The feature
Why it matters
Keep a recoverable encrypted copy without treating cloud storage as an unlocked photo library.
01
Encrypted before destination storage
On Android, NullVault creates a portable encrypted package before handing it to the compatible storage destination you select. That destination may be local storage or a document provider with its own synchronization and retention behavior.
The backup is not a normal plaintext gallery. A restore needs both the valid encrypted package and its matching backup recovery phrase.
02
Restore needs both key material and data
A recovery phrase is key material, not a compressed copy of the library. Portable Android recovery needs both its separate backup phrase and the encrypted backup file that contains the protected data.
Keep the encrypted package and its phrase in different safe locations. Duress and panic wipe affect future local access but do not remove exported backup files.
Documentation basis
Documented claims
- iOS CloudKit backup stores encrypted objects and restores only a matching authenticated generation with the original recovery phrase.
- Android creates portable encrypted backups that restore with a separate backup recovery phrase.
Know the boundary
Important limitations
- A lost backup phrase cannot be reconstructed by NullVault support.
- A backup destination or synchronized provider may retain versions according to its own storage and deletion behavior.
- Duress, panic wipe, and ordinary local deletion do not guarantee removal of exported backup files.
Clear answers
Questions about this feature
Is the Android backup a normal gallery folder?
No. NullVault creates a portable encrypted package rather than exporting the vault as a folder of plaintext photos and files.
Is the recovery phrase enough without a backup?
No. The phrase does not contain the vault's media and files; clean-install recovery also needs a valid matching encrypted backup.
Does panic wipe delete my exported backup?
No. Exported encrypted backup files are separate copies and are not deleted by the local panic-wipe or duress action.