Keeping a record, not destroying one

Documentation matters in these situations, and it usually matters later rather than now: photos, screenshots of messages, financial records, letters. What it needs to do is stay intact and stay unreadable to anyone else until it reaches someone who can act on it.

That makes this the opposite of the usual vault pitch. Vaultine has a Duress Vault, a code that wipes your real vaults when entered, and for some people it is the right tool. For preserving a record it usually is not, because destroying the record under pressure is the outcome to avoid. The Decoy Vault is the fitting feature here: a second code opens a separate vault holding files you chose in advance, so an unlock in front of someone produces an ordinary result while the real vault stays closed and untouched.

A copy that isn't on the device

Phones get taken, broken and reset. If the only copy of a record is on the phone, then whoever controls the phone controls the record.

Encrypted backup to your own Dropbox puts a copy somewhere else, encrypted before it leaves the device, so it is unreadable to Dropbox or anyone reaching the account. The 12-word recovery phrase is what restores access to it, which is why it belongs somewhere other than the phone it protects: written down somewhere safe, or left with someone you trust.

What this cannot do

This section matters more than the rest of the page.

Vaultine is visible on the device. It appears as Vaultine, with its own name and icon. The Decoy Vault changes what opens when a particular code is used; it does not change whether the app is on the phone. For some people, an unfamiliar app being found is itself the risk, and no setting inside the app changes that.

It does not defeat monitoring software. If something on the device is capturing the screen, keystrokes or activity, it can capture what happens inside any app, encrypted or not. A device the other person has never had access to is safer than one you are trying to secure after the fact. That might be a friend's phone, a work computer, or a machine at a library or an advocacy centre.

A purchase leaves a trail we do not control. Vaultine itself requires no account and no email address. But if you buy Vaultine Pro, that purchase goes through Apple, Google or Microsoft, and their records are their own: a receipt can be emailed to the account that made the purchase, and on a shared or family-linked account it can appear in a purchase history someone else can see. The free tier involves no purchase at all, and covers one vault of up to 10 files. If a purchase record would be a problem, that is worth knowing before you buy rather than after.

It is not a safety plan. Software cannot tell you what is safe to do, when, or in what order. That is real expertise and it exists.

Where the actual help is

Domestic abuse advocates and helplines work on exactly these questions, including technology and device safety specifically, and they do it without charge and without judgment. Many organisations publish guidance on phones, accounts and monitoring, and can help you work out what is safe in your particular circumstances rather than in general.

If you are deciding whether a vault app is a good idea for your situation, that is a better question to ask them than to ask us. Vaultine's job here is narrow: keep a record encrypted, keep it deniable during an ordinary look at the phone, and help a copy of it exist somewhere the device cannot take with it.