PrivacyVaults

A Sensitive Vault Behind Its Own Password: Extra Protection for What Matters Most

Most of your vault should be easy to reach: unlocked with a glance, recoverable if you lose your phone. But a few things deserve a second wall. A sensitive vault is sealed behind its own password, cannot be shared, and is deliberately out of reach of your recovery phrase. No backdoor, not even for us.

Security is not one setting turned up to maximum for everything. The passwords you use twenty times a day should be frictionless and easy to get back. But almost everyone has a short list of things that are different: a document, a few photos, a login whose exposure would genuinely hurt. For those, convenience is not the priority; a second wall is.

That is what a sensitive vault is for. It is one of the separate vaults you can now keep, but hardened on purpose: it has its own password, it can never be shared, and it is walled off from the recovery paths that protect the rest of your data. You are trading recoverability for absolute privacy, deliberately, with your eyes open.

Key takeaways

  • A sensitive vault is sealed behind its own password, on top of Face ID or Touch ID.
  • Your 24-word recovery phrase cannot reach it. Those words bring back your other vaults, never this one.
  • It cannot be shared with anyone, so its contents can never be handed out, even by accident.
  • No backdoor, not even us. You save a dedicated recovery code at setup; if both the password and that code are lost, no one can open it.

What makes it "sensitive"

Setting up a sensitive vault is a short, three-step ritual, and each step spells out a trade-off you are choosing:

What you setWhat it means
Its own passwordThe vault will not open on biometrics alone. You enter a password only you know, every time.
Out of the recovery phraseYour 24 words rebuild your other vaults, never this one, so a recovered phrase can never expose it.
Cannot be sharedA sensitive vault has no invite. Its contents are for you alone.
Its own recovery codeYou save a separate code and confirm you have stored it safely. That code, plus your password, is the only way back in.
The absence of a backdoor is the feature. Because there is no master way in, no one, not an attacker, not a court order to us, not us on our best day, can open it without your password.

The trade-off, stated plainly

A sensitive vault gives up the safety nets on purpose. There is no "we'll help you recover it" path, because such a path would also be a way in for someone who is not you. This is the same logic behind zero-knowledge design, taken to its strictest conclusion.

Save the recovery code, for real. During setup you are shown a recovery code and asked to confirm you have saved it somewhere safe before the vault is created. Treat it like the 24-word phrase for your main vault: write it down, store it offline, do not keep it only on the same device. If the password and the code are both gone, the vault is gone.

What belongs in one (and what does not)

A sensitive vault is a small, sharp tool, not a second home for everything.

Think of your vaults as concentric walls: your normal vault for daily life, a shared vault for what your household holds together, and a sensitive vault as the innermost room, opened only by you, only with a password, with no spare key anywhere.

An innermost room, with no spare key.

Put your most private things behind a second wall: a sensitive vault with its own password, unshareable, with no backdoor. Alongside your everyday and shared vaults, on iPhone, iPad, and Mac.

Explore Kinship Vault