Export is the moment protection ends

Everything a vault does applies to content inside its boundary. An export deliberately crosses that boundary, and from that instant the file is governed by wherever it landed.

That destination may generate a thumbnail, upload automatically to a cloud library, include the file in the next system backup, add it to a recents list, and hand a copy to whoever you shared it with. None of that is reversible from inside the vault.

Choose the destination before you unlock

A share-sheet destination chosen under time pressure can synchronise an exported file unexpectedly. Choosing the destination and cleanup steps beforehand reduces that risk; it does not remove every copy the destination may create.

Decide what needs to leave, where exactly it is going, and what you will do with the copy afterwards — then unlock.

Verify the export before deleting anything

Confirm dimensions, dates, video playback, and filenames on the exported copy. An export can silently transcode, strip metadata, or produce a file that opens as a thumbnail but fails at full size.

Never delete the vault copy on the assumption an export succeeded. Verify first, delete second, in that order without exception.

Clean up afterwards

  • Export only the specific items needed, not a bulk selection.
  • Verify full files at the destination before relying on them.
  • Complete the external task, then lock the vault.
  • Remove temporary copies from Photos, Files, Downloads, editors, and message threads.
  • Empty the relevant Trash or Recently Deleted once you are certain.

The two costly errors

  • Bulk exporting into a cloud-synced gallery by accident.
  • Deleting the vault copy before confirming the export actually worked.

A fictional example

Sofia starts with a non-sensitive test: “Choose the destination before unlocking.” Next, Sofia follows the second check: “Verify dimensions, dates, video playback, and filenames.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Bulk exporting to a cloud-synced gallery by accident
  • Deleting the vault copy before confirming the export

What this workflow does not change

  • Bulk exporting to a cloud-synced gallery by accident
  • Deleting the vault copy before confirming the export

Questions people ask

Can support export a vault that will not open?

Not when genuine encryption requires a missing user secret; preserve backups and use documented recovery.

Sources and further reading