If the app is NullVault
A forgotten pattern on a surviving device and a lost device require different recovery paths. On Android, the device-recovery phrase can replace the pattern while that vault remains on the same device; migration uses a portable encrypted backup and its separate backup phrase. iPhone uses its documented per-vault recovery and encrypted iCloud backup flow.
Read recovery phrase versus encrypted backup and platform backup details before changing anything. Support can explain those flows but cannot recreate missing secrets or private content. Installing NullVault does not recover photos locked inside another app.
Stop before the app decides for you
Repeated guesses can trigger lockout delays or, in products with destructive policies, an irreversible response. Stop before continuing attempts changes the available recovery options.
Put the phone down. Nothing about the situation improves with more attempts, and several things get worse.
Establish exactly what you are recovering
Recovery advice is worthless without knowing which app, which device, and which credential. A vault that locks an interface behaves nothing like one that derives an encryption key from what you type.
Write down the app name and version, the device it is installed on, whether the app is still installed with its data intact, and whether you ever created a backup or recorded a recovery phrase. That inventory determines which paths remain open.
Why support often cannot help
A vault can derive key material from your credential while also offering recovery wrapping, escrow, or another recovery mechanism. Whether support can help depends on the actual documented architecture, not key derivation alone.
That property is the point of the design, and it is also its cost. An app that can reset your access on request is making a different trade — usually a reasonable one, but one with different privacy implications you should understand before relying on it.
Where a recovery path may still exist
- A recovery phrase recorded when the vault was created, stored separately from the phone.
- A portable encrypted backup, together with whatever secret unlocks it — which may not be the credential you forgot.
- A system-level backup that captured the app's data, where the app supports restoring from one.
- For account-based vaults, a vendor reset flow — with the privacy trade that implies.
Actions that close doors permanently
Several common troubleshooting reflexes destroy the data you are trying to reach. Treat all of them as irreversible.
- Clearing app data or storage, which typically removes the encrypted content itself.
- Uninstalling and reinstalling, which on many platforms deletes the app's local documents.
- Entering a destructive duress or panic credential as a guess.
- Factory-resetting the device before confirming that a backup restores.
Contacting support without making things worse
Official support can confirm which recovery paths a given app supports, and that is worth asking. What it does not need is your private content.
Never send a recovery phrase, credential, or protected private files to anyone — including someone presenting themselves as support. A legitimate support process may request limited diagnostic metadata, but it should not require secrets or private content to recover access.
Preventing the same outcome next time
Once the immediate situation is resolved, the fix is structural rather than mnemonic. Record the recovery phrase somewhere physically separate from the phone, and create a portable encrypted backup whose secret you store separately again.
Then test it. A backup you have never restored is an assumption, and this guide exists because assumptions fail at the worst moment.
A fictional example
Eli starts with a non-sensitive test: “Confirm whether the app is still installed with its data intact.” Next, Eli follows the second check: “Locate same-device and backup recovery material separately.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Clearing app data
- Trying destructive duress or panic credentials as guesses
What this workflow does not change
- Recovery requires the correct surviving data and the credentials supported by that app.
- A purchase receipt or a new app installation does not decrypt another vault.
- Destructive troubleshooting can remove the remaining recovery path.
Questions people ask
Can NullVault device recovery replace a forgotten pattern?
On the same Android device, a configured device-recovery phrase can replace the pattern; it is not a lost-device backup.