Export is the moment protection ends
Everything a vault does applies to content inside its boundary. An export deliberately crosses that boundary, and from that instant the file is governed by wherever it landed.
That destination may generate a thumbnail, upload automatically to a cloud library, include the file in the next system backup, add it to a recents list, and hand a copy to whoever you shared it with. None of that is reversible from inside the vault.
Choose the destination before you unlock
A share-sheet destination chosen under time pressure can synchronise an exported file unexpectedly. Choosing the destination and cleanup steps beforehand reduces that risk; it does not remove every copy the destination may create.
Decide what needs to leave, where exactly it is going, and what you will do with the copy afterwards — then unlock.
Verify the export before deleting anything
Confirm dimensions, dates, video playback, and filenames on the exported copy. An export can silently transcode, strip metadata, or produce a file that opens as a thumbnail but fails at full size.
Never delete the vault copy on the assumption an export succeeded. Verify first, delete second, in that order without exception.
Clean up afterwards
- Export only the specific items needed, not a bulk selection.
- Verify full files at the destination before relying on them.
- Complete the external task, then lock the vault.
- Remove temporary copies from Photos, Files, Downloads, editors, and message threads.
- Empty the relevant Trash or Recently Deleted once you are certain.
The two costly errors
- Bulk exporting into a cloud-synced gallery by accident.
- Deleting the vault copy before confirming the export actually worked.
A fictional example
Sofia starts with a non-sensitive test: “Choose the destination before unlocking.” Next, Sofia follows the second check: “Verify dimensions, dates, video playback, and filenames.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Bulk exporting to a cloud-synced gallery by accident
- Deleting the vault copy before confirming the export
What this workflow does not change
- Bulk exporting to a cloud-synced gallery by accident
- Deleting the vault copy before confirming the export
Questions people ask
Can support export a vault that will not open?
Not when genuine encryption requires a missing user secret; preserve backups and use documented recovery.