Decide which risk you are addressing
Three different problems get the same question, and they need different answers: another person using your Mac while you are logged in, someone stealing the machine, and someone reaching your iCloud account.
FileVault addresses the second. A separate macOS account addresses the first. Neither addresses the third. Choosing before configuring saves considerable effort.
FileVault protects a powered-down Mac
FileVault protects data at rest, especially on a powered-off Mac. Logging out alone does not guarantee that volume keys are unavailable. After volume unlock, macOS permissions and session controls still govern file access.
FileVault does not hide accessible files from someone using your unlocked session. A separately encrypted container can retain its own access boundary while it remains locked or unmounted.
Photos Hidden is still Photos
The Hidden album on macOS behaves like its iOS counterpart: it moves items out of ordinary view within the Photos library, and it remains subject to iCloud Photos synchronisation.
It solves casual browsing. It does not create a separate encrypted container, and the hidden state travels to your other devices.
Options in order of separation
- Photos Hidden — casual concealment within the library.
- A separate macOS user account — genuine separation from another person using the machine.
- An encrypted disk image — a distinct encrypted container with its own password.
- A properly designed vault application — encrypted storage with its own credential and recovery.
Before you move anything
- Decide whether the risk is another user, theft, or account compromise.
- Check iCloud Photos sync status before moving or deleting items.
- Test opening and backing up an encrypted container before trusting it.
- Confirm what your Time Machine or other backup captures.
Two false protections
- Using Finder's hidden-file flag, which is a display convention anyone can toggle.
- Leaving an encrypted disk image mounted during a shared session, which makes it an ordinary folder.
A fictional example
Priya starts with a non-sensitive test: “Decide whether the risk is another Mac user, account theft, or device loss.” Next, Priya follows the second check: “Check iCloud Photos synchronization before moving or deleting anything.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Using Finder's hidden-file flag as security
- Leaving an encrypted disk image mounted on a shared session
What this workflow does not change
- Using Finder's hidden-file flag as security
- Leaving an encrypted disk image mounted on a shared session
Questions people ask
Does FileVault lock one photo folder?
No. FileVault encrypts volumes at rest. A screen lock or logout is not a separate encrypted folder; use a locked encrypted container for that boundary.