Private vaults protect content with client-side encryption before hosted synchronization. Encryption does not make every piece of service metadata invisible.

What is protected

Private vault content is encrypted before upload and decrypted by an authorized client after unlock. The interface indicates the active protection mode.

What the service still needs

Account identity, subscription state, device records, usage limits, vault identifiers and operational logs may be required to operate the hosted service. These are documented separately from encrypted content.

Recovery limits

If a private-vault secret cannot be reconstructed, encrypted content may be unrecoverable. Keep a tested precise backup and readable export in a location controlled by you.

Locking and devices

Lock state is local to the client session. Revoking a cloud device prevents future authorized access from that credential but does not remotely erase unrelated local exports or backups.