Proton

Proton Account recovery explained

Lecture
11 minutes
Catégorie
Password reset

It’s extremely important to secure your Proton Account with multiple recovery methods. If you lose your password without having a recovery method set up, you risk permanently losing access to your account and data.

You can set up multiple recovery methods in your account settings. At a minimum, we recommend enabling your recovery phrase, an extra password reset method, and an extra data recovery(nouvelle fenêtre) method.

How it works

For security reasons, we don’t keep user passwords on our systems. But this means we can’t reset your password for you if it’s lost. To avoid being locked out permanently, you’ll need to have access to a recovery method.

Recovery methods

A recovery method is a secure alternative way to regain control of your account. Because Proton doesn’t know your password and can’t read your data, recovery methods must be set up and kept by the account holder (you). How to set up a recovery method

Not all recovery methods have the same function

There are two steps to recovering a Proton Account:

  1. Password reset: Lets you set a new password without knowing the old one.
  2. Data recovery: Decrypts the data on your account so you can read and interact with it again.

Your recovery phrase covers both steps. But most other recovery methods only allow one or the other:

  • If you have a password reset method and no data recovery method, you’ll lose access to everything that was on your account before the password reset (unless you remember your old password).
  • If you have a data recovery method but no password reset method, you won’t be able to get back into your account at all.

That’s why it’s so important to have multiple recovery methods available.

At a minimum, we recommend enabling your recovery phrase and two backup methods — one for password reset, and another for data recovery.

Proton’s recovery methods

DescriptionPassword reset?Data recovery?Notes
Recovery phrase12-digit sequence of words that you can download, print, or write down for safekeepingYesYesContained in the Recovery Kit provided during account creation. In most cases, this is the most convenient way to recover your account.
Signed-in resetRecovery feature that lets you reset a lost password from an active sessionYesYes*Only works if you’re signed in to Proton. This should not be your only recovery method.
Password reset via emailVerifies your identity using your secondary email addressYesNoCombine with a data recovery method.
Password reset via mobile phoneVerifies your identity using your phone numberYesNoCombine with a data recovery method.
Device data backupStores an encrypted backup keychain (recovery file) in your browser’s web storageNoYesPreviously known as Device-based recovery and Device data recovery.
Combine with a password reset method.
Recovery fileEncrypted backup keychain stored in a file that you can download and save to your deviceNoYesCombine with a password reset method.

*Technically, signed-in reset prevents your data from being locked in the first place.

How to view and enable recovery methods

These instructions explain how to enable or disable a recovery method in your account settings. However, you can also use our account safety review tool to turn on recommended recovery methods, and check if you’ve enabled enough recovery options to recover your account.

  1. Sign in to account.proton.me. Go to Settings ⚙️ → All settings.

If you’re locked out, skip to how to recover your account

  1. Select Recovery from the left sidebar.

At the top of the page, you’ll see your account safety review. This tells you if your account and data are sufficiently protected by the recovery methods you currently have turned on.

Scroll down to view the recovery methods available for your account (under Account recovery, Data recovery, and Password reset).

  1. Use the toggles to enable or disable your preferred recovery methods. For detailed instructions, we have dedicated setup and usage guides for each recovery method.

Enable at least one password reset method, and one data recovery method. Once you’re done, check the account safety review panel again. It should say “Your account and data can be recovered“.

How to recover your account

If you lose your password, there are a few different ways to regain control of your account — depending on which recovery methods you have enabled. Here’s what to do:

  1. Check if you’re signed in on another device

If you have an active session on another device, you can use Signed-in reset to reset your password.

Signed-in reset is available on our web apps — if you’re signed in somewhere else, you can transfer your session to a web app with our QR-code sign-in feature.

  1. Use your recovery phrase

If you’re completely locked out, your recovery phrase is usually the most convenient way to get back into your account.

It lets you reset your password and recover your data at the same time — no need for two separate recovery methods.

Your recovery phrase is contained in your Recovery Kit, which you may have been prompted to download and save when you created your account.

  1. Use a password reset method, then recover your data

If you can’t use signed-in reset or your recovery phrase, you’ll need to have two separate recovery methods enabled — one password reset method, and one data recovery method.

Password reset methods

Data recovery methods

After recovering your account

Some recovery methods can only be used once. Once you’ve recovered your account, you should regenerate any recovery methods that can’t be used a second time.

  1. Open your account recovery settings (Settings → All settings → Recovery)
  2. Scroll to the recovery method (or methods) you used.

If your recovery method can’t be used again, you’ll see a notification saying Your <recovery method> is outdated.

  1. Click Update recovery method, and follow the steps to update your recovery method.

Account recovery for Proton organization members

If you’re a non-private user in a Proton for Business or Proton Visionary organization, you won’t be able to use recovery methods. Contact your administrator for help resetting your password.

Lost two-factor authentication (2FA)

If your security key or authenticator app is lost or not working, you can sign in with a recovery code (provided when you set up 2FA) or another recovery method.

Account recovery and two-password mode

All recovery methods work for two-password mode — even if you lose both passwords.

A password reset automatically reverts your account to one-password mode. Once you’re back into your account, you can re-enable two-password mode in Settings.