Are Photo Vault Apps Safe?
Some are, in a specific sense you can check. The label tells you nothing. The signs that separate an encrypted vault from a PIN screen, and the risks that apply to every vault app, including ours.
Some are, in a specific sense you can check. A vault app is safe to the extent that it encrypts your files with a key only you hold, and says what it does not protect against. The word vault on its own tells you neither. Five signs separate an encrypted vault from a PIN screen over ordinary files, and all five can be checked before you install. Four risks apply to every vault app, whatever its design, including ours.
1. What safe has to mean
Safe from what, and from whom? A vault app is asked to do two different jobs. The honest answer to "is it safe" depends on which one you mean.
- Keeping a photo out of sight when someone is holding the phone, or when a widget or a Memory brings it up. Almost every app of this kind does this. So does the built-in Hidden album.
- Keeping the file unreadable by a person who has the phone and the passcode, or a copy of the storage. Only an app that encrypts the files with a password separate from the passcode does this. That is what a photo vault app is in the sense the word suggests.
These apps are sold on the second job and often deliver the first. That is not always dishonest, because for many people the first job is the whole problem. It becomes a problem when someone picks an app for the second job and gets the first. The rest of this page is how to tell, and then what the second kind still cannot do.
2. Five signs you can check
All from the App Store listing and the developer's website, before you install anything. Our ranked comparison applies these to six named apps with sources. This is the general version.
It names what it encrypts, and how
An encryption method, a way of turning your password into a key with a round count, and what is covered: photos, videos, thumbnails, and the database of names and albums. Those are four separate things. "AES-256-GCM, PBKDF2 at 600,000 rounds" is a claim you can check and hold the developer to. "Bank-level" or "military-grade" promises nothing. An app that encrypts only its settings could say it truthfully. What the terms mean is a separate guide.
It says whether the developer can get your photos back
This is the most telling single question. If the answer is yes, the developer holds something that can unlock your files without your password. The protection is against outsiders, not against the developer. If the answer is no, a forgotten password is permanent. Both are legitimate. A developer who will not answer clearly is the problem.
Its privacy label matches its pitch
The App Privacy section is where the developer says what the app collects. Read it for fit. An app that offers cloud backup and lists User Content makes sense. An app whose whole pitch is "nothing leaves your phone", but which lists heavy tracking, deserves a closer read of its privacy policy. The label is the developer's own answer, and nobody checks it. That applies to ours too.
It works in Airplane Mode
The one sign you can test rather than read. Install the app, turn on Airplane Mode, use it normally. An app that works fully offline is not uploading anything while offline. That does not prove what it does when online. But it is something you saw rather than something you were told, and there are few of those in this category.
It writes down its limits
The strongest sign there is. Every real design has limits. A developer who has thought it through can state them, because they had to work them out to build the app. Look for a security page that uses the words "does not protect against". A page that lists only strengths means either nobody looked, or somebody did and chose not to say.
3. Risks that apply to every vault app, including ours
These do not go away with better encryption. Obscura Photo Vault is subject to all four, and the security paper says so.
A forgotten password
For an encrypted vault with no reset, this is the most likely way to lose your photos. It is far more likely than any attack. It is the same fact as "nobody else can open it", seen from the other side. The two habits that protect against it, a password manager and a tested export, are in what happens if you forget your vault password.
The originals
Moving a photo into a vault copies it. The original is still in your library until you delete it. Then it is in Recently Deleted for thirty days, and in iCloud Photos until the deletion catches up. During that time it is behind a lock your phone passcode opens. No vault app can reach into Photos and fix this for you. Our guide to where a photo persists on an iPhone lists every place.
A phone compromised while the vault is open
To show you a photo, the app has to unscramble it. So the key and the readable photo are in memory. Anything running inside the app at that moment can reach both. No app-level encryption fixes a broken phone, and no developer should claim otherwise.
The app is visible, and so is the phone
A vault icon says there is something in it. A disguise changes the icon, not the App Store purchase history or the Settings list. Screenshots, screen recording and someone looking over your shoulder all happen after the photo is unscrambled. Encryption hides contents. It does not hide that there is something to hide.
4. Risks specific to vaults with a server
A vault that syncs to an account gains real things: access from several devices, a copy that survives a lost phone, and usually a password reset. It also gains a second place where your data lives, with risks a phone-only vault does not have:
- A server that holds copies, with its own risk of being breached, its own staff, and its own legal exposure.
- An account that can be attacked, by phishing, by SIM swapping, or by reusing a leaked password, separately from the vault password.
- A recovery process, which is a path that can go wrong, be tricked, or be forced. If it can give you your photos back, in principle it can give them to someone convincing enough.
- A dependence on the developer staying in business. A phone-only vault you have exported outlives the developer. A cloud vault may not.
None of this makes cloud vaults unsafe as a group. It makes them a different trade. Where the encryption keys live is what decides how that trade comes out. Our guide to the four kinds of app sets the designs side by side.
5. What you cannot check from outside
Two things, and a page like this that hinted otherwise would be selling something.
Whether the app does what its description says. Without the source code or an independent audit, "AES-256-GCM" is a claim. Everything above tests whether a developer is specific and frank. That usually goes with care. It does not prove the app is correct. Nobody has audited our app either.
Whether there are subtle mistakes. Most real encryption failures are good methods used slightly wrongly: a number reused that should never be, a key made too cheaply, a thumbnail left readable in a cache. None of that is visible on a product page, and often not from outside the company at all.
So the realistic goal is not certainty. It is narrowing the field to developers who make claims you can check and who describe their own limits. Then keep a tested export somewhere safe, which protects you against the developer as well as against the phone. How to do that, and what deleting the app actually removes, is in deleting or moving a vault app.
6. Common questions
Are photo vault apps safe?
Some are, in a specific sense. They encrypt your files on the phone with a key made from a password only you hold, and they say in writing what that does not protect against. Others put a PIN screen in front of ordinary files, which protects against a glance and little else. The word vault does not tell you which. What tells you is the listing's encryption claim, the privacy label, and whether the developer writes down the limits.
Can photo vault apps see your photos?
It depends on the kind. An app with no server and no account has nowhere to send them, and you can test that in Airplane Mode. An app that syncs to a cloud account keeps copies on its servers. Whether the developer can read them depends on who holds the encryption keys. If the developer can reset your password and give your photos back, the developer holds a key. Privacy labels are the developer's own answer, ours included, so treat them as claims.
What is the biggest risk of using a photo vault app?
For an encrypted vault with no reset, forgetting the password. That is permanent. For every kind of vault, the originals. The photo you moved is still in your library until you delete it, then in Recently Deleted for thirty days, and in iCloud until the deletion catches up. A vault is only as private as the clean-up afterwards.
Can a photo vault be hacked?
Any software can have flaws, and no app on this site is described as beyond attack. What encryption changes is what an attacker needs: your password, or access to the phone while the vault is unlocked. A vault that encrypts, and says where its limits are, narrows the ways in. It does not remove them.
Is a vault app safer than the iPhone Hidden album?
Against different things. The Hidden album opens with your phone passcode and syncs to iCloud. An encrypted vault opens only with its own password and can keep everything on the phone. If the risk is a glance, they are the same. If the risk is someone with your passcode or your Apple Account, only the encrypted vault deals with it.
Sources
- Apple Support: Delete photos on your iPhone or iPad, on Recently Deleted
- Apple Support: iCloud data security overview
- OWASP Password Storage Cheat Sheet, on key derivation work factors
- Obscura Photo Vault security paper, section 11, on what falls outside the threat model
Obscura Photo Vault
An encrypted photo vault for iPhone. Photos and videos are encrypted on your device with AES-256-GCM. There are no accounts, no servers and no analytics, and the app does not require a network connection. If you forget your password, nobody can recover the contents, including us.
View on the App Store →