Panic wipe is an emergency action intended to remove future access to protected local content; its name alone does not establish physical erasure of storage or deletion of remote copies.
Read the outcome, not just the button label
Apps use wipe, reset and delete to describe different operations. An action might remove database entries, delete files, invalidate keys, or combine several steps. Each has different consequences for recovery. A clear product description identifies the local data affected and the copies outside the action's control.
NIST's media-sanitization guidance treats sanitization as a process whose method and assurance need evaluation. A marketing word or an empty interface is not evidence that every physical trace is gone.
Account for copies first
An encrypted export, device snapshot, cloud backup or recipient download may survive a local wipe. The same applies to a plaintext copy that left the vault before the action. A test should therefore ask what remains outside the app, not only whether the local list is empty.
NullVault's boundary
NullVault documents panic wipe and duress behavior separately, with platform-specific availability. Their descriptions limit the claim to the documented local effects; they do not guarantee erasure from flash storage or deletion of remote copies.
Before deciding to enable an emergency control, inventory what you need to retain and understand the recovery consequences. Use the encrypted-backup checklist and copy audit with harmless sample data. Never treat a destructive control as a substitute for personal safety planning.