What documenting means and why it matters for your security

Documenting means keeping a record of your digital accounts, passwords, recovery information, and the devices you own — so you can prove what you have, recover access if something goes wrong, and know what to protect. It is not about writing a diary. It is about creating a paper or digital trail that lets you act fast when you need to.

When your email gets hacked, you need to prove you own it. When you forget a password, you need backup codes. When someone steals your phone, you need to know which accounts were on it. When you die, your family needs to know what to close. Documentation is the difference between "I think I had an account there" and "Here is proof, here is the recovery method, here is what to do next."

Most people keep this information scattered — a password in their head, a recovery code in a drawer, a list of devices nowhere. The goal is to gather it in one place, keep it safe, and update it when things change.

Key Takeaways

  • Create a single record that lists every account you use, where to log in, and how to recover access if you lose the password.
  • Store this record in a password manager (like Bitwarden or 1Password) or a locked document on your computer, never in plain text on your phone.
  • Include recovery codes, backup email addresses, and phone numbers for each account, because passwords alone are not enough.
  • Document your devices — phone, laptop, tablet — with their serial numbers and what accounts are on them, so you know what to lock down if one is stolen.
  • Update your documentation every time you change a password, add a new account, or change your recovery information.

What to document about each account

For every account that matters — email, banking, social media, work, cloud storage — write down the same set of information. You do not need to memorize it, but you need to know where it is.

Start with the basics: the website or app name, your username or email address, and the password. Then add the recovery method: a backup email address, a phone number where you can receive a code, or both. Many accounts let you generate recovery codes — a list of one-time passwords you can use if you lose access to your phone or email. Download these codes and store them with your account record. If the account offers two-factor authentication (a second login step using your phone or an authenticator app), note which method you chose and where the backup codes are.

Add any security questions and their answers if the account uses them. Add the date you created the account and the date you last changed the password. Add notes about what the account is for — "email for work", "banking at First National", "social media I rarely use" — so you know at a glance what matters most.

For accounts tied to money or identity — bank, credit card, investment, tax filing, health insurance — also write down the customer service phone number and your account number. If you ever need to prove you own the account over the phone, you will have this ready.

Where to store your documentation safely

The safest place is a password manager — a program that stores passwords in encrypted form and fills them in for you. Bitwarden, 1Password, and Dashlane are common choices. A password manager lets you store not just passwords but notes, recovery codes, and security questions all in one place, locked behind a single strong password. If you use a password manager, you do not need a separate document.

If you do not use a password manager, create a document on your computer — not your phone, not the cloud, not email — and encrypt it. On Windows, you can use a Word document and set a password in File > Info > Protect Document. On Mac, use a Notes file and lock it, or create a Word document with a password. On Linux, use a text editor and encrypt the file with GPG. The goal is a file that requires a password to open.

Do not store passwords in a Google Doc, a Notes app synced to the cloud, or an email draft. Do not write them on a sticky note on your monitor. Do not use a spreadsheet in Dropbox or OneDrive unless you encrypt the file first. Cloud storage is convenient but it means your passwords are on someone else's server, and if that server is breached, your passwords are exposed.

If you have a physical safe at home, you can print a copy of your account list (without passwords) and store it there. This is useful for your family if something happens to you — they can see what accounts exist and contact the companies to request access. But keep the passwords in encrypted digital form only.

Documenting your devices

Make a list of every device you own that connects to the internet: your phone, laptop, tablet, smartwatch, smart home devices. For each one, write down the device name, the operating system and version, the serial number (usually in Settings), and which accounts are logged in on it.

The serial number matters because it is how you prove you own the device if it is stolen. You can find it in Settings on most devices — on iPhone it is in Settings > General > About > Serial Number, on Android it is in Settings > About Phone > Serial Number, on Windows it is in Settings > System > About > Device ID.

Note which accounts are on each device. If your phone has your email, banking app, and social media, write that down. If your laptop has your work email and cloud storage, write that down. This way, if a device is stolen or lost, you know exactly which accounts to lock down first.

Also note the phone number associated with each device (your phone's number, for example) and whether the device is set up with biometric login (fingerprint, face recognition). This information helps you recover the device or lock it remotely if it is lost.

Creating a recovery plan for your family

If something happens to you — illness, death, or extended absence — your family may need to access your accounts. Create a separate document that explains what to do and where to find your documentation.

Write down where you keep your password manager or encrypted document (on your computer, in a safe, with a lawyer). Write down the password to that manager or document, and give it to someone you trust — a spouse, adult child, or lawyer. You can also use a service like Google's Inactive Account Manager or Apple's Legacy Contact feature, which lets you designate someone who can request access to your accounts if you become inactive.

In your recovery document, list which accounts are critical — email, banking, insurance, mortgage — and which ones do not matter. Explain how to contact each company to request access. Most companies have a process for this, but it requires proof of death or legal authority, so your family will need to know what documents to gather.

Store this recovery document separately from your passwords. Your family should know it exists and where to find it, but they should not need your password manager password to find it.

Keeping your documentation up to date

Documentation only works if it is current. Every time you change a password, update your record. Every time you create a new account, add it to your list. Every time you delete an account, remove it from your list. Every time you change your recovery email or phone number, update that too.

Set a reminder to review your documentation twice a year — once in January and once in July, for example. Go through your list and check that the passwords are still correct, that the recovery methods still work, and that you have not forgotten any accounts. Delete accounts you no longer use. Add any new ones.

If you use a password manager, it will usually alert you if a password is weak or if a site you use has been breached. Pay attention to these alerts and change the password right away. Update your documentation at the same time.

What to do if you discover a breach

If you learn that a website you use has been hacked, your documentation tells you exactly what to do. Look up the account in your record, change the password immediately, and check whether the site offers two-factor authentication — turn it on if it does not already have it. Update your recovery codes if the site generated new ones.

Then check whether you used the same password on other sites. If you did, change the password on those sites too. This is why a password manager is useful — it shows you all the places you used a particular password, so you can change them all.

If the breach included your email address and password, watch for phishing emails pretending to be from that site. Do not click links in unexpected emails — instead, go to the site directly by typing the address in your browser.

Frequently Asked Questions

Should I write my passwords down on paper?

Only if you keep the paper in a locked safe at home and nowhere else. Paper is safer than a cloud document, but less convenient than a password manager. A password manager is the best choice for most people because it is encrypted, portable, and searchable. If you use paper, never photograph it or email it to yourself.

What if I forget the password to my password manager?

You will lose access to all your passwords. Most password managers let you set up a recovery email or backup codes when you create your account — do this immediately and store the recovery codes in a safe place. If you forget the master password and have no recovery method, the company cannot help you because they do not store the password.

Do I need to document accounts I barely use?

Yes, because you might forget they exist. Old social media accounts, free email addresses, and trial subscriptions can be used by hackers to reset passwords on other accounts or to impersonate you. Document everything, then delete the accounts you do not need. If you are not sure, keep it documented for now and delete it later.

Can I use the same password for multiple accounts?

No. If one site is breached, hackers will try that password on every other site. Use a unique password for every account. A password manager makes this easy because it generates and remembers unique passwords for you.

What should I do with old documentation when I delete an account?

Remove it from your active list, but keep a separate archive of deleted accounts for at least a year. This way, if you need to prove you owned an account or if the company contacts you about it, you have a record. After a year, you can delete the archive.