Google says it can’t provide passwords or other login details. Amazon’s bereavement page runs the other way, and it invites a survivor holding the account email to sign in.
That gap runs through the whole subject, and it leaves your family holding a password with no plain answer. Meta wrote its terms the strict way. Sharing a password or handing an account to somebody else is barred there, and reporting a death freezes the profile. The freeze removes access even from relatives who know the password and had been using the account all along.
No prosecution of a survivor or executor for logging in with a dead person’s password appears in research closed July 28, 2026. That worry comes from theory, not real cases. Reading that as permission would go too far, because the decisions below leave the question open in more than one direction.
The practical trouble arrives long before any of that. Copying comes first, so save the photos and files before you test a login.
Two-factor codes arrive by text message, and the number they arrive at usually belongs to the person who died. Cancel the phone plan and the codes stop. Email verification runs into the same wall when the recovery address was another account of the same person. Keeping the number live and the handset charged keeps those codes coming.
Meta says it freezes an account to stop attempted logins, and anyone at all can report a death. None of that needs a prosecutor. A copy of the data is what the documented routes deliver, and no examined platform hands over a working password.
What the courts have decided, and what they left open
Three federal decisions get quoted in this argument. Not one of them involved an executor, a family member, or an account whose holder had died.
A 2016 decision from the Ninth Circuit, known as Nosal, put authorization in the hands of the system owner. The account holder’s permission didn’t count. The court was deciding an employment dispute over shared logins, and no reported case applies it to an executor. Read literally, the reasoning says a platform decides who may sign in, whatever the person who chose the password wanted.
The Supreme Court narrowed the Computer Fraud and Abuse Act in 2021, in a decision known as Van Buren. That narrowing stopped short of the question here. The justices expressly reserved whether a gate can be built out of contracts and policies rather than out of code.
A reserved question is one the court chose not to answer, so the contract theory survived the ruling untouched. Terms of service still carry weight.
A third case sits closer to home. Power Ventures, from the Ninth Circuit in 2016, dealt with a company using Facebook logins that users had handed over.
The court held that breaking a site’s terms of service, on its own, can’t establish liability under the federal act. Permission, not the contract, became the deciding point. Once Facebook told the company to stop, the users’ own consent no longer covered what happened next. Whether ordinary boilerplate terms amount to that kind of revocation is a question the court didn’t answer.
Those three decisions are the whole federal case law people reach for, and none was written with survivors in mind. Nobody can tell you how a judge would read them. An estate lawyer in the relevant state is the person to ask before anyone reads the silence as safety.
The platform’s contract is a separate question
Criminal exposure is one question, and the agreement each platform wrote for its own users is a different one. The second one decides what happens in practice.
Nearly every platform examined for this site bars credential sharing, account transfer, or both, somewhere in its terms. Breaking those terms rarely ends in court. The usual ending is a locked account, a memorialized profile, or a support ticket that stops moving. Once a platform has decided an account belongs to somebody who died, the password stops being the thing that opens it.
Google’s support pages state that the company can’t provide passwords or other login details, and no survivorship clause changes that. A different route exists in its place. Google runs a request process for a person who has died.
Apple’s route ends somewhere else again. A Legacy Contact receives a separate account holding a copy of the data, not the account the person used.
That copy leaves out purchased media, and it leaves out the iCloud Keychain where the person’s other passwords were stored. The legacy key can’t decrypt them. Payment details and passkeys sit behind the same wall, so a family’s likeliest source of other passwords stays shut. X states plainly that it can’t provide account access to anyone, whatever their relationship to the person who died.
Two platforms break that pattern, and both do it in writing rather than by accident. Amazon is one, and Snapchat is the other. Snapchat’s documented deletion path presumes the requester already holds the credentials, or the address the account was opened with.
None of the examined platforms releases login credentials. Access, in every one of these processes, means a limited role, a download of the data, or a separate account.
Knowing that changes what you ask for, because none of these processes offers the password as an outcome. Ask for the data instead. A copy can carry the photographs, the messages a platform is willing to release, and the record of what the account held. Which of those a particular estate can pursue is a question for the lawyer handling it, in the state where it sits.
Where the state acts help, and where they stop
Most states have adopted a digital-asset law built on a model act from 2015, the Revised Uniform Fiduciary Access to Digital Assets Act. Louisiana and Massachusetts have adopted neither. The count reached 47 states plus the District of Columbia by July 28, 2026, and Delaware keeps an older act instead.
One clause in that act speaks to this page, and it covers trustees and conservators as well as executors. Section 15(d) counts a fiduciary acting within their duties as an authorized user for computer-fraud purposes.
The wording aims at state computer-crime statutes, and every state has one of its own. Two limits sit on top of it. The Uniform Law Commission, which wrote the model act, cautions that federal courts may not treat the clause as settling the point. The clause also leaves the platform’s contract standing, so a term barring credential use doesn’t fall with it.
Federal charging policy adds a third layer, and the Department of Justice rewrote its own in 2022. The policy holds back from contract-based theories. Prosecution of somebody who gets into another person’s account is preserved, and survivors are never mentioned in the document.
Charging policy is guidance, not law. Federal prosecutors can change it, and it binds no state prosecutor working under a state computer-crime statute.
So the protection an executor has under a state act stops at the edge of federal law and of the platform’s terms. Three rulebooks apply, and they don’t agree. Whether a particular login in a particular state is safe is a question for the lawyer handling the estate. Where the estate is large, or the family disagrees, the probate court supervising it is the other place to ask.
The route that doesn’t need a password
The procedural route avoids all three rulebooks, and it works better when someone sets it up before a death. Three settings do most of the work. Facebook’s legacy contact, Google’s Inactive Account Manager, and Apple’s Legacy Contact each name somebody in advance.
Under the act, a direction like that outranks a will, provided the tool can be changed at any time. Google’s tool sends a data-download link to as many as 10 recipients after a period of silence the user picks.
No death documentation is needed for that link, and no survivor can move the timer forward. Apple’s version has a harder edge. The named contact needs an access key generated when the setting was created, and Apple holds only an encrypted packet. Losing the key ends the route, because the company can’t decrypt what it stores.
A password manager can go further, because Bitwarden’s emergency access lets a trusted contact take over the vault. Takeover removes every two-step login method. The scope is the whole vault, the feature needs a paid plan, and nothing tells the contact that anyone has died.
After a death, a documented request replaces the password, and the paperwork varies little between platforms. The list is short. A written request, a certified death certificate, letters of appointment, and evidence of consent make up the baseline.
The act then puts a clock on it. Compliance is due within 60 days, though the custodian keeps the right to demand a court order instead.
What comes back may be full access, partial access, or a copy of the data, at the company’s choice. A refusal is common enough to plan for. Read the page on company refusals before writing again. Ask the lawyer handling the estate which outcome is worth pursuing, and whether a court order is worth seeking at all.
