Choosing a vault

Every photo vault says it is encrypted

The word is doing almost no work. Encrypted where, with what key, and who else holds a copy of it — those are the questions, and a store listing rarely answers any of them.

Below are eight things worth checking before you move your photos into any vault app, each with a way to check it yourself rather than take someone's word for it. Finn's own answers are here too, clearly marked, so you can hold this page to the same standard.

Eight questions

  1. Does it need an account?

    An account is an identity. An email address or phone number ties the vault to a person, creates a record on someone's server, and gives a support desk something to reset. Every one of those is a way in that has nothing to do with your PIN.

    How to checkInstall it and watch the first screen. If it asks to sign up before it shows you anything, the answer is yes.
    FinnNo account, no email address, no phone number. The first screen asks for a PIN, and any six digits create a vault.
  2. Where does the encryption happen?

    On your device, or on their server after upload? If it is the second, the operator handled your plaintext at least once, and "encrypted at rest" describes their disk, not your privacy.

    How to checkLook for the phrase "on your device" or "end-to-end" in the privacy policy, not the marketing page. Vague wording here is usually deliberate.
    FinnEach file is encrypted with AES-256-GCM on the phone, before it exists anywhere else. Each file's key is itself encrypted under a key derived from your PIN with Argon2id.
  3. What happens if you forget the PIN?

    This is the sharpest question on the list. If the app can send you a reset link, then the app can open your vault — and so can anyone who takes over that reset path.

    How to checkLook for a "forgot password" link. If one exists and it works by email, your vault is only as private as your inbox.
    FinnRecovery codes, issued once when the vault is created. Without the PIN or those codes it does not open, and that includes for us. Write them down.
  4. What does the App Privacy label say?

    The label on the App Store page is a declaration the developer is accountable for, which makes it more reliable than anything written on their website.

    How to checkOpen the App Store listing and scroll to App Privacy. Watch for Identifiers, Usage Data, and anything under "Used to Track You".
    FinnFour types: Photos and Videos, Other User Content, User ID, Purchase History. Each for App Functionality, each linked to identity, none used for tracking.
  5. Is there a decoy vault, and does it cost extra?

    A decoy matters in exactly the situation these apps exist for: someone is standing over you asking you to unlock the phone. Putting that behind a purchase is a strange decision.

    How to checkSearch the listing for "decoy", "duress" or "fake vault", then check whether it sits on the paid tier.
    FinnA second PIN opens a separate, ordinary-looking vault. Free on every account. No feature in Finn is behind the subscription — only capacity is.
  6. What happens if you stop paying?

    Ask before you subscribe, because the answers vary more than you would expect. A lapse should never delete, hide, or lock what is already in the vault.

    How to checkSearch the app's support pages for "cancel" or "expired". If nobody says plainly what happens to your files, assume the worst answer.
    FinnNothing is deleted or hidden. A lapsed account can still view, export, share and delete everything it holds. The only thing it loses is adding more, until it is back under the free limit.
  7. Does it carry analytics or advertising SDKs?

    A vault that reports your behaviour to a third party has undermined its own premise, even if the photos themselves never move.

    How to checkThe privacy label again, plus the policy's list of third parties. "We may share with partners" is the phrase to notice.
    FinnNo analytics, no usage statistics, no advertising identifiers, no third-party trackers.
  8. Will it tell you what it cannot do?

    Security marketing rewards absolute claims, so an app willing to name its own limits is telling you something about how the rest of its claims were written.

    How to checkLook for any sentence in the policy that reduces a claim rather than inflating one. Most apps have none.
    FinnThe section below is ours.

What Finn does not do

Held to the eighth question, in the same place as everything else:

  • We make no zero-knowledge claim. Your files are encrypted on your device and we hold ciphertext, but we do not assert the stronger property, and you should be sceptical of apps that assert it casually.
  • We hold encrypted copies of your media in our object storage. The first row of the privacy policy's table says so, along with exactly what form it is in. Plaintext never reaches us.
  • Deletion is cryptographic, not physical. Destroying a file's keys makes it permanently unreadable. Overwriting files on flash storage does not reliably erase them, so we do not claim that it does.
  • The browser is a browser. It blocks ads and trackers on the device and keeps no cookies or cache, but it cannot make a website you visit private, and nothing can.
  • A vault cannot protect an unlocked phone in someone's hands. That is what the decoy PIN is for, and it is a mitigation, not a guarantee.

If you want to try it

Finn is free for up to 100 items, permanently — not a trial. No account, no email address, nothing to cancel if you stop using it.

Last checked 10 September 2026. This page describes what to look for in any vault app and what Finn does; it deliberately does not rank named competitors, because those facts change with every release and a table like that is wrong within a month of being written.