How your files are protected

Every file is encrypted on your phone with AES-256-GCM, under a random 256-bit key that only your password, PIN or fingerprint can unlock. That key is never stored in the clear, and the app has no internet permission.

Close-up of a brushed steel combination dial on a dark safe door.

How do the keys fit together?

One master key opens everything. Your password, PIN and fingerprint each unlock their own wrapped copy of it.

You unlock with

  • Your passwordArgon2id turns it into the key that unwraps the master key.
  • Your PINChecked against an Argon2id hash, then the phone's hardware Keystore unwraps its copy.
  • Your fingerprintAndroid confirms it is you, then the Keystore unwraps its copy.
Vault Master Key256-bit, randomNever stored in the clear. Three wrapped copies on the phone, one per unlock method. In memory only while the vault is open.

It opens

  • Every fileEach one encrypted with AES-256-GCM.
  • Names, folders and datesThe key to the SQLCipher database.
  • Guard photosThe private key that opens sealed photos.
Three ways to unlock, one master key. Each unlock method opens its own wrapped copy of the Vault Master Key, and that key opens your files, the encrypted database and Guard's photos.

The Vault Master Key (VMK) is 256 random bits, made on your phone when you create the vault. It is the only thing that can decrypt your files. What sits on the phone are three wrapped copies of it, each one locked by a different unlock method.

The key lives in memory only while the vault is open, and it is overwritten with zeros the moment the vault locks.

What happens when you unlock?

Each way in opens its own copy of the master key, and none of them stores your secret.

  • Your password

    Never stored. Argon2id, a deliberately slow and memory-hungry function (OWASP 2024 settings), turns it into the key that unwraps the master key. That makes guessing on a graphics card far more expensive than older methods such as PBKDF2.

  • Your PIN

    Checked against an Argon2id hash. The master key's PIN copy is wrapped by a hardware Keystore key that cannot leave the phone, so a short PIN is useless to anyone who copies the vault's files off it.

  • Your fingerprint

    Handled entirely by Android, which only tells the app "yes, it is you". The Keystore then releases the fingerprint copy. The app never receives fingerprint data.

What stops someone from guessing?

Waiting times that grow with every wrong try, and a lockout for the PIN.

What happens after wrong guesses
Wrong guessWhat happens
PIN, 5 wrong triesThe PIN is locked for 30 minutes.
PasswordThe wait doubles each time: 2 s, 4 s, 8 s and so on, up to 5 minutes.
Closing the appChanges nothing. Both counters are kept.
Guard's "Is it you?" checkThe same lockouts as the unlock screen.

How are files stored?

Encrypted one by one, under random names, with their names and folders in an encrypted database.

  • One file, one sealed blob

    Each file is encrypted with AES-256-GCM and saved under a random name (a UUID). On disk the vault is a folder of anonymous, scrambled files.

  • Names and folders encrypted too

    File names, types, folders and dates live in a SQLCipher database whose key comes from the master key.

  • Checked before you see it

    The whole file is decrypted and its GCM tag verified before a single byte is shown. AES-GCM only proves a file is untouched at the very end, so acting on it sooner is a known mistake.

  • Nothing readable on disk

    Photos, PDFs and text open inside the app without ever being written to the phone in readable form.

Checking the whole file first costs memory, which is why one file can be up to about a fifth of the memory Android gives the app. More on the size limit.

Can anyone take screenshots?

Not of Home or Guard, and not of the vault unless you allow it.

Stillgarth uses Android's FLAG_SECURE, which blocks screenshots and hides the app's preview in the recent apps list. The vault follows its Block screenshots and app previews setting. It is on by default and can only be changed from inside the unlocked vault.

One exception: while your backup recovery code is on screen, Android 13 and newer allow a screenshot so you can keep it. On older Android the block stays, because those versions would also show the code in the app switcher.

How are Guard photos sealed?

With your vault's public key. Guard can lock photos away, but it can never open them.

When you create a vault, it makes an RSA-3072 key pair. Guard encrypts each photo with a fresh AES-256-GCM key and wraps that key with the public half (RSA-OAEP with SHA-256). Only the sealed result is written to storage.

The private half is stored encrypted under a key derived from the master key, so only an unlocked vault can open the photos. Changing your password or PIN does not affect it.

Erasing the vault, by hand or with a duress code, deletes the key pair and any sealed photos still waiting.

What Phone Guard does

Does anything leave the phone?

Only what you send yourself.

  • Stillgarth does not request Android's internet permission, so it cannot connect to any server. The app's build fails if that permission is ever added.
  • No accounts, ads, analytics, crash reporting or tracking.
  • Sharing or exporting a file sends it where you choose.
  • The encrypted backup goes to the place you pick, and the app you pick does the uploading. The developer never receives it and cannot open it.
How the encrypted backup works

What can't it protect against?

Some things are outside any app's reach. Here is what to know before you rely on it.

  • A rooted or tampered phone

    The vault refuses to open where it finds root, an emulator, a debugger or Frida. These checks look for common signs. They cannot catch everything.

  • Someone watching you type

    Anyone who sees your password or PIN can open the vault. A fingerprint is harder to watch.

  • Copies somewhere else

    A file that is also in a cloud backup (such as Google Photos), another app or another device stays there.

  • Traces in flash storage

    Phone storage can keep traces of a file after it is overwritten and deleted.

  • A forgotten password

    It is never stored, so nobody can reset it, including the developer. Keep it, or your backup recovery code, somewhere safe.

  • Guard's own log

    The list of times and kinds of events is kept in the app's private storage, where no other app can read it, but it is not encrypted. The photos are.

  • Android's own settings

    Someone using your unlocked phone can turn off unlock detection in Android settings. Guard's "Is it you?" check stops a casual snoop, not a determined one.

  • Right after a restart

    Guard takes no photos until you tap its "Tap to re-arm" notification. That is an Android rule for background camera use.

  • No outside review yet

    The app has not had an independent security review.

Encryption that stays on your phone

Stillgarth keeps every key on the device and has no way to send anything anywhere.