Vault / Security
Know what protects
your content.
Two separate kinds of access
Face ID, Touch ID, or your device passcode opens the app. Each container has its own password. Vault does not store that container password in Keychain, and device authentication does not replace it.
There is no recovery-key or forgotten-password recovery workflow. A weak password can be guessed against an exported file without access to your phone.
Encrypted containers
The current format uses Argon2id to derive protection from a password, HKDF-SHA256 for key derivation, and XChaCha20-Poly1305 authenticated encryption. Container metadata, including names and folder relationships, is encrypted.
These established building blocks do not make the complete application independently audited. Correctness, password strength, device security, and operational behavior all matter.
Exports, backups, and older copies
A whole-volume export remains encrypted. Exporting an individual file or photo produces an unencrypted copy at the destination you choose. iOS, Files providers, and cloud-backed destinations may retain or sync copies.
Deleting an item does not guarantee its removal from historical snapshots or backups. Changing a password does not make every old export inaccessible. Keep backups and old passwords under your control.
Important limits
- Vault cannot protect visible or unlocked content on a compromised operating system.
- It cannot guarantee that screenshots or every in-memory copy are prevented or erased.
- The current format does not provide historical-snapshot deniability: comparing old and new files can reveal changed regions.
- There is no promise of anonymity, coercion safety, guaranteed flash erasure, or portable rollback protection.
- Unsaved edits are discarded when the app locks. Keep tested backups outside the app.
See Vault support for practical help with access, backups, and export.