Crypto holders tend to think about exactly one document as sensitive: the seed phrase. Correctly so β€” it's the master key, and typing it into any app is the wrong move regardless of the app. But it's rarely the only paper trail. There's usually a keystore export from a software wallet, a folder of exchange two-factor backup codes, a note about which hardware wallet holds which coins, maybe a transaction history exported for taxes. All of that sits somewhere, and "somewhere" is often a phone's Files app, a Notes entry, or a folder in Dropbox nobody thinks twice about.

This is about that second category β€” the files worth encrypting, not the phrase that never belongs in an app at all.

What the seed phrase rule actually protects against

The reason nobody serious tells you to store a seed phrase digitally isn't superstition. A phrase typed into any software, however well-intentioned, exists somewhere a screenshot, a clipboard history, a synced note, or a compromised device can reach it. Paper or metal, kept offline, removes that entire category of risk. That advice doesn't change here, and nothing in this post is an argument against it.

What it doesn't cover is everything else in a crypto holder's file drawer.

The files that actually need a lock

Keystore exports (keystore.json, UTC--... files). A software wallet's keystore file is itself encrypted, gated by its own password. Losing the file alone doesn't hand someone your coins. But it identifies the wallet, and it's one password away from being useful to whoever has it β€” worth keeping away from anyone who shouldn't know it exists, let alone try opening it.

Exchange two-factor backup codes. Every exchange that supports 2FA gives you one-time backup codes for when you lose the device running your authenticator. Those codes, sitting in a screenshot or a plaintext note, are a direct account-recovery path for anyone who finds them.

Hardware wallet notes. Which device holds which coins, serial numbers, PIN reminders that aren't the PIN itself. Not catastrophic alone, but useful reconnaissance for a targeted theft, especially combined with anything else on the same device.

Transaction history exports. Tax season produces CSVs and PDFs with wallet addresses, amounts and dates. Not a key to anything, but a clear picture of what you hold and roughly what it's worth β€” not something to leave sitting in a Downloads folder.

Why the cloud is the wrong place for any of it, unencrypted

The instinct to back these files up somewhere off-device is correct. Devices get lost, stolen, or simply die. The mistake is uploading them as-is. A keystore file or a screenshot of backup codes sitting in Dropbox or Google Drive is readable by the provider, and by anyone who breaches the provider or takes over the account it's stored under β€” the same gap covered in more depth in why your photos aren't safe in the cloud.

Encrypting the file on-device before it goes anywhere closes that gap without giving up the backup itself. The cloud copy becomes ciphertext: worthless to read, still there if the original device is gone.

Where Vaultine fits

Vaultine encrypts each file individually with AES-256-GCM on the device, with the key derived from your own pattern or PIN β€” never your crypto seed phrase, never anything typed for you. It's built to hold exactly the category of file this post is about: keystore exports, 2FA backup codes, hardware wallet notes, transaction records. Import them, and they're unreadable without your vault's own credential, whether they stay on-device or get backed up through your own encrypted Dropbox.

The same vault runs on iPhone, Mac, Android and Windows, and a 12-word recovery phrase gets the vault itself back on a new device if you lose the one it was on β€” restoring your files, not your crypto. Free covers one vault, up to 10 files; Pro adds unlimited vaults, Decoy and Duress Vaults, and encrypted Dropbox backup for $1.99 a month, $14.99 a year, or $39.99 once for lifetime ($29.99 on Windows).

What it won't do: ask for, store, or transmit a seed phrase, or replace a hardware wallet's secure element. Different job, and the two aren't in competition β€” see how Vaultine's recovery phrase actually works for the mechanism this relies on, and 5 types of files you should never keep unencrypted for the broader version of this same argument.

Getting started

Sort what you actually have first: seed phrase stays on paper or metal, offline, full stop. Everything else β€” keystore files, backup codes, wallet notes, tax exports β€” is a candidate for an encrypted vault rather than a plaintext folder. You can try Vaultine's free tier at vaultine.app.