The honest, zero-knowledge answer — and how LegendPass makes it less likely to matter.
With a zero-knowledge password manager like LegendPass, if you forget your master password there is no way for us to reset it for you — the decryption key is derived from that password and never stored on our servers. That is the deliberate cost of a design where nobody but you can open your vault. The fix is prevention: choose a memorable master password, and rely on on-device biometrics for daily unlock.
The whole point of zero-knowledge encryption is that your data is encrypted on your device with a key only you hold. If we could reset your master password, we would also be able to read your vault — and so would anyone who compromised us. LegendPass has no recovery backdoor by design. This is the same tradeoff every serious zero-knowledge manager (1Password, Bitwarden) makes.
If you have a zero-knowledge manager, use any recovery kit, emergency sheet, or locally stored backup you created at setup. In LegendPass, attaching your daily unlock to on-device biometrics means a forgotten master password is far less disruptive, because your biometrics already open the vault on your trusted devices.
No — and that's a security feature, not a bug. Because we never store your master password or the key it derives, neither we nor an attacker can ever unlock your vault. Keep a backup of your master password.
No. With LegendPass you unlock with biometrics — face, fingerprint, palmprint, hand geometry, or gesture — so the master password is mostly a setup and emergency tool.
Physically storing it in a secure place is far safer than reusing passwords online. Just keep it out of screenshots, notes apps, and email.
Your device's local biometrics can still unlock the vault, since the key is derived on-device. You can then set a new master password from inside the app.
Unlock with your biometrics so a forgotten master password is rarely a problem.