PUBLISHED 1 SEP, 2026 · UPDATED 6 OCT, 2026

How to Hide Photos on iPhone: Moving Them Out of the Camera Roll

Hiding a photo in the Photos app only changes where it is listed. See how an encrypted vault works (AES-256-GCM) and where the original stays on your iPhone.

How to Hide Photos on iPhone: Moving Them Out of the Camera Roll

Most guides on how to hide photos on iPhone end at one tap. They do not say where the original file goes. This guide does. It separates hiding a photo from encrypting it, then walks through moving photos into an encrypted vault, Weave Vault, and deleting the originals yourself. It also states what the app does not claim.

What 'hiding' a photo on iPhone actually means

The word covers two different things. One changes where a photo is listed. The other changes whether the file can be read at all. Knowing which one you need decides which method makes sense.

Hiding versus encrypting

Hiding moves a photo out of the main grid. The file is still there, still stored the same way, and it is still readable by anything that can open the Photos library.

Encrypting is different. The file is transformed so that its contents are unreadable without a credential. Without the credential, the bytes are noise.

Where the original photo stays

A photo in the camera roll is stored by the Photos app. Any hiding method that leaves the original there only changes where it is listed. The iPhone also has a built-in Hidden album in Photos. It is a long-standing iOS feature, and Apple's own Photos documentation is the place to read exactly how it behaves. This guide makes no claim beyond that.

The point that matters here is simple. If the original stays in the Photos library, the photo has been re-filed, not removed.

What you are really trying to prevent

Name the threat plainly. Someone has your unlocked phone in their hand and is scrolling through photos. That is the case this guide is about. It is not about an attacker with specialised equipment, and nothing below claims to defeat one.

Hide photos in an encrypted vault app

A vault app keeps a separate, encrypted copy of your files outside the camera roll. Once the original is deleted from Photos, scrolling the camera roll shows nothing, because nothing is there.

Weave Vault Add Files sheet offering Photos or Files as the import source The Add Files sheet offers Photos or Files as the source, and its note that originals stay put is the detail most hide-photo guides leave out.

What a vault does differently

A vault does not just re-list a photo. It encrypts the file and stores the ciphertext inside the app. The photo is no longer readable by simply opening it from the camera roll, because it has been removed from there and sealed elsewhere.

What Weave Vault does with the file

Weave Vault is a private photo and file vault for iPhone and iPad (iOS 16+) and Android. There is no Windows, Mac or web app.

Files are sealed with AES-256-GCM. Each file gets a fresh random 96-bit nonce and a 128-bit authentication tag. Per-item subkeys are derived with HKDF-SHA256, defined in RFC 5869. Large files are encrypted in independently authenticated chunks, up to a ceiling of 16 GB per file. The full description lives on the security page.

No account, no analytics

There is no account of any kind. No email, no profile, no sign-up, on free or Pro. There is no analytics, no crash reporting, and no advertising or attribution SDKs.

There is also no web signup. You get the app from the App Store, reached through the homepage.

Move your photos into the vault, step by step

The import is a copy, not a move. Keep that in mind through every step below. The last step is the one that actually takes the photo out of the camera roll.

Create your pattern and save the recovery phrase

Setup asks you to draw a pattern on a 5x5 grid. The pattern needs at least 6 dots and 2 direction changes. You draw it twice to confirm. See pattern unlock for how the unlock screen works.

Each vault also gets its own 12-word recovery phrase. It is shown once during setup. Write it down somewhere that is not the phone.

Import from the Photos picker

Tap Add Files. The sheet offers Photos or Files as the source. Choose Photos and select the items you want.

A progress dialog reads 'Encrypting to vault'. It tells you to keep the app open until it finishes. Do so. Leaving early is how an import gets interrupted.

You can also capture new photos directly into the vault with the secure camera, so they never reach the camera roll in the first place.

Delete the originals yourself

Importing copies the photo in. It does not remove the original. Per the app's own sheet, originals stay in Photos, or in their original location, unless you delete them there.

So the user has to delete the originals from Photos. Open the vault first and confirm the imported items open correctly. Then delete the originals in Photos.

One more detail. Deleted Photos items may stay in Recently Deleted for about 30 days. The copy is therefore not gone from the phone immediately. If you want it gone sooner, clear Recently Deleted as well.

How the vault opens: a pattern, not a passcode

There is one credential. It is the pattern. There is no separate passphrase to remember or type.

Weave Vault dark lock screen with a pattern drawn on a 5x5 dot grid The lock screen is the single credential: a pattern drawn on a 5x5 dot grid, with no passcode field beside it.

The key hierarchy in one paragraph

The order is this. The unlock pattern goes through Argon2id. That produces a key-encryption key. The key-encryption key wraps a random 256-bit per-vault content key, generated by a CSRNG. The Argon2id-derived key does not encrypt file contents directly. Argon2id runs with the parameters in RFC 9106: t=3, m=64 MiB, p=1, over a 128-bit salt.

That structure means the file encryption key is random, not derived from your pattern. The pattern only unlocks the key that holds it.

What an unrecognised pattern does

An unrecognised pattern opens a fresh, empty vault. It does not show an error. The app keeps no vault list, no switcher and no count. Someone guessing a pattern gets an empty vault, not a message that tells them the guess was wrong. Related reading: multiple vaults.

The pattern is never written to disk

The pattern is never written to disk. Not to a file, and not to the Keychain.

The app states its limit in one sentence, quoted as published: "We make no claim about what an examiner with the physical device could or could not determine." Do not read this guide as a promise that a forensic pull would recover nothing. It makes no such promise.

Keep hidden photos organised, and what is free versus Pro

Once photos are in the vault, you may want them grouped. That is where the free and Pro split matters.

Weave Vault Private folder grid of ten personal photos Personal photos grouped in their own folder inside the vault, which is the organisation the folders paragraph below describes.

Folders inside the vault

Folders group files inside a vault, as the screenshot shows. Folders are a Pro feature. See folders for the details.

Free tier limits

The free tier allows up to 3 vaults and up to 50 files per vault. There is no claim of unlimited storage, and none should be assumed.

What Pro adds

The manifesto puts it in one line, verbatim: "Pro opens doors: more vaults, encrypted backup, sharing, folders."

Pro is sold as a monthly subscription, an annual subscription with a 7-day trial, or a one-time lifetime purchase. Current terms are in the App Store listing. Browsing and exporting your own files work without a subscription, including if Pro lapses.

What can go wrong: lost patterns, backup and sharing

A vault that nobody can open for you is a vault you must be able to open yourself. These are the three places it can go wrong.

If you lose the pattern and the phrase

If both the pattern and the phrase are lost, the vault cannot be opened. The support page says it directly: "we do not hold a copy, and there is no support process that can override this." Read support before you rely on a vault for the only copy of a photo.

Backup: enabling versus restoring

There is no Weave Vault vault-storage server. Encrypted backup copies the vault's ciphertext to your own iCloud or Google Drive. No vault key and no plaintext leaves the device. See encrypted backup.

Nothing is uploaded by default. Weave Vault is also excluded from the phone's ordinary device backup by design, so a routine iCloud or Finder backup of the phone never contains it.

The split is exact. Enabling backup requires Pro. Restoring never does. The support page's wording is "requires Pro; restoring never does."

Sharing a copy

Sharing sends a point-in-time copy of a whole vault. It is re-keyed from scratch each time. It carries an enforced expiry, and you can revoke it early from Shared vaults in the vault's settings. Recipients do not need a vault of their own and do not need to pay. More in secure sharing.

The short version

Hiding a photo re-files it. Encrypting it makes the file unreadable without the pattern. To get a photo out of the camera roll, import it into the vault, check that it opens, and delete the original from Photos. Then clear Recently Deleted if you want it gone sooner. To start, find Weave Vault through the homepage and the App Store link there.

← All posts