Recovery depends on what already existed elsewhere
This is the moment when the backup arrangement you actually had, rather than the one you intended, determines the outcome. If the private data existed only on the missing phone, no tool creates it now.
That is bleak but it is worth stating plainly, because the alternative is spending the first hours pursuing options that were never going to work.
Secure the accounts first
Before any recovery attempt, deal with the sessions the phone was carrying. Change credentials on exposed accounts and revoke active sessions rather than only changing passwords, prioritising anything that can reset other accounts.
This is time-sensitive in a way the file recovery is not. The backup will still be there in an hour; an attacker's window may not be.
Think before erasing remotely
Remote erase reduces the chance of someone reaching the device's contents, and it also ends any remaining possibility of recovering data held only there.
If your vault content is covered by a tested backup, this is easy. If it is not, you are weighing exposure against permanent loss — and that decision deserves more than the first few minutes of panic.
What a recovery phrase does and does not do
A recovery phrase authorises recovery. It does not contain your files. Holding the phrase without a backup gives you the ability to unlock something that does not exist.
This distinction disappoints people at exactly the wrong moment, which is why it is worth internalising before you need it.
The order that works
- Use the platform's lost-device controls and secure any exposed accounts.
- Hold off on remote erase until you understand its effect on any remaining recovery path.
- Locate the most recent independent encrypted backup and its matching phrase.
- Restore onto a trusted replacement device — not a borrowed one.
- Verify representative files opened correctly before considering it resolved.
Mistakes made under pressure
- Assuming the recovery phrase contains the files themselves.
- Erasing remotely before checking what recovery options remain.
- Restoring private content onto an untrusted or borrowed device.
A fictional example
Priya starts with a non-sensitive test: “Use the platform's lost-device controls and secure exposed accounts.” Next, Priya follows the second check: “Do not erase remotely until you understand the effect on any remaining recovery path.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Assuming a recovery phrase contains the files
- Rushing to erase before checking recovery options
- Restoring on an untrusted borrowed device
What this workflow does not change
- Assuming a recovery phrase contains the files
- Rushing to erase before checking recovery options
- Restoring on an untrusted borrowed device
Questions people ask
Can NullVault device recovery restore a lost device?
No. The documented same-device phrase can replace a forgotten pattern while that vault remains on the same device.
What if no backup exists?
Local-first encryption may make remote recovery impossible by design.