Sensitive files
Keep private notes and media
truly private
Move the documents and photos you don’t want on other apps’ camera rolls into an encrypted vault. They are encrypted on your phone before they are sent, the item’s name included, under a key we never receive — so we cannot read them. Turning on web access is what changes that: it seals new photos, documents and notes with a key we hold, which is what lets them open on your dashboard, and we say so rather than letting you assume otherwise.
On-device AES-256-GCM · Auth-bound key · Encrypted item names
Sensitive files
A vault that names who holds the key
Notes, photos and larger media
Small items inline, large files as encrypted blobs — all in one sealed place.
Auth-bound key
A biometric or device unlock authorizes the key for a short window, then it re-locks.
Encrypted storage
Nothing leaves the phone in the clear, file names included. Passwords use a key only your phone has; media can use a per-account key we hold, so it opens on the web as well.
How it works
What happens when you add a file
Sealed before it moves
A file you add on the phone is encrypted there with AES-256-GCM using a key generated in the Android Keystore. The key is non-exportable — it cannot be copied off the device even by the app that created it — and the encryption happens before anything is written or uploaded. A file you add from a computer instead is encrypted when it reaches us, because a browser has no such key; the vault marks those so you can tell them apart.
Unlocked for a window, then re-locked
The key is authentication-bound. A biometric or device-credential unlock authorizes it for a short window so you can work, after which it re-locks. Leaving the app open doesn’t leave the vault open.
Names are encrypted too
An item’s name is part of what gets sealed. A filename like “passport-scan” is exactly the kind of metadata that leaks the thing you were trying to protect, so it’s treated as content, not as a label.
Backups you carry yourself
A portable backup is encrypted with a key derived from a passphrase you choose, using PBKDF2-HMAC-SHA256 at 210,000 iterations. It’s deliberately not the device key, because a device-bound key can’t restore onto a new phone. The server stores the ciphertext plus the public salt and nonce — nothing that can open it.
Questions
Protect sensitive files: common questions
What can I put in the vault?
Are file names encrypted as well as contents?
If I lose my phone, can I get my files back?
Does NexGuard upload my whole camera roll?
Get early access
Seal what’s private
Get NexGuard free and move your sensitive notes and files into a device-encrypted vault.