In final testing

NexGuard isn’t on Google Play yet. Join early access and we’ll send the install link the day it opens.

Home Solutions Protect sensitive files

Sensitive files

Keep private notes and media
truly private

Move the documents and photos you don’t want on other apps’ camera rolls into an encrypted vault. They are encrypted on your phone before they are sent, the item’s name included, under a key we never receive — so we cannot read them. Turning on web access is what changes that: it seals new photos, documents and notes with a key we hold, which is what lets them open on your dashboard, and we say so rather than letting you assume otherwise.

On-device AES-256-GCM · Auth-bound key · Encrypted item names

Sealed on your deviceCiphertext is all the server sees.

Sensitive files

A vault that names who holds the key

Notes, photos and larger media

Small items inline, large files as encrypted blobs — all in one sealed place.

Auth-bound key

A biometric or device unlock authorizes the key for a short window, then it re-locks.

Encrypted storage

Nothing leaves the phone in the clear, file names included. Passwords use a key only your phone has; media can use a per-account key we hold, so it opens on the web as well.

How it works

What happens when you add a file

Sealed before it moves

A file you add on the phone is encrypted there with AES-256-GCM using a key generated in the Android Keystore. The key is non-exportable — it cannot be copied off the device even by the app that created it — and the encryption happens before anything is written or uploaded. A file you add from a computer instead is encrypted when it reaches us, because a browser has no such key; the vault marks those so you can tell them apart.

Unlocked for a window, then re-locked

The key is authentication-bound. A biometric or device-credential unlock authorizes it for a short window so you can work, after which it re-locks. Leaving the app open doesn’t leave the vault open.

Names are encrypted too

An item’s name is part of what gets sealed. A filename like “passport-scan” is exactly the kind of metadata that leaks the thing you were trying to protect, so it’s treated as content, not as a label.

Backups you carry yourself

A portable backup is encrypted with a key derived from a passphrase you choose, using PBKDF2-HMAC-SHA256 at 210,000 iterations. It’s deliberately not the device key, because a device-bound key can’t restore onto a new phone. The server stores the ciphertext plus the public salt and nonce — nothing that can open it.

Questions

Protect sensitive files: common questions

What can I put in the vault?
Private notes, documents, photos and other media. Smaller items are stored inline; larger files are sealed into encrypted blobs. Added on the phone, the encryption happens there first; added from a computer, it happens on arrival.
Are file names encrypted as well as contents?
Yes, the name is sealed with the content rather than stored as a label. For password items that means we hold no readable list of them at all. For media you have made web-accessible, the name is encrypted under the per-account key we hold, because your dashboard has to be able to show you the name of the file you are opening.
If I lose my phone, can I get my files back?
Only from a backup you made yourself with a passphrase you still have. The device key is non-exportable by design, so it can’t be recovered — which is precisely why the portable backup exists. Make one before you need it.
Does NexGuard upload my whole camera roll?
No. Nothing is added to the vault unless you add it. There is no background sync, no automatic import and no scanning of your gallery.

Get early access

Seal what’s private

Get NexGuard free and move your sensitive notes and files into a device-encrypted vault.