Separate account protection from file recovery: a locked vault may protect its local copy, but recovering your files depends on a surviving backup and the right credentials.
Work from a device you trust
Use the device maker's official lost-device service and account guidance. Be cautious with unsolicited messages claiming that the phone was found or asking for your account password. A missing device and a compromised cloud account are different problems, even if they happen together.
Do not assume that a remote action has completed simply because you requested it. Connectivity, device state and the platform's rules determine what happens next. Keep the recovery problem separate from any decision to erase a device.
Check what survives
| What you have | What it means |
|---|---|
| A tested encrypted backup and its phrase | Follow the documented restore process on a compatible trusted device |
| A phrase but no surviving vault data | The phrase cannot recreate missing file bytes |
| A cloud photo-library copy | Its account access and sharing rules still matter |
| Only the missing phone | Local-only files may be unrecoverable |
NullVault's part of the boundary
Automatic lock and local encryption reduce exposure under their documented device assumptions. They do not prove whether a person observed an earlier unlock or already held a copy.
The phone-theft checklist provides the wider account and device sequence. The recovery guide explains what you need for the data itself. After recovery, rebuild your backup arrangement before storing new irreplaceable material.