The user should provide a password, that is only useful if the service emails the recipients with a link to hosted page that will decrypt the data client side.
But if the recipient forgets the password? They won't be able to reset it, in most case either, because the reset link goes to the original email which the recipient may not have access to.