Security model

Private by design, not by promise.

You don’t have to trust us. Sealby is private because of how it is built: there is no account, no server, and the keys never leave your devices.

Sealby security, at a glance

  • AES-256-GCM encryption on your device, with a separate key for every file
  • Keys protected by the Secure Enclave
  • No account, no server, no master key, no backdoor
  • iCloud only ever stores encrypted data it can’t read
  • A recovery phrase for every vault, held only by you

Encrypted on your device

Every file and note is encrypted with AES-256-GCM before it is saved or synced. Each file has its own key. Nothing is ever stored in readable form.

Keys in the Secure Enclave

Your keys are protected by the Secure Enclave in your device and unlocked by your PIN, pattern or passphrase. They are never uploaded or shared with anyone, including us.

iCloud sees nothing readable

When backup or sync is on, only encrypted data leaves your device. Apple stores it but can’t read it. Neither can we.

No account, no server, no backdoor

There is nothing to sign in to, and no server holds your keys. There is no master key and no backdoor. Access depends on no one but you.

Deniable by design

Each vault sits behind its own PIN. Vaults are stored as identical encrypted blocks, with no list of them and no count, anywhere.

Recovery you control

Each vault has its own recovery phrase, created on your device and shown only to you. Keep it safe, and you can restore that vault on any device.

Readable on your phone. Unreadable everywhere else.

Your content

Photos, files and notes on your iPhone.

AES-256-GCM

Each file gets its own key. The keys are protected by the Secure Enclave.

Unreadable data

All that iCloud ever stores. Without your key, it cannot be read.

What a server could see

  • That encrypted data exists, and roughly how large it is
  • When a backup last changed

What no one can see

  • Your files, photos, videos, or notes
  • Your PIN, passphrase, or encryption keys
  • How many vaults you have, or whether a hidden one exists
  • Anything readable, ever, because there is no key to hand over

Straight answers.

Can Sealby or Apple read my data?

No. Your data is encrypted on your device, and only encrypted data is ever stored or synced. There is no account, no server-held key and no backdoor. There is nothing readable for anyone to access or be forced to hand over.

What encryption does Sealby use?

Files and notes are encrypted with AES-256-GCM, each with its own key. The keys are protected by the Secure Enclave in your device and unlocked by your PIN, pattern or passphrase.

What if I lose my recovery phrase?

Then that vault depends on this phone and its PIN, pattern or passphrase alone. If you lose those too, or lose the phone, no one can recover the vault. There is no master key and no backdoor. That is the trade-off that makes Sealby readable by no one but you, so store your recovery phrase carefully.

Do you track me on this website?

No. This site uses no trackers, no advertising pixels and no cookies. Privacy is the product, so the website matches.

More: how deniable vaults work ·full FAQ ·Found a security issue? Write to hello@sealby.app.

Privacy that doesn’t depend on trusting us.

Download Sealby and keep your data unreadable to everyone but you.

Download on the App Store

iPhone & iPad · iOS 17+ · Free