Vault
A place in this browser to keep files encrypted. They are encrypted on your device before they are stored, and open again with a passkey or a recovery code. Nothing is uploaded: after it loads, this page cannot send anything anywhere.
The files stay in this browser on this device; browsers do not sync them. What can travel is the key: a synced passkey opens the vault on another device once you bring the files there with a backup.
Opening the vault…
A new version of the vault is ready.
This browser can't hold a vault
The vault needs the browser's private file storage and background workers. Private windows often turn the storage off; a normal window in a current browser has both.
Make a vault
On iPhone and iPad, an app added to the Home Screen keeps its storage apart from Safari's: a vault made here is not in the app, nor the other way round. If you want the app, add it to the Home Screen first and make the vault there.
Or bring one back
A backup exported from a vault: a .tar file. Its passkeys or its recovery code open it here.
Locked
Use the recovery code
Add without unlocking
Files added now are encrypted to the vault's public key, which opens nothing. They wait, encrypted, and join the vault the next time it is unlocked.
No files yet. Add some, or drop them on this page.
Storage
Backup
One .tar file with everything, still encrypted. Import it into a browser without a vault, or read it with the age tool and the vault's key.
Ways to unlock
Removing a passkey here stops it opening the vault; the passkey itself stays in your password manager until you delete it there.
Delete the vault
Deletes every file in it from this browser. Backups and passkeys elsewhere are not touched.
How it works
Making a vault makes a key: a post-quantum key in the age format, from random numbers made on this device. Every file you add is encrypted to it as it is read, in small pieces, so even a large file never sits in memory whole, and stored in the browser's private file storage for this site. So are the names, types and sizes, in an encrypted list. The key itself is only ever stored encrypted: once to the recovery code, and once to each passkey, through its PRF extension. Unlocking opens one of those, and the key stays in memory until you lock, close the page, or leave it alone for 15 minutes.
The page can be installed as an app, and works offline. On Android, it shows in the Share menu: what you share is encrypted into the vault without unlocking it, and waits there until you do.
Browsers can delete a site's storage when space runs short, or, in Safari, after a week without a visit (apps on the Home Screen excepted). Asking the browser to keep it helps; a backup is the only sure way.