Documents that must not be lost and must not leak
Insurance policies, ID cards, deeds, certificates, credentials. The Vault keeps them encrypted on the device, and we cannot open them.
Encrypted before it leaves the phone
Vault content is encrypted in the app with a key we never see in readable form. What sits on the server is ciphertext. That is not a policy promise — it is how the system is built.
Approval releases the key, not the button
When a document needs approval, what the approval releases is the key. A denied request leaves the requester holding ciphertext they cannot read, rather than a hidden button.
Face and fingerprint unlock the device
Biometrics unlock a key held on that phone. They are not a password substitute, not a way into our servers, and the biometric data never leaves your device.
One recovery code, held by you
When you first set up the Vault, the app shows a recovery code once. You have to type it back to prove it was really saved — not tick a box saying you copied it.
Emergency access for the household's own documents
A member can nominate another member to request emergency access to documents the household could already see. The request is visible when it is made, the waiting period is one you choose, and the household owner can stop it at any point within that period.
Two limits we state up front
A document you mark private opens only with your password and your recovery code. Losing both means the content is gone, and we say so on the setup screen rather than in a footnote. Emergency access does not reach a private document either — only ones already open to the household.
Documents that remind you themselves
Policies and certificates carry their expiry date, and a reminder arrives before it passes. The most sensitive ones live as vault items.
Store one important document properly
Start with the policy or the ID card that has been sitting in your photo gallery.
Get the app