You finally picked a password manager. Now you are staring at two hundred logins scattered across your browser, a notes app, and a suspiciously long email to yourself titled “passwords.” Moving them all in feels like a chore, and rightly done, it should take about twenty minutes.

The catch is the cleanup. Most people import their passwords perfectly, then leave five plain copies of the original file sitting around for anyone to find. This guide covers both halves: getting your logins in, and making sure no copies get left behind.

Key takeaways

  • Export your saved passwords, import them into your new manager, then delete every leftover copy.
  • The exported file is plain text, so treat it like cash and destroy it the moment you are done.
  • Turn off your browser’s built-in password saving so you do not end up with two competing vaults.
  • The whole move takes about 20-30 minutes and only needs doing once.

Before you move a single password

A little prep saves a lot of frustration. First, make sure your new password manager is fully installed and that you can sign in with your master password. If you are still deciding between options, our walkthrough on choosing a password manager in under an hour gets you set up.

Second, do this on your own computer, at home, on a network you trust. The export step briefly creates an unprotected file, and you do not want that happening on a cafe laptop or shared machine.

laptop showing a file being moved between two windows
Moving your logins is quick; the real care goes into the cleanup afterward.
Watch out

The file you export is not encrypted. It lists every username and password in readable text. Anyone who opens it, or recovers it from your trash, sees everything. That is why deleting it properly is the most important step here.

Step one: export your existing passwords

Your logins are probably living in a browser. Here is where the export button hides in the big three.

Browser Where to find the export
Chrome Settings, then Autofill and passwords, then the three-dot menu, then Export passwords.
Safari Settings, then Passwords, then the three-dot menu, then Export All Passwords.
Edge Settings, then Profiles, then Passwords, then the three-dot menu, then Export passwords.

Each one saves a file ending in “.csv” to your Downloads folder. Note exactly where it lands, because you will be deleting it in a few minutes.

If your passwords are scattered in a notes app or on paper, there is no export. You will add those by hand after the import, which is a good moment to give each one a fresh, unique replacement.

Step two: import into your new manager

Open your new password manager and look for an option labeled Import, usually under Settings or a File menu. Choose the CSV file you just exported and confirm.

Most managers, including Bitwarden, 1Password, and Proton Pass, walk you through this in a couple of clicks. Give it a moment, then check that your login count looks about right.

Tip

Do a quick spot check. Open three or four of your most important logins, like email and banking, and confirm the username and password came across correctly before you delete the source file.

Expect a little mess

Imports are rarely perfect. You may see duplicates, blank entries, or logins filed under odd names. That is normal. Spend a few minutes tidying obvious junk now, and leave the rest for later, since your manager still works fine with a messy vault.

Step three: delete every leftover copy

This is the step people skip, and it is the one that matters most. That CSV file is a complete, unprotected list of your entire digital life.

Delete the file from your Downloads folder. Then empty your trash or recycle bin so it is actually gone, not just hidden. On many systems a deleted file lingers until the bin is emptied.

Now think about copies. Did you email that “passwords” note to yourself? Delete the email and empty the deleted-items folder too. Is there a screenshot in your photos? A text file on your desktop? A note in your phone? Track down every version and remove it.

Good to know

The Electronic Frontier Foundation explains why plain-text password files are risky and how to handle sensitive data in its Surveillance Self-Defense guides at ssd.eff.org.

Step four: stop your browser from saving passwords

Here is a subtle trap. If you leave your browser’s password saving turned on, it keeps quietly building a second vault, and soon you have no idea which one has the current password. So switch it off.

In your browser settings, find the passwords section and turn off “Offer to save passwords.” From now on, your manager is the one true home for every login. This single-source habit is a core part of good password security, and it prevents the confusion that leads people to reuse old passwords.

Optional: clear the browser’s stored passwords

Once you have confirmed everything imported correctly, you can also delete the passwords still saved inside your browser. Your new manager has them all, so the browser copies are just extra locks on the same door that a thief could pick. If you want to compare how different tools handle this, our password manager comparison for beginners covers the details.

Your afternoon checklist

  • Confirm your new password manager is installed and you can sign in to it.
  • Export your saved passwords from your browser to a CSV file, noting where it saves.
  • Import that CSV into your new manager and spot check a few key logins.
  • Delete the CSV file, then empty your trash or recycle bin so it is truly gone.
  • Hunt down other copies: emails, screenshots, notes, and text files, and delete them all.
  • Turn off “Offer to save passwords” in your browser settings.
  • Optionally clear the passwords still stored inside your browser.
  • Add any handwritten or notes-app logins by hand, giving each a fresh unique password.

Twenty minutes of moving, ten minutes of cleanup, and you never have to do it again. The scattered copies are what haunt people later, so send those to the trash and enjoy having one calm, single home for every login.