AES-256-GCM Argon2id No account

Your hidden aren’t private. Weave Vault is.

Your passcode was designed to be quick to type, not hard to guess — and Face ID decides who holds the phone, not who sees what’s on it. Weave Vault seals every photo, video, and file with AES-256-GCM, behind a pattern that is never written to disk — not even as a hash. Draw a different pattern and you open a different vault.

Download on theApp Store Get it onGoogle Play

Free to download. iPhone and iPad on iOS 16 or later, and Android.

Draw your pattern

The mechanic

Every pattern opens its own vault

There is no vault list, no account switcher, and no error telling you a pattern wasn’t recognised. A pattern the app doesn’t know doesn’t push back — it opens a fresh, empty vault, exactly as though it had always been yours.

Nothing to compare against

Your pattern isn’t hashed and checked against a stored value. It is fed straight into a key-derivation function. If the key it produces doesn’t unwrap a vault, there is nothing to report — and nothing on the device that could have reported it.

Every attempt goes somewhere

The app never rejects a pattern, and never tells you a vault is absent. An unfamiliar pattern and a brand-new one follow the same path in the code, so they are the same experience on the screen.

A vault is born on first import

Draw a pattern and nothing has been written yet. The moment you add your first file, the app generates a random vault key, wraps it with the key derived from your pattern, and shows you a 12-word recovery phrase — once.

The count stays in your head

No screen in the app displays how many vaults exist on the device — not settings, not the storage readout. You keep one vault or several; the app never counts them back at you.

Security architecture

We can’t read your files. Neither can Apple, Google, or the server we run.

Backup ciphertext goes to your own iCloud or Google Drive. Sharing splits the key in two, so the half our service holds opens nothing by itself. Nothing exotic, nothing homemade, and no gaps in what gets sealed.

  • AES-256-GCMFiles, thumbnails, filenames, metadata
  • Argon2id · RFC 9106Your pattern → a 256-bit key
  • HKDF-SHA256A separate subkey for every item
  • BIP-39The 12-word recovery phrase
  • 4 MB sealed chunksSingle files up to 16 GB
  • Split-key sharingNeither half opens anything alone

Read the security detail →

Beyond the lock screen

The vault is the beginning, not the whole app

Everything below keeps the same rule: your keys stay on your device, and anything that leaves it leaves sealed.

Encrypted backup

Losing a phone shouldn’t mean losing everything. Back up to your own iCloud on iPhone and iPad, or your own Google Drive on Android. What uploads is the same ciphertext that sits on your phone, so the provider stores bytes it cannot read.

Off by default, and yours to turn on when you want it.

Secure sharing

Send a point-in-time copy of a vault to someone you trust. They open it with a one-time phrase, and the half of the key that phrase derives never touches a server. Every share carries a mandatory expiry of up to 30 days, and you can revoke one early.

Duress mode

Arm a second pattern. Drawing it opens a decoy vault while the phone forgets how to open every other one, and it looks like an ordinary unlock.

A backup, if you have one, is frozen rather than deleted — so it stays your way back.

Folders

Organise inside a vault. Folder names live in the sealed manifest like everything else, so how you sort your files is as private as the files themselves.

In-app camera

Capture straight into the open vault. The photo is encrypted in memory and never passes through your device’s photo library, so there is no copy left in the camera roll to clean up.

Large files, whole albums

Photos, videos, PDFs, and documents, with single files up to 16 GB. Import a batch and it is encrypted item by item, with progress you can watch and cancel.

Nothing you put in a vault is ever held hostage. Getting your files back out — restoring a backup, opening a share, browsing, exporting — always works, on every device you own, for as long as you have your pattern or your recovery phrase.

How it works

Three steps, then it’s just an album

  1. Draw a pattern

    Connect at least six dots on the 5×5 grid. Argon2id — the memory-hard gold standard for resisting GPU-scale brute force — stretches that gesture into a 256-bit key. Nothing has been written to disk yet.

  2. Add your first file

    The vault comes into existence: a random key of its own, wrapped by the key your pattern derived. Files, thumbnails and filenames are all sealed with AES-256-GCM before they touch storage. Write down the 12-word phrase — it is shown once.

  3. Close the app

    Leave the app or lock the phone, and the keys are wiped from memory. What stays on disk is ciphertext — nothing left to read, and nothing to skim.

Frequently asked

The questions worth asking

Who is this actually for?

Anyone whose phone is sometimes in someone else’s hands. Friends, children, partners, colleagues, the relative who picks up your phone to look at one photo and keeps scrolling.

Most photo vaults share one problem: the lock is also an announcement. A folder marked private, a gallery pretending to be a calculator — both tell you exactly where to push.

Weave Vault’s lock doesn’t answer questions. Every pattern opens its own vault; an unfamiliar one opens a fresh, empty vault instead of an error; and no screen in the app says how many vaults exist. The lock is still a lock — it just tells whoever is holding your phone nothing about what is behind it.

What if I forget my pattern?

Enter that vault’s 12-word recovery phrase from the unlock screen and set a new pattern. If you have lost the recovery phrase as well, the vault cannot be opened — by you or by us. There is no support process that unlocks it, because there is nothing on our side to unlock it with.

Does anything get uploaded?

Only if you turn it on. By default Weave Vault makes no network requests at all, and the vault is excluded from your phone’s normal device backup so a routine iCloud or Finder backup never contains it.

If you enable encrypted backup, ciphertext goes to your iCloud or your Google Drive. If you create a share, the sealed contents go to Apple’s servers and a small control record — expiry, revocation, and an open counter — goes to a service we run, so that expiry and revocation can be enforced rather than merely promised. In every case the keys stay with you and the files stay unreadable to Apple, to Google, and to us.

Why no Face ID, Touch ID, or PIN?

Because those need something stored to check against. A pattern doesn’t: it is the input the encryption key is derived from, and the derivation is thrown away the moment the vault opens. Fewer stored secrets is a cleaner threat model and considerably less code.

What happens to the originals I import?

They stay where they were. Weave Vault only ever receives the items you pick in your operating system’s own picker — it does not browse, enumerate, or index your photo library. Importing makes an encrypted copy, so deleting the original afterwards is a decision you make deliberately, and the app walks you through it.

What is the threat model — honestly?

Without your pattern, the encrypted vault is genuinely hard to open. AES-256-GCM does not yield to brute force in any practical timeframe, and Argon2id is designed specifically to make guessing slow and memory-hungry rather than cheap and parallel.

What if I uninstall the app?

Uninstalling removes the vault and everything in it from the device. If encrypted backup was on, that backup survives and can be restored on a new install with your pattern or recovery phrase. If it wasn’t, treat the uninstall as permanent.

Put the private things somewhere private.

Free to download, with no account to create and nothing to set up. Draw a pattern, add a file, and the vault exists.

Download on theApp Store Get it onGoogle Play