Choose for iPhone, Android and your budget

For iPhone, compare the built-in Hidden album with a vault that uses an independent credential. Start with how to hide photos on iPhone. For Android, decide whether you need a protected media folder, a Samsung app workspace, or separate content vaults; see how to hide photos on Android.

If you want a photo vault without ads or recurring payments, check the current store disclosure and paid-tier conditions separately. A free download, an ad-free experience and a one-time purchase are different promises. NullVault pricing lists verified iPhone limits and directs Android users to its current store offers. Keep the backup and recovery requirements in the decision even when the download is free.

Compare options for your platform

Reviewed 11 September 2026. This table compares documented workflows, not results of an independent security test. NullVault Team publishes this guide. These are starting points, not an exhaustive ranking; check current device requirements and store offers before choosing.

Option and platform Account and storage Cost Backup and recovery tradeoff
Apple Hidden album, iPhone Part of Photos; no separate vault registration. Hidden items remain in the photo library; iCloud Photos can sync them. Included with Photos; cloud storage may cost extra. Hiding is not a backup. Recovery depends on the copies and backup arrangements you keep.
Google Photos Locked Folder, Android Uses the device screen lock, not a separate folder password. Google Account sign-in is used for backup and access on other devices. Available in Google Photos; cloud storage limits and paid plans apply. Google warns that unbacked-up local items can be lost after app deletion, clearing data or device loss.
NullVault, iPhone and Android Local encrypted spaces opened by separate patterns; no NullVault account for core offline use. See platform-specific plans. iPhone offers Free and optional Pro purchases; Android offers must be checked separately. Keep the appropriate recovery credential and a tested encrypted backup. Optional online services differ by platform.

On iPhone, start with Hidden album if keeping items out of the ordinary photo view meets your needs. On Android, evaluate Locked Folder if using the device screen lock is acceptable. Consider a separate vault when you need unrelated credentials or independently addressed spaces. Compare Hidden album, Locked Folder and NullVault recovery in more detail.

A vault is a system, not a lock screen

Almost every vault app looks the same at the moment of unlock, which is why screenshots are a poor basis for choosing one. The differences appear across the whole lifecycle: import, storage, unlock, display, export, backup, restore, deletion, and support.

Weakness or ambiguity at any one of those stages can undermine an otherwise impressive encryption claim. Evaluate the chain, not the padlock.

Confirm availability before anything else

Check that the product actually ships on your platform, in your region, at the version you are reading about. Vault apps are frequently reviewed based on announcements, roadmaps, or the other platform's feature set.

Platform differences are normal and not a red flag in themselves — but a vendor that blurs them into a single promise is telling you something about how it handles other claims.

Read the storage and key model

Look for a documented answer to four questions: what algorithm and mode protect file contents, how the key is derived from your credential, where that key material lives while the app is closed, and whether filenames, thumbnails, and metadata are protected alongside the files.

A vendor that publishes this is inviting scrutiny, which is itself a signal. A vendor that publishes only a cipher name is asking for trust it has not evidenced.

Understand the account model

Whether an account is required changes the threat model substantially. An account-free local vault removes a whole category of remote risk and shifts recovery entirely onto you. An account-based vault can offer convenient reset paths, at the cost of a party who can potentially authorise access.

Neither is universally correct. What matters is that you know which one you chose and why.

Test the full lifecycle with files you do not care about

  • Confirm the product is genuinely available for your platform and version.
  • Read the storage, key derivation, metadata, and account documentation.
  • Import an original-quality file and verify it plays or opens correctly inside the vault.
  • Lock fully, reopen from a cold start, and export the file again.
  • Create a backup, restore it after a reinstall, and open real content from the restored copy.
  • Read the limitations page and confirm what happens after uninstall or device loss.

How to read the marketing

  • Choosing from screenshots or an app icon rather than documentation.
  • Trusting “military-grade” or similar labels that describe nothing specific.
  • Treating a disguised icon as a security control rather than a social one.
  • Skipping restore testing because the import worked.
  • Assuming a high store rating reflects security review rather than usability.

The question most people skip

Ask what happens on the worst day: the phone is lost, the app is gone, and you have forgotten the credential. Whatever the answer is, it should be documented before you commit content to the vault.

A vault that cannot answer that question clearly is not a product to rely on until its recovery behavior is clarified. That ambiguity does not establish that its confidentiality is equivalent to the camera roll.

A fictional example

Leo starts with a non-sensitive test: “Confirm the product is actually available for your platform.” Next, Leo follows the second check: “Read the storage, key derivation, metadata, and account model.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Choosing from screenshots alone
  • Trusting vague encryption labels
  • Skipping restore testing

What this workflow does not change

  • A comparison of published documentation does not establish an independent security audit.
  • Availability, prices and optional services can differ by platform and region.
  • A vault cannot protect copies already exported or content visible in a compromised session.

Questions people ask

Does a calculator disguise add encryption?

Not by itself. Camouflage and cryptographic protection are separate features.

Should a vault have a master list?

That depends on usability needs. NullVault deliberately avoids a visible master list and maps different patterns to different spaces.

Sources and further reading