Device-encrypted vault
The server only ever
sees ciphertext
Vault items added on the phone are encrypted there before they are sent, and the item’s name is encrypted with them. Two keys are in play: passwords and authenticator secrets use a non-exportable AES-256-GCM key in the Android Keystore that we never receive, while photos, documents and notes can optionally use a per-account key we hold, which is what lets them open on your web dashboard.
AES-256-GCM · Hardware-backed key · Encrypted item names
How it works
Encrypted before it ever leaves your phone
The device key is auth-bound: a biometric or device-credential unlock authorizes it for a short window, then it re-locks. We never receive that key, and the ciphertext it sealed is useless without it. The per-account key behind web-accessible media is the other case, and the page says so where it applies.
Least data, by design
What we hold — and what we never do
What we store
Ciphertext blobs and the fact that a vault item exists — never the item’s name in the clear, and never anything in the clear. For password items we hold no key, so the bytes stay shut. For web-accessible photos, documents and notes we hold the key, and say so.
What stays on device
The encryption key never leaves your phone. It’s non-exportable and bound to recent authentication, so only you can unseal an item.
If you delete your account
Your records are removed. The ciphertext we held is useless without your on-device key, which we never had in the first place.
Get early access
Seal what’s private
Get NexGuard free and store your most sensitive notes and files in a vault only you can open.