Switching from Chrome
U2 Secured imports the CSV that Chrome's own password export produces, parsed and encrypted in your browser before anything reaches a server.
Chrome's password manager is genuinely convenient, and it encrypts what it stores. The argument for moving is not that it is unsafe — it is that your passwords are tied to one browser and one Google account, there is no published zero-knowledge design, no way to share a credential with anyone, and no second factor stored anywhere. This page covers the export, the import, and what changes once you have made the move.
The move, step by step
Export your passwords from Chrome
In Chrome, go to Settings → Autofill and passwords → Google Password Manager → Settings, and choose Export passwords → Download file. You may be asked to confirm with your device screen lock or your Google password first.
Chrome produces a CSV with a name, url, username and password column, plus an optional note column when a password has one attached. That is everything Chrome exports — there is no secondary file for anything else, because Chrome's password manager does not track item types beyond a single login.
Google owns this part of the journey and occasionally moves the menus. Their support article, linked at the foot of this page, is the authority on it.
That file is every one of your saved passwords in plain text, sitting in your Downloads folder. Nothing in it is encrypted. Keep it on your own machine, do not email it to yourself, and delete it as soon as the import is done — step 4.
Open Settings → Import in the U2 Secured web vault
Sign in to the web vault — creating an account takes a couple of minutes if you have not already — go to Settings → Import, choose Chrome, and pick your CSV file. Import lives in the web vault only — the browser extension and the mobile apps do not have it.
You need to be the workspace owner or an admin; on a brand-new personal workspace, that is simply you. The file may be up to 10 MB, which comfortably covers even a saved-password list in the thousands.
You also choose where the items land: an existing folder you can write to, or a new one created there and then.
Read the review screen before anything is uploaded
The review step is the point of the whole flow. For the file you handed it, it reports how many items are ready, how many are already in your vault, how many rows it could not use and why, and how much room your plan has left. Every skipped row is named by its row number in your own file, so you can go and look at it.
The parser needs the name, url, username and password columns; if any is missing, the file is refused right there, with a message naming both what was missing and the headers it did find — the surest sign you handed over a file from somewhere else.
If the import would take you past your plan's item limit, the screen says by how many, before a single item is uploaded.
Confirm, then delete the export file
Each item is encrypted in your browser and uploaded in batches. If your session locks part-way through, the run pauses and resumes from where it stopped rather than starting over or uploading anything twice.
When it finishes, delete the CSV and empty your trash: a file in the trash is still a file. Nothing needs it again, and re-running the same import later is safe — duplicates are detected in your browser against what is already in your vault, so importing the same file twice does not double your entries.
What comes across
- Every saved login: site, username, password, and whatever was in the note column.
- Names and notes in any language. Fields are length-capped and stripped of control characters on the way in, and anything trimmed, flagged or dropped is reported against its row number instead of disappearing quietly.
What does not
Chrome's export is the narrowest of the sources this importer reads, so there is less to lose than with a dedicated password manager — but read this before assuming everything came across.
- Passkeys. Chrome's own passkey manager is a separate system from its password export and is not included in the CSV at all — nothing here can move a passkey for you.
- Payment cards and addresses saved in Chrome's autofill. Those export separately, if at all, and are not vault content this importer reads.
- There is no folder or category concept in a Chrome export to preserve — Chrome's manager does not have one, so nothing is lost there, and every item lands in the single folder you chose during import.
- There is no second factor to bring across, because Chrome does not store one — see below.
- Rows with no password, no username and no note. They are not credentials, so they are skipped and listed rather than imported as empty entries you would have to explain to yourself later.
Chrome never had your two-factor codes — U2 Secured does, for free
This is the one place this move adds something rather than costing you anything: Chrome's password manager has no concept of a two-factor code, so there is nothing to hand over during this import.
Every source format this importer reads is checked for a TOTP secret and, when one is found, lifted out before encryption and handed back as a QR code rather than written into the vault — that is a deliberate design decision, not an oversight, and it is explained on the other migration guides on this site. Chrome's CSV simply never carries one, because Chrome's password manager was never built to store a second factor at all.
If you currently keep your authenticator codes in a different app, or on paper, or nowhere, U2 Secured Authenticator generates them for free — it is a separate app from the vault, on purpose, so a password and its second factor are never sitting in the same store.
Set it up any time after this import: scan the QR code your bank, email provider or any other site shows you when you turn on two-factor authentication, the same way you would with any authenticator app.
If you already use a different authenticator app for some accounts, there is no need to move those — U2 Secured Authenticator is for accounts you have not set up two-factor authentication on yet, or want in one place going forward.
What it will cost
Chrome's password manager is free, and comparing it to a paid plan would be misleading — this move is worth making on the free plan alone for most people coming from Chrome, since a personal password list rarely runs past a few hundred entries. Paid plans exist for when a vault grows past that, or a household or small team wants more than one person on it.
Free
$0one user
500 items
- 7-day audit log
- The same cryptography as every paid plan — encryption does not improve with price
- No breach monitoring, no SSO
Where a Chrome password list almost always fits.
Basic
$5per block of 5 users, per month — $1.00 per user
1,000 items
- Unlimited users, billed in blocks of five — a household or small team
- 30-day audit log
- Breach monitoring
- Auto-lock policy across web, extension and mobile
Premium
$9per block of 5 users, per month — $1.80 per user
10,000 items
- Single sign-on with OIDC and SAML
- 365-day audit log
- API access
- Breach monitoring and auto-lock policy
- Paid plans bill per block of five users with a minimum of one block, so one person on Basic pays $5 a month and a team of twelve pays for three blocks.
- Basic and Premium start with a 7-day trial at sign-up and ask for no card. If no payment method is added by the end of it, the workspace is paused rather than charged.
- The import review screen shows the room left on your plan before you commit to an upload, and refuses an import that would exceed it.
Two things this is not
Worth reading now rather than assuming.
- There are no shared folders. The only sharing U2 Secured has is a temporary public link to a single item; there is no user-to-user and no team or organisation sharing. Chrome's passwords were never shareable either, so this is not a step backward — just not a feature this move gives you.
- The browser extension is Chrome and Edge only, which — coming from Chrome — is not a limitation for you specifically. There is no Firefox or Safari extension, and there are iOS and Android apps if you use another device.
Questions people actually ask
- Does U2 Secured import from Chrome?
- Yes. The web vault reads the CSV Chrome's own password export produces under Settings → Import, and also imports from Bitwarden, LastPass and 1Password. Import is available to the workspace owner and admins — on a new personal workspace, that is you.
- Is Chrome not secure enough already?
- Chrome's password manager encrypts what it stores and is genuinely convenient. The reason to move is not that it is unsafe today — it is that your passwords stay tied to one browser and one Google account, there is no published zero-knowledge guarantee, no way to share a credential with anyone, and no second factor stored anywhere.
- What is zero-knowledge, and does Chrome have it?
- Zero-knowledge means the service storing your data cannot read it, even in principle: U2 Secured derives your vault key from your master password on your device via Argon2id and HKDF, and only AES-256-GCM ciphertext ever reaches the server. Chrome does not publish an equivalent design for its password manager, and access to your Google account is what protects your saved passwords there.
- Do my Chrome passwords come with two-factor codes?
- No — Chrome's password manager has never stored two-factor codes, so there is nothing to bring across on that front. U2 Secured Authenticator generates them for free, in a separate app from the vault, and you can set it up for any account any time after this import.
- What about passkeys I saved in Chrome?
- Not covered by this import. Chrome's passkey manager is a separate system from its password export, and the CSV this importer reads does not include them.
- How many passwords can I import?
- The free plan holds 500 items for one user, Basic holds 1,000 and Premium holds 10,000. Most people coming from Chrome have a personal list well inside 500. The limit is per workspace and counts items already in the vault, so the review screen shows the room remaining before anything is uploaded and refuses an import that would exceed it.
- Can U2 Secured see my passwords during the import?
- No. The CSV is parsed in your browser and each item is encrypted there, with a key derived from your master password via Argon2id and HKDF; items travel as AES-256-GCM ciphertext. The server stores blobs it cannot read, and neither the master password nor the vault key is ever sent to it.
- What should I do with the exported CSV afterwards?
- Delete it and empty your trash. It is an unencrypted copy of every password you saved in Chrome, and it has no further use once the import has finished.
Source for the Chrome side
The steps above were read from Google's own support article on the date shown. Chrome changes its interface from time to time; if the menus have moved, their article is the authority and this page is out of date.
- Google Chrome Help — Save, delete, edit and manage passwords in Chrome · read 2026-09-25
Ready when you are
Create a workspace, export from Chrome, and run the import. The review screen tells you what will happen before anything is uploaded — and if something about your list does not fit, ask us first.