PrivateVault PRO – Offline Encrypted File Vault & Manager
PrivateVault PRO protects photos, videos, documents, audio, archives, notes, and other files in a local encrypted vault—without accounts, cloud, backends, ads, analytics, or network-access permission. Content and authenticated metadata are encrypted on-device, with vault files kept in app-private storage outside galleries, media scanners, and file-manager browsing.
Argon2id Password + Recovery-Code Protection
● Random 256-bit Vault Master Key (VMK): your password is not used directly as the file-encryption key
● Argon2id v1.3: 64 MiB memory, 3 passes, parallelism 4, random 32-byte salt, strict UTF-8 without normalization, and 256-bit output
● Memory-hard derivation raises offline guessing cost; KDF descriptors are versioned and allowlisted
● Two-secret design: the password-derived key and random 256-character recovery code are combined with HMAC-SHA256/HKDF-SHA256 to protect the VMK in an authenticated AES-256-GCM envelope
● A device-local recovery-code copy is encrypted under a non-exportable Android Keystore key, hardware-backed when available
● Supported PBKDF2-HMAC-SHA256 vaults remain unlockable and upgradeable compulsorily
● Passwords/recovery codes are not stored in recoverable plaintext. New passwords support 8–127 UTF-16 code units
Authenticated Vault Encryption
● AES-256-GCM: modified ciphertext fails authentication
● PVL2: files stream in independently authenticated chunks with fresh random nonces and authenticated structure
● PVMD: entries, folders, revisions, active blob references, and repository state use versioned authenticated metadata
● Activity logs are encrypted locally and re-encrypted after credential changes
Authentication & Access Controls
● Elapsed-time brute-force limiter that resists device-clock changes
● Secure biometric unlock through a device-bound Android Keystore wrapper
● Optional 2FA Unlock requires password + biometric when enabled
● Data Control authorization for sensitive operations
● Panic Lock clears temporary decrypted files, locks the vault, requires password plus biometric both, and applies a 10-minute lockout after one and only failed attempt; Although panic lock sensitivity is adjustable
● Optional Intruder Selfie stores failed-unlock attempts evidence locally depending on camera's availability in newer android versions
Encrypted File Manager
Import, organize, search, sort, filter, rename, copy, move, pin, star, inspect SHA-256 hashes and metadata, manage revisions, and delete encrypted items.
Private Media, Documents & Notes
View supported images, video, audio, PDFs, archives, text, and code. Create encrypted notes, capture media, scan images into encrypted PDFs, inspect archives, and use supported editing or conversion tools.
Recovery Backups & Encrypted Sharing
● New recovery-enabled backup versions require the backup password and exact saved 256-character recovery code to restore
● Authenticated headers, manifest, entry structure, payload, and destination hashes are verified before restored metadata becomes active
● Backup and restore are streamed, bounded, and staged before final activation
● PPSH1 shared encrypted files use password-only Argon2id and AES-256-GCM, so recipients do not need your recovery code
● Pv PRO can open, re-import, and change a PPSH password after authenticating and independently verifying the replacement
Important Security Boundary
Vault content is encrypted at rest. Plaintext intentionally exported, shared, or opened in another app is outside the vault and no longer protected by PrivateVault encryption. App-private temporary copies are scheduled for cleanup.
Keep your password and recovery code safe: neither can be recovered. Recovery code-enabled backups need both after reset or reinstall and only recovers in Pv PRO.
Offline encryption app to manage confidentiality & integrity of important files