1. Decide what you are protecting against

Write down the realistic situation first. Are you concerned about:

  • someone scrolling through an unlocked phone;
  • a lost or stolen locked device;
  • an image appearing in recents, search, sharing suggestions, or a cloud library;
  • another person knowing one vault pattern;
  • device loss or damage;
  • spyware or a compromised operating system?

An encrypted vault can help with the first five when configured carefully. It cannot reliably protect content from a compromised device that observes the moment you unlock or view it.

2. Use encryption, not only a hidden album

A hidden system album changes where a photo appears. An encrypted photo vault stores its managed copy as ciphertext and requires vault access before rendering it.

NullVault's pattern-locked vaults take this further: different patterns address different vaults, and the ordinary interface does not display a master vault list. That reduces casual discovery but is not a claim that all traces of vault use disappear.

3. Import carefully

When NullVault is available, use the in-app import flow or private camera and import feature. Before removing anything from the original location:

  1. Open the imported item inside the vault.
  2. Check that the full image—not only a thumbnail—renders correctly.
  3. Confirm any Live Photo, RAW, edit, or paired-media behavior that matters to you.
  4. Lock the vault and confirm the item opens again after unlocking.
  5. Verify your recovery or backup plan if the image is irreplaceable.

Do not delete the only known-good original until you have verified the protected copy.

4. Understand what deleting the original means

Removing a source photo from Apple Photos, Google Photos, a gallery, or file storage is controlled by that service and operating system. It may move to a Recently Deleted or Trash area, remain in a cloud library, exist on another synchronized device, or persist in storage history.

NullVault cannot promise physical erasure from flash. Deletion should be understood as removal from the active location, not proof that every historical copy is gone. Review security limitations before relying on deletion for a high-risk situation.

5. Choose an uncommon vault pattern

Avoid a simple letter, straight line, familiar phone-unlock gesture, or shape that someone has seen before. Use a longer gesture with changes in direction and broad grid coverage.

Each NullVault pattern addresses a vault. Keep the pattern private and shield the screen while drawing it. A memory-hard derivation can slow guessing, but it cannot make a predictable pattern unpredictable.

6. Lock early and reduce screen exposure

Enable a short automatic-lock interval and let the app lock when it moves to the background. NullVault's automatic lock is designed to revoke active app access when attention moves elsewhere.

Those controls cannot stop another camera or a compromised device. View private content only where the physical surroundings and device are trustworthy.

7. Plan for a forgotten pattern and a lost phone

Recovery and backup are different:

  • On Android, same-device recovery and portable backup recovery are separate flows with separate phrases.

Read recovery phrase versus encrypted backup and store any phrase offline. Never email it to yourself, paste it into chat, or send it to support.

8. Treat every export as a new copy

An export intentionally moves plaintext outside NullVault's managed encrypted storage. The destination may create thumbnails, previews, backups, logs, or synchronized copies. Use secure export only when you trust the receiving app, person, and storage location.

Encryption does not prevent a recipient from photographing, exporting, or retaining content after access.

A short safety checklist

  • The vault copy opens correctly after a lock and unlock.
  • The pattern is uncommon and not reused.
  • Automatic locking is enabled.
  • Recovery material is stored offline and separate from the phone.
  • Any backup needed for device-loss recovery has been tested.
  • The original photo's other locations and trash folders are understood.
  • No unnecessary plaintext export remains.
  • The device is updated and not believed to be compromised.

Questions people ask

Is an encrypted vault safer than a hidden album?

For protection while locked, yes: encryption protects the managed file contents, while a hidden album may only change visibility. Neither approach can protect a screen or plaintext on a compromised device.

Should I delete the original immediately after import?

No. First verify the complete protected copy, confirm it survives a lock/reopen cycle, and make any recovery or backup you need. Then decide knowingly how the source service handles deletion and trash.

Will the photo disappear from every cloud service?

Not automatically. Check every library, synchronized device, shared album, message, export, and backup where the original may exist.

Can NullVault hide that I use a vault app?

No. The app installation and encrypted storage may be observable. Hidden-vault design concerns the ordinary vault list and scoped discovery, not concealment of the app itself.

Guide reviewed: 11 August 2026.