Store backup codes somewhere available when the phone is unavailable, but protected from anyone who could combine them with your password.
Good storage options
- A trusted password manager with a strong master password and its own recovery plan.
- A printed copy in a secure physical location.
- An encrypted file on a separate device or encrypted drive.
- Two separated copies for the most important accounts.
Avoid single points of failure
- Do not keep the only copy as a screenshot on the protected phone.
- Do not leave plain-text codes in email drafts or cloud photos.
- Do not store the password and recovery code together in an obvious note.
- Do not share codes with support staff or callers.
Label without oversharing
Record the service name, generation date and whether codes are single-use. Avoid writing the full account password beside them.
Maintain them
Cross out or delete a code after use, generate a fresh set when the service invalidates the old one and review storage after moving house, changing password manager or replacing devices.
Store codes for recovery, not convenience
Backup codes are usually powerful one-time credentials. Keep them away from the phone and away from an unprotected file that shares the same cloud account they are meant to recover.
- Paper in a secure private location is simple and independent of account access.
- An encrypted password-manager note can work when the vault itself has an independent recovery route.
- For high-value accounts, keep two controlled copies in separate locations.
- Replace the stored set whenever the service regenerates or invalidates codes.
Label each set with the service and date without adding the account password. Periodically confirm that the codes still correspond to an active account and have not all been consumed.
Official sources
Facts checked: 26 July 2026. Device behaviour, account features and menu paths can change. Recheck the current instructions for your exact device, software version and service before acting.


