v3 Vault encryption architecture
v3 Vault entries are stored on your device with AES-256-GCM envelope encryption.
Keepspire draws its product boundary around privacy, and labels the current state honestly: v3 Vault entries are stored on your device with AES-256-GCM envelope encryption. The Android Internal Alpha is in closed testing; public download, public fundraising and store submission are not open, and a third-party human security audit is not yet complete.
A simplified view of the key and data flow in Keepspire's v3 Vault. Tap each step for a plain-language explanation; each step describes only what is already implemented.
Keepspire can generate a high-strength random passphrase as your master password, which you must store safely offline. Only you hold it — Keepspire, the developer and the cloud cannot retrieve it for you.
The v3 Vault derives keys with Argon2id; master-password material is never stored in plaintext on the device.
The derived key unlocks the Vault key, which handles each record.
v3 Vault entries are stored on your device with AES-256-GCM envelope encryption.
Vault entries are stored on your device by default.
You can create an encrypted backup and restore it; only a backup you export or share yourself ever leaves the device.
On supported Android devices, unlock material is protected via the Android KeyStore; your master password still applies.
The diagram is simplified. Keepspire has not completed a third-party human security / cryptography audit — please don't treat it as an audited product.
Below are only the things already implemented; what isn't done yet is listed clearly under “Open items” on this page.
v3 Vault entries are stored on your device with AES-256-GCM envelope encryption.
The v3 Vault derives keys with Argon2id; master-password material is never stored in plaintext on the device.
You can create an encrypted backup (SNCB3 format) and restore your vault; moving to a new phone also goes through the encrypted backup-and-restore flow.
On Android devices that support and pass the secure-hardware check, biometrics protect unlock material via the Android KeyStore; not using it doesn't affect the app, and your master password still applies.
Screenshot protection is on by default (screenshots and screen recording are blocked) and can be turned off in Settings; Keepspire tries to clear sensitive content copied by the app on timeout, lock or going to the background.
Screenshots and screen recording are blocked.
You decide whether to keep it on.
On timeout, lock or going to the background, it tries to clear sensitive content copied by the app.
Forgetting your master password can make data permanently unrecoverable. Store your master password / passphrase safely in a trusted, offline way, and we recommend making regular local backups as your fallback if you lose it. Biometrics are only for everyday device unlock — they do not replace your master password.
Without the master password, no key can be derived; the developer should not be able to decrypt user content.
The app re-locks after leaving the foreground, reducing the chance of someone seeing content directly.
Core features don't rely on a Keepspire account or a constant network connection. Device transfer is currently unavailable.
Everyday use doesn't rely on cloud sync; your data stays on your device.
No account; everyday use doesn't rely on a network.
Offline. No accounts. No data collection. Read the full policy →
Internal Alpha is approved, but public download and store submission still wait on the following.
The product has not completed a third-party human security / cryptography audit; this will be arranged before public release.
iOS is not yet verified; for now only Android is supported.
Pre-release documents such as the privacy policy, store assets and support process.
v3 Vault entries are stored on your device with AES-256-GCM envelope encryption. The Android Internal Alpha is in closed testing; public download, public fundraising and store submission are not open, and a third-party human security audit is not yet complete.
No. Keepspire, the developer and the cloud cannot retrieve your master password for you. Back up your master password / passphrase safely, and we recommend making regular local backups as your fallback if you lose it.
Everyday use doesn't rely on cloud sync; your data stays on your device. Device transfer is currently unavailable.