How Lockspeare protects your photos

Lockspeare encrypts every photo and video on your phone. This page explains exactly how, including what it cannot protect against, so you can judge it for yourself.

Last updated October 2, 2026

The short version

  • Every photo and video is encrypted on your phone with AES-256-GCM before it is stored.
  • The key that opens your vault is protected twice: by your PIN or pattern, and by a hardware-backed key in Android Keystore that never leaves your phone.
  • A copy of your phone’s storage contains only encrypted data. Without your phone’s secure hardware, nobody can try PINs or patterns against it.
  • Your 12-word recovery phrase is the only way to open a vault on another phone or from a backup.
  • Lockspeare has no servers and no accounts. We never receive your files, your PIN or pattern, or your keys.

What is encrypted

Everything you put in a vault: photos, videos, their thumbnails, their original file names, dates and albums.

Each file is encrypted with its own key, derived from your vault’s master key. Large files are encrypted in 1 MB segments, each with its own integrity check, so videos can be played without decrypting the whole file at once, and any change to an encrypted file is detected. We use Google’s Tink library for this, rather than writing our own encryption.

Encrypted files are stored in Lockspeare’s private app storage with random names. Files from all your vaults sit in the same folder, so the folder does not show which vault a file belongs to.

How your PIN or pattern opens a vault

When you set up Lockspeare, you choose how to unlock it: a PIN of at least 6 digits, or a pattern on a 3×3 grid like your lock screen. Every vault on the phone uses the same kind of lock, so the lock screen gives nothing away.

Each vault has a random 256-bit master key, created on your phone. That key is never stored in readable form. It is stored in two locked forms:

Locked with your PIN or pattern, on this phone. Your PIN or pattern is turned into a key with Argon2id, an algorithm designed to make every guess slow and memory-hungry. The result is then encrypted again with a key held in Android Keystore, inside your phone’s secure hardware. That second key cannot be copied off the phone.

This matters because a PIN or pattern is short. On its own, it could be guessed quickly by a computer working on a copy of your files. Tying it to your phone’s hardware means guesses can only be made on your phone, and each one is slow.

Locked with your recovery phrase. When you create a vault, Lockspeare shows you 12 words, chosen at random from a standard list of 2,048 words. That gives about 128 bits of randomness, far beyond what anyone can guess. The phrase opens the vault if you forget your PIN or pattern, move to a new phone, or restore a backup.

You confirm a few of the words before the vault is ready. Write them down somewhere safe. We do not have a copy.

Separate vaults and the decoy vault

Each PIN or pattern opens its own vault. You can use a second one for a decoy vault with harmless photos, in case someone ever pressures you to unlock the app.

Lockspeare always keeps the same number of vault slots on disk, whether you use one vault or several. Unused slots are filled with random data that looks the same as a real, encrypted vault. The app has no list of vaults. So neither the screen nor a copy of your files shows how many vaults you have.

One limit: to avoid overwriting a vault when you create a new one, the app keeps a note of which slots are taken, locked with your phone’s hardware key. Someone with full control of your unlocked phone could read that note and learn how many vaults exist, though not what is in them.

Backups

Backups are optional. There are two kinds.

Google Drive. Lockspeare stores the backup in a hidden app folder in your own Google Drive. It uploads the files exactly as they are stored on your phone: already encrypted. It also uploads your vault key locked with your recovery phrase. It never uploads the copy locked with your PIN or pattern, because that copy only works with your phone’s hardware.

To restore on a new phone, you enter your recovery phrase, then choose a new PIN or pattern.

Lockspeare asks only for permission to its own hidden folder in your Drive, not for access to your other files. Google can see how many backup files there are, roughly how big they are and when they were uploaded. It cannot see what is in them.

Backup file. You can also export a vault as a single encrypted file and save it anywhere: another cloud service, a memory card or your computer. It opens only with your recovery phrase.

Android’s own automatic backup is turned off for Lockspeare. It could not restore the hardware-bound keys, so it would only copy data nobody can use.

While you use the app

  • Screenshots, screen recordings and the preview in your recent apps are blocked.
  • The vault locks as soon as you leave the app, unless you choose a short delay.
  • Locking clears the keys and any decrypted previews from the app’s memory and temporary storage. Android apps run on a system that can make internal copies of memory, so we clear everything we control but cannot promise that no copy remains in memory until it is reused.
  • Photos and videos you take with the camera inside Lockspeare go straight into the vault and never appear in your gallery, so cloud photo backups never see them. Photos are encrypted from memory. Android’s video recorder needs a file, so a video is written to Lockspeare’s private storage while you record, encrypted as soon as you stop, and the unencrypted file is deleted.

When you add a photo from your gallery, Lockspeare first encrypts it, then reopens the encrypted copy and checks that it matches the original. Only then does it offer to delete the original, through Android’s own confirmation dialog.

Two places are outside Lockspeare’s reach, and we remind you about both after every import:

  • Your gallery’s trash. Many gallery apps keep deleted photos for about 30 days. Empty it to remove them for good.
  • Cloud photo backups. If a photo was already backed up by a cloud photo service, that copy stays there until you delete it.

What leaves your phone

  • Nothing, by default. Lockspeare works fully offline.
  • Google Drive, only if you turn on backup, and only encrypted files.
  • Google Play, to process purchases.
  • Crash reports, only if you turn them on in Settings. They contain technical details like the phone model and where the app failed. Never your files, file names, PIN or pattern.

There are no ads, no advertising IDs and no analytics libraries in the app.

What Lockspeare cannot protect against

Being honest about limits is part of security. Lockspeare does not protect against:

  • Someone watching you enter your PIN or draw your pattern. Shield the screen.
  • A compromised phone while your vault is open. Malware with deep access to your phone, or a hacked operating system, can see what is on your screen.
  • Someone with full control of your unlocked phone and unlimited time. They could try PINs or patterns on the phone itself. Argon2id makes every try slow, and a longer PIN or pattern makes the job much harder, but a short one is still short.
  • Seeing that Lockspeare is installed, how much encrypted data it holds, and the approximate size of each encrypted file.
  • Losing both your PIN or pattern and your recovery phrase. Nobody can open the vault then, including us.

Independent review

This design has not yet been independently audited. We plan to have it reviewed before Lockspeare launches, and we will publish the result here. If you find a problem, write to security@lockspeare.com.