient, and it pays us nothing. If you read no further, install it and move on with your day.
The rest of this page is about the narrower cases where something else wins — because they do exist. If you already live inside Proton's ecosystem, if you're setting up a family or small team where polish decides whether people actually use the thing, or if you bought a Nord bundle and are wondering whether to bother with the included manager, the answer changes.
The 30-second version
- Most people, any budget → Bitwarden. Free tier is enough, open-source, audited, boring in the best way.
- Already using Proton Mail or Proton VPN → Proton Pass. One account, Swiss jurisdiction, one bill.
- A family or small team where adoption is the hard part → 1Password. The polish is the feature; there is no free tier.
- You already pay for a Nord bundle → NordPass is fine and already paid for. Don't buy it standalone over the others.
- The worst option is the one you don't set up. Any of these four beats the password you've reused since 2019.
Why a password manager beats what you're doing now
The case isn't really about hackers cracking your password. It's about reuse. Companies get breached constantly, and when they do, the leaked email-and-password pairs get fed into automated login attempts against every other service on the internet. This is called credential stuffing, and it's why one bad breach at a forum you forgot you joined turns into someone reading your email. Your password doesn't have to be weak. It just has to be the same one twice.
A password manager fixes this by making every password different and none of them memorable — which is fine, because you were never going to remember them anyway. You remember one master password. The tool remembers the other 200. That's the entire pitch, and it's a good one.
The secondary benefit that sneaks up on people: a manager will audit what you already have. Point it at your existing logins and it will tell you which passwords are reused, which are weak, and which have shown up in known breaches. That first audit is usually a bad afternoon and then a permanently better situation.
The honest caveat: a password manager is a single point of failure, and pretending otherwise would be dishonest. If someone gets your master password and your second factor, they get everything. The reason this trade is still overwhelmingly worth making is that the realistic alternative — reuse across dozens of sites of wildly varying security — is a single point of failure too, just one you don't control and can't audit.
Pick by what you actually need
| What's true about you | Best fit | Runner-up | Why |
|---|---|---|---|
| "I just need to stop reusing passwords, cheaply" | Bitwarden | Proton Pass | Free tier covers unlimited passwords and syncs across your devices |
| "I want open-source I can verify, not a promise" | Bitwarden | Proton Pass | Both publish client source; Bitwarden has the longer track record of independent audits |
| "I already pay for Proton Mail or Proton VPN" | Proton Pass | Bitwarden | It's bundled into plans you may already hold — one login, one company, Swiss jurisdiction |
| "I'm setting this up for a partner or kids who will give up if it's fiddly" | 1Password | Proton Pass | The most forgiving onboarding and sharing model of the four |
| "Small team, needs to look professional to non-technical staff" | 1Password | Bitwarden | Polish drives adoption; Bitwarden's org tier is cheaper but plainer |
| "I already bought a Nord bundle" | NordPass | — | It's already paid for. Use it rather than run nothing. |
| "I want to self-host my own vault" | Bitwarden | — | The only one of the four with a real self-hosting story |
| "I care most about who can be legally compelled to hand over data" | Proton Pass | Bitwarden | Swiss-based, with a published transparency record — read it yourself before deciding |
Feature sets and free-tier limits change often. Every one of these is a 2026 snapshot — check the tool's own pricing page before you commit to anything.
1. Bitwarden — the default, and it pays us nothing Top pick, $0 to us
Bitwarden is open-source, has commissioned independent security audits, offers a free tier that includes unlimited stored passwords across unlimited devices, and can be self-hosted if you're the kind of person who wants that. The paid personal tier is inexpensive and mostly buys convenience and advanced two-factor options rather than core security. For the overwhelming majority of people asking "which password manager should I use," this is the end of the question.
It's worth saying plainly why this recommendation is unusual: Bitwarden runs no affiliate program. There is no commission, no bounty, no revenue share — not for us, not for anyone. That's a deliberate policy choice on their part, and it means Bitwarden is systematically under-recommended across the entire review internet relative to how good it is. We think that's worth correcting, even though correcting it costs us money.
The honest part: the interface is plainer than 1Password's, and that's not just aesthetics — the setup flow, the sharing UI and the mobile experience all feel a step behind. If you're the technical person in your household installing this for someone who is not, expect to answer more questions than you would with 1Password. Browser extension autofill occasionally needs a manual nudge on awkward login forms. None of this is a security concern; it's a "will my dad keep using it" concern, and that's a real concern.
Look at Bitwarden → Plain link — we currently earn nothing from this link. Bitwarden has no affiliate program at all, and it's still our top pick.
2. Proton Pass — if you're already in the Proton ecosystem
Proton Pass is the password manager inside the Proton suite — the same company as Proton Mail, Proton VPN and Proton Drive, based in Switzerland, with open-source clients and a long-standing privacy-first positioning. If you already pay Proton for something else, Pass may be included in your plan or cost very little to add, and it collapses several accounts into one. That consolidation is worth more than it sounds: fewer vendors is fewer breach surfaces and fewer renewal dates to track.
The email-alias feature is the genuinely differentiated bit. Rather than handing every site your real address, you can generate a per-site alias — which means when a site leaks, you know exactly who leaked it, and you can kill that alias without changing your actual email.
The honest part: Pass is the youngest product in Proton's lineup and it shows in small ways — fewer power-user features and a smaller third-party integration story than 1Password or Bitwarden. And if you're not already a Proton customer, the ecosystem argument evaporates, at which point Bitwarden does the same job for less. Buying into a suite also means one company holds your email, your VPN and your passwords, which is convenient right up until you want to leave. Our Proton VPN review covers the wider suite and the same trade-off.
Look at Proton Pass → Plain link — we currently earn nothing from this link.
3. 1Password — the one non-technical people keep using
1Password is the most polished product in this category and has been for years. Travel mode, the sharing model, the family setup flow, the way it handles recovery for a household — these are solved problems here in a way they aren't elsewhere. If your actual obstacle is "I need four other humans to adopt this and not complain," 1Password is worth paying for, because a password manager nobody uses protects nobody.
It's also the strongest small-team pick of the four for the same reason: onboarding a non-technical colleague takes minutes rather than a support conversation.
The honest part: there is no free tier. Not a limited one — none. You pay from day one, after a trial, and you keep paying. For a solo person who just wants to stop reusing passwords, that's a hard sell against Bitwarden's free plan doing the same core job. It's also a closed-source product: you're trusting audits and reputation rather than reading the code. That's a perfectly reasonable trust model, but it is a different one from Bitwarden's, and worth naming.
Look at 1Password → Plain link — we currently earn nothing from this link.
4. NordPass — mostly makes sense if you already have the bundle
NordPass comes from the Nord family, which most people meet through NordVPN. It's a competent, clean, modern password manager with the usual feature set, and it's frequently bundled into Nord subscriptions people have already bought. If that's you, use it — a bundled manager you actually turn on beats a better manager you never install.
The honest part: it's the newest of the four and doesn't have the audit history or the years of independent scrutiny that Bitwarden and 1Password have accumulated. In a category where the entire value proposition is trust built slowly, "newer" is a genuine mark against it — not a disqualification, but a reason not to pick it over the others on features alone. Bought standalone, we'd struggle to explain why you'd choose it over Bitwarden free or Proton Pass. Its best argument is bundle economics, and bundle economics are a reason to use something, not a reason to buy it.
Look at NordPass → Plain link — we currently earn nothing from this link.
Briefly: Keeper and Dashlane
Two names you'll see on every other list, with the honest caveats that usually get left off:
- Keeper — a capable product, especially in business and compliance-heavy settings, with a broad enterprise feature set. The caveat we can't ignore: in 2017 Keeper brought legal action against a journalist over reporting on a security vulnerability. The suit was later dropped, but for a security company, how you respond to researchers and reporters is part of the product. We're not telling you not to use it; we are telling you that's on the record and you should weigh it.
- Dashlane — genuinely good autofill, one of the smoothest experiences in the category, and a long history. The caveat is direction of travel: its consumer offering has narrowed over the years while the company has leaned into business plans, and its free tier is far more limited than it once was. If you're picking a tool you intend to keep for a decade, ask where the product is heading, not just where it is.
We're not linking either, because we don't currently have a link worth giving you and we're not going to publish numbers we can't verify. Both are easy to find.
Autofill removes a friction point that causes real lockouts
Here's the part general security guides never cover. If you have ADHD, the password problem isn't only a security problem — it's an executive function problem, and it shows up in specific, expensive ways.
- The lockout spiral. You need to log in, you can't remember which variant you used, you try four, the account locks, and now the ten-minute task is a forty-minute recovery process involving a support email. It is a familiar pattern for anyone whose working memory doesn't reliably hand back what it stored, and each time it costs a chunk of the day and a chunk of morale.
- The abandoned task. A login prompt at the wrong moment is a wall. You went to cancel a subscription, hit the password screen, felt the friction, and closed the tab — and the subscription is still billing you eight months later. Autofill removes the wall before your motivation drains through it.
- The reset loop as a coping strategy. Using "forgot password" as your actual login method every single time is remarkably common. It works, technically. It also burns several minutes and a mail-app context switch each time, which is where the real task goes to die.
How to set it up so it actually sticks: install the browser extension and the phone app on the same day — half-installed is worse than not installed, because you'll hit the machine that doesn't have it and lose faith in the whole system. Turn on biometric unlock so opening the vault is a fingerprint rather than a decision. Then do not attempt to import 200 passwords in one sitting; let the manager save each login as you naturally use it over a few weeks. The big-bang migration is the version that gets abandoned at password 40.
See the full ADHD solopreneur tool stack →Setting it up without losing a weekend
- Pick one and install it everywhere today — browser extension plus phone app. Partial installs are how this fails.
- Create a strong master password you can actually recall. Four or five unrelated words beats a short string of symbols, both for strength and for your ability to type it on a phone at 7am.
- Set up recovery immediately. Recovery code, emergency contact, or recovery key — whatever your tool offers. Print it. Put it somewhere physical. A zero-knowledge vendor genuinely cannot rescue you.
- Turn on two-factor authentication on the vault itself, then on email, then on banking. In that order — your email is the master key to everything else.
- Let it fill up organically. Save logins as you use them for two or three weeks, then run the built-in audit and fix only the reused passwords on accounts that matter. You do not need to fix the 2014 forum.
FAQ
- Is a free password manager actually safe?
- A free tier from a credible vendor is far safer than the alternative most people are actually running, which is a handful of reused passwords. Bitwarden's free plan is open-source, unlimited on password count, and syncs across devices — the paid upgrade buys extras like advanced two-factor options and emergency access, not core security. The unsafe free password manager is the one from a vendor with no published audits and no business model you can point at.
- What happens if I forget my master password?
- In a properly zero-knowledge password manager, the vendor cannot recover it, because they never had your key. That is the security guarantee and the risk in the same sentence. Every tool here offers some recovery mechanism — a recovery code, an emergency-access contact, or an account recovery key — and you should set one up on day one and store it somewhere physical. Writing the master password on paper in a drawer at home is not the worst plan; reusing a weak one so you can remember it is.
- Which password manager is best for ADHD?
- The one whose autofill you will actually accept rather than dismiss. Autofill removes a working-memory task from a moment when you are already mid-task, which is exactly the moment a distractible brain abandons things or triggers a lockout by guessing. In practice that means installing the browser extension and the phone app on the same day, and turning on biometric unlock so the friction of opening the vault is a fingerprint rather than a decision.
- Do you earn commission from these links?
- Not from any tool on this page. Every link here is a plain, non-earning link — we have no affiliate relationship with Bitwarden, Proton, 1Password or NordPass today. Bitwarden in particular pays affiliates nothing by policy and it is still our default recommendation, which is the honest test of whether a comparison like this is worth reading.
- Should I use my browser's built-in password manager instead?
- It is a real improvement over reuse and it is free, so if that is the only thing you will stick with, use it. The trade-offs are portability and scope: browser vaults are awkward to move between ecosystems, cover apps less well than a dedicated tool, and rarely handle secure notes, shared family vaults or passkeys as cleanly. A dedicated manager also makes it easier to audit which of your old passwords are reused or breached.
Bottom line: install Bitwarden unless you have a specific reason not to — it's free, open-source, and pays us nothing, which is exactly why we're comfortable putting it first. Choose Proton Pass if you're already inside Proton. Choose 1Password if adoption by other people is your real problem and you accept there's no free tier. Choose NordPass if it's already in a bundle you own. Then set up recovery on day one, and let the vault fill itself.
A password manager removes one recurring friction point. If friction is the theme of your week rather than the exception, start with our guide to calm productivity when you're overwhelmed.