Passcode on a folder, or encryption on a file
These are two different mechanisms and the distinction matters when something goes wrong.
A passcode on a folder controls what the app shows you. If the app is the only thing standing between someone and the files, then anyone who reaches the storage another way — a backup extraction, a forensic tool, a stolen and unlocked device — is not stopped by the passcode, because the files themselves were never changed.
Vaultine encrypts each file with AES-256-GCM before it is written, and the stored data is split and randomised so nothing on disk resembles the original. The key is derived from your pattern or PIN and is never stored. Pull the drive, mount it elsewhere, run recovery software over it: without your code there is nothing readable to find.
Two folders, or two prepared answers
Privault's secondary passcode opens a second folder, which produces a decoy effect: show that one, keep the other private.
Vaultine separates the two jobs that this collapses together. The Decoy Vault opens on a second code and shows a vault you stocked in advance with harmless files, so you decide what someone sees. The Duress Vault opens on a third code, shows an empty vault, and wipes your real vaults as it does — for when the files must not survive at all. Both are Pro features and both are configured deliberately.
Because Vaultine rejects any code it does not recognise, the vaults on the device are exactly the ones you created. That is worth knowing about any vault app: some derive the key straight from whatever is typed, which means every input opens something, including a vault you never made.
One vault, four platforms
Privault is an iPhone app. Vaultine runs on Windows, macOS, iOS and Android, so the same vault is on the machine where your documents actually live.




