PUBLISHED 9 SEP, 2026 · UPDATED 6 OCT, 2026

Hide Photos App on iPhone and Android: What Actually Keeps Them Private

How a hide photos app really protects files: what is encrypted, what key opens it, what leaves the phone, and what happens if you forget the pattern.

Hide Photos App on iPhone and Android: What Actually Keeps Them Private

Most lists of hide photos apps rank features and star ratings. This guide does something narrower. It explains the mechanism: what is encrypted, what key opens it, what leaves the device, and what happens if you forget the credential. Then it states what Weave Vault does and does not do. You can use the same questions on any app.

What a hide photos app does, and what hiding is not

A hide photos app moves photos out of the camera roll and into its own storage. That is all the term guarantees. Whether those photos are private depends on one thing: whether that storage is encrypted, and what key protects it.

Hiding a photo versus encrypting it

Hiding changes where a file appears. Encrypting changes what the file contains. An app can hide a photo without encrypting it. In that case the file is still readable by anything that finds it.

Weave Vault encrypts. It seals every file with AES-256-GCM. Each file gets a fresh random 96-bit nonce and a 128-bit authentication tag. The tag means a tampered file fails to open instead of opening as garbage.

Weave Vault runs on iPhone and iPad (iOS 16 or later) and on Android. There is no Windows, Mac or web app.

This article does not describe how the built-in hidden albums on iOS or Android work. Check the platform's own documentation and ask them the same questions listed at the end.

Why the question to ask is what opens the file, not where it is moved

A folder name is not a lock. If the app's storage is protected only by being out of sight, the protection ends when someone looks. If it is protected by a key, the question becomes: where does the key come from, and where is it kept? The next sections answer that for Weave Vault. Full detail is on the security page.

Moving photos in: what happens to the originals

Importing copies a file into the vault. It does not remove the original. This is the step readers most often miss, and the app says so on screen.

Weave Vault Add Files sheet with Photos or Files as the import source The Add Files sheet offers Photos or Files and notes that originals stay where they were until you delete them.

Importing from Photos or Files

The Add Files sheet offers two sources: Photos or Files. The sheet states that originals stay in Photos, or in their original location, unless you delete them there.

Import then shows an "Encrypting to vault" progress dialog. It asks you to keep the app open until it finishes. Do not switch away mid-import.

The in-app camera is an alternative. It avoids the camera roll in the first place. The secure camera page describes exactly what it does, and this article states nothing beyond that page.

Deleting the original copy yourself

After the import finishes, delete the original from Photos yourself. Then check the Recently Deleted folder. The sheet notes that deleted Photos items may stay in Recently Deleted for about 30 days. Until that folder is emptied, a copy can still be there.

The order is simple:

  1. Import into the vault and wait for the dialog to close.
  2. Confirm the files open inside the vault.
  3. Delete the originals in Photos or Files.
  4. Empty Recently Deleted.

How the lock works: a pattern, Argon2id and a content key

Weave Vault has one credential: a pattern drawn on a 5x5 dot grid. There is no separate passphrase. The pattern unlock page covers the feature. This section covers the cryptography.

Weave Vault dark lock screen with a pattern drawn on a 5x5 dot grid The unlock screen, where the pattern, the only credential, is drawn.

The key hierarchy, in order

The order matters, so here it is step by step:

  1. You draw the unlock pattern.
  2. The pattern goes through Argon2id, a memory-hard key derivation function specified in RFC 9106.
  3. The result is a key-encryption key.
  4. That key unwraps a random 256-bit per-vault content key. A CSRNG generated the content key when the vault was created.

The Argon2id-derived key does not encrypt file contents directly. It only wraps the content key. The Argon2id parameters are t=3, m=64 MiB, p=1, over a 128-bit salt.

Per-item subkeys are derived with HKDF-SHA256, as defined in RFC 5869. Large files are encrypted in independently authenticated chunks. The ceiling is 16 GB per file.

What is never written to disk

The pattern is never written to disk. Not to a file, and not to the Keychain. It exists only while you draw it.

Setup enforces a minimum. The setup screen requires at least 6 dots and at least 2 direction changes on the 5x5 grid. A short, straight swipe is rejected.

What stays on the phone: no account, no analytics, no server

Encryption protects the files. The next question is what else leaves the phone. For Weave Vault the answer is short. Sources are the security page and the support page.

No account of any kind

There is no account. No email, no profile, no sign-up. That holds on the free tier and on Pro.

There are also no analytics, no crash reporting, and no advertising or attribution SDKs.

Backup goes to your own cloud, not ours

There is no Weave Vault vault-storage server. Nothing is uploaded by default.

Encrypted backup is optional. It copies the vault's ciphertext to your own iCloud or Google Drive. No vault key and no plaintext leaves the device. Details are on the encrypted backup page.

Weave Vault is also excluded from the phone's ordinary device backup by design. A routine iCloud or Finder backup of the phone never contains it.

One limit applies, and it is stated as the project states it: "We make no claim about what an examiner with the physical device could or could not determine." Do not read this article as a promise that a forensic examination would find nothing.

Organising private photos once they are inside

A vault is easier to use when it is sorted. Weave Vault lets you move photos into folders inside the vault.

Weave Vault Private folder grid of ten personal photos A Private folder inside an unlocked vault, shown as a grid of photos.

Folders for private, family and documents

Folders are a Pro feature. The free-tier screenshot shows a PRO badge on New Folder. The manifesto puts it this way: "Pro opens doors: more vaults, encrypted backup, sharing, folders." The folders page has the feature description.

Folder names are limited to 30 characters. That limit appears on the New Folder sheet.

Search and filter inside the vault

Select mode offers Move, Remove and Delete on the items you choose. Read the three labels before you tap. Remove and Delete are different actions.

The vault is not only for photos. The app's own screenshots show specimen IDs, screenshots and backup codes. Those screenshots are labelled SPECIMEN sample data. They are not real documents.

One pattern, more than one vault

This is the part of the design that surprises people. The app keeps no list of vaults.

An unrecognised pattern opens a fresh empty vault

If you draw a pattern the app does not recognise, it opens a fresh empty vault. It does not show an error. The app keeps no vault list, no switcher and no count.

The free tier allows up to 3 vaults. More vaults need Pro. The multiple vaults page explains the mechanism.

Decoy vaults and the duress pattern

Duress mode is covered on the duress mode page. Read that page, and the warning on the app's duress setup screen, before you rely on it. This article describes it only as far as that page does.

A second vault is not a guarantee against someone who holds the device and examines it. Do not treat a decoy as a defence against that.

If you forget the pattern: recovery, backup and sharing limits

A design with no account and no server has a consequence. Nobody can reset your credential for you.

The 12-word recovery phrase

Each vault has its own 12-word recovery phrase. It is shown once. Write it down when you see it.

If both the pattern and the phrase are lost, the vault cannot be opened. In the project's words: "we do not hold a copy, and there is no support process that can override this." The support page states the same.

Backup: enabling needs Pro, restoring never does

The split is exact. Enabling backup requires Pro. Restoring never does. Browsing and exporting your own files work without a subscription, including if Pro lapses.

So a lapsed subscription does not lock you out of your own files. It only stops you from turning backup on.

Sharing a copy with someone else

Sharing sends a point-in-time copy of a whole vault. It is re-keyed from scratch each time. It has an enforced expiry, and you can revoke it early from Shared vaults in the vault's settings. The secure sharing page has the full description.

Recipients "don't need a vault of their own and don't need to pay for anything."

What it costs, and how to choose a hide photos app

Free tier limits

The free tier allows up to 3 vaults and up to 50 files per vault.

Pro is sold three ways: a monthly subscription, an annual subscription with a 7-day trial, or a one-time lifetime purchase. This article does not quote prices. Check the current price in the store listing. Do not assume unlimited storage. It is not published anywhere.

A short checklist for any app

Ask these five questions of any hide photos app, including this one:

  1. Is each file encrypted, or only moved?
  2. What key opens it, and where does that key come from?
  3. Does the app need an account?
  4. Is anything uploaded by default?
  5. What happens if you forget the credential?

An app that answers all five in plain terms is easier to trust than one that answers with a rating.

Weave Vault is available from the App Store and Google Play. Both are linked from the homepage. There is no web signup.

← All posts