Agreed! We actually have 3 options available for developers to choose from right now: local storage, session storage, or memory.
The memory option does exactly what you said, derives the encryption key dynamically from the password in memory.
It's actually a bit more complex in how it works under the hood (i.e. the above isn't exactly how it works), happy to get deeper into the details :)
Note this option is provided in the form of the rememberMe parameter here: https://userbase.com/docs/sdk/sign-in/
Your Q&A scheme is also definitely a plausible backup option! Thanks for the suggestion!