How your files are protected
Every file is encrypted on your phone with AES-256-GCM, under a random 256-bit key that only your password, PIN or fingerprint can unlock. That key is never stored in the clear, and the app has no internet permission.

How do the keys fit together?
One master key opens everything. Your password, PIN and fingerprint each unlock their own wrapped copy of it.
You unlock with
- Your passwordArgon2id turns it into the key that unwraps the master key.
- Your PINChecked against an Argon2id hash, then the phone's hardware Keystore unwraps its copy.
- Your fingerprintAndroid confirms it is you, then the Keystore unwraps its copy.
It opens
- Every fileEach one encrypted with AES-256-GCM.
- Names, folders and datesThe key to the SQLCipher database.
- Guard photosThe private key that opens sealed photos.
The Vault Master Key (VMK) is 256 random bits, made on your phone when you create the vault. It is the only thing that can decrypt your files. What sits on the phone are three wrapped copies of it, each one locked by a different unlock method.
The key lives in memory only while the vault is open, and it is overwritten with zeros the moment the vault locks.
What happens when you unlock?
Each way in opens its own copy of the master key, and none of them stores your secret.
Your password
Never stored. Argon2id, a deliberately slow and memory-hungry function (OWASP 2024 settings), turns it into the key that unwraps the master key. That makes guessing on a graphics card far more expensive than older methods such as PBKDF2.
Your PIN
Checked against an Argon2id hash. The master key's PIN copy is wrapped by a hardware Keystore key that cannot leave the phone, so a short PIN is useless to anyone who copies the vault's files off it.
Your fingerprint
Handled entirely by Android, which only tells the app "yes, it is you". The Keystore then releases the fingerprint copy. The app never receives fingerprint data.
What stops someone from guessing?
Waiting times that grow with every wrong try, and a lockout for the PIN.
| Wrong guess | What happens |
|---|---|
| PIN, 5 wrong tries | The PIN is locked for 30 minutes. |
| Password | The wait doubles each time: 2 s, 4 s, 8 s and so on, up to 5 minutes. |
| Closing the app | Changes nothing. Both counters are kept. |
| Guard's "Is it you?" check | The same lockouts as the unlock screen. |
How are files stored?
Encrypted one by one, under random names, with their names and folders in an encrypted database.
One file, one sealed blob
Each file is encrypted with AES-256-GCM and saved under a random name (a UUID). On disk the vault is a folder of anonymous, scrambled files.
Names and folders encrypted too
File names, types, folders and dates live in a SQLCipher database whose key comes from the master key.
Checked before you see it
The whole file is decrypted and its GCM tag verified before a single byte is shown. AES-GCM only proves a file is untouched at the very end, so acting on it sooner is a known mistake.
Nothing readable on disk
Photos, PDFs and text open inside the app without ever being written to the phone in readable form.
Checking the whole file first costs memory, which is why one file can be up to about a fifth of the memory Android gives the app. More on the size limit.
Can anyone take screenshots?
Not of Home or Guard, and not of the vault unless you allow it.
Stillgarth uses Android's FLAG_SECURE, which blocks screenshots and hides the app's preview in the recent apps list. The vault follows its Block screenshots and app previews setting. It is on by default and can only be changed from inside the unlocked vault.
One exception: while your backup recovery code is on screen, Android 13 and newer allow a screenshot so you can keep it. On older Android the block stays, because those versions would also show the code in the app switcher.
How are Guard photos sealed?
With your vault's public key. Guard can lock photos away, but it can never open them.
When you create a vault, it makes an RSA-3072 key pair. Guard encrypts each photo with a fresh AES-256-GCM key and wraps that key with the public half (RSA-OAEP with SHA-256). Only the sealed result is written to storage.
The private half is stored encrypted under a key derived from the master key, so only an unlocked vault can open the photos. Changing your password or PIN does not affect it.
Erasing the vault, by hand or with a duress code, deletes the key pair and any sealed photos still waiting.
What Phone Guard doesDoes anything leave the phone?
Only what you send yourself.
- Stillgarth does not request Android's internet permission, so it cannot connect to any server. The app's build fails if that permission is ever added.
- No accounts, ads, analytics, crash reporting or tracking.
- Sharing or exporting a file sends it where you choose.
- The encrypted backup goes to the place you pick, and the app you pick does the uploading. The developer never receives it and cannot open it.
What can't it protect against?
Some things are outside any app's reach. Here is what to know before you rely on it.
A rooted or tampered phone
The vault refuses to open where it finds root, an emulator, a debugger or Frida. These checks look for common signs. They cannot catch everything.
Someone watching you type
Anyone who sees your password or PIN can open the vault. A fingerprint is harder to watch.
Copies somewhere else
A file that is also in a cloud backup (such as Google Photos), another app or another device stays there.
Traces in flash storage
Phone storage can keep traces of a file after it is overwritten and deleted.
A forgotten password
It is never stored, so nobody can reset it, including the developer. Keep it, or your backup recovery code, somewhere safe.
Guard's own log
The list of times and kinds of events is kept in the app's private storage, where no other app can read it, but it is not encrypted. The photos are.
Android's own settings
Someone using your unlocked phone can turn off unlock detection in Android settings. Guard's "Is it you?" check stops a casual snoop, not a determined one.
Right after a restart
Guard takes no photos until you tap its "Tap to re-arm" notification. That is an Android rule for background camera use.
No outside review yet
The app has not had an independent security review.
Encryption that stays on your phone
Stillgarth keeps every key on the device and has no way to send anything anywhere.