Lifetime Premium is 40% off until October 1 — then the price goes up

Security model

Strong by architecture, not by promise.

Sealby’s privacy doesn’t ask you to trust a company. It comes from how the app is built — local-first, account-free, and encrypted with keys that live only on your devices.

Sealby security, at a glance

  • AES-256-GCM encryption on-device, with a separate key per file
  • Keys protected by the Secure Enclave
  • No account, no server, no master key, no backdoor
  • iCloud only ever stores an unreadable encrypted blob
  • Per-vault recovery phrase, held only by you

Encrypted on your device

Every file and note is encrypted with AES-256-GCM before it is written to storage or synced. Each file gets its own key, so nothing is ever held in plaintext at rest.

Keys in the Secure Enclave

Your keys are protected by your device’s Secure Enclave and unlocked by your PIN, pattern or passphrase. They are never uploaded, escrowed, or shared with us.

iCloud only sees a blob

When backup or sync is on, what leaves your device is an opaque encrypted blob. Apple’s servers store it but cannot read it, and neither can we.

No account, no server, no backdoor

There is nothing to sign into and no server that holds your keys. There is no master key and no recovery backdoor — access depends on no one but you.

Deniable by design

Multiple vaults sit behind different PINs and are indistinguishable from random data, so the existence and number of vaults can’t be proven.

Recovery you control

Each vault has its own recovery phrase, generated on your device and shown only to you. Keep it safe and you can restore that vault anywhere.

Plaintext in. Unreadable blob out.

Your content

Photos, files and notes on your iPhone.

AES-256-GCM

Sealed with per-file keys held in the Secure Enclave.

Opaque blob

All iCloud ever stores. No key, no meaning.

What a server could see

  • The encrypted blob exists and roughly how large it is
  • When a backup last changed

What no one can see

  • Your files, photos, videos, or notes
  • Your PIN, passphrase, or encryption keys
  • How many vaults you have — or whether a hidden one exists
  • Anything readable, ever — there is no key to hand over

Straight answers.

Can Sealby or Apple read my data?

No. Your data is encrypted on your device and only an unreadable blob is stored or synced. There is no account, no server-held key, and no backdoor — so there is nothing readable for anyone to access or be compelled to hand over.

What encryption does Sealby use?

Files and notes are encrypted with AES-256-GCM using per-file keys, which are protected by your device’s Secure Enclave and unlocked by your PIN, pattern or passphrase.

What if I lose my recovery phrase?

Because there is no master key or backdoor, a vault with no other access path cannot be recovered. That is the trade-off that makes Sealby unreadable to everyone but you, so store your recovery phrase carefully.

Do you track me on this website?

No. This site uses no trackers or advertising pixels and sets no cookies. Privacy is the product, so the website is built to match.

More: how deniable vaults work ·full FAQ ·Found a security issue? Write to hello@sealby.app.

Privacy you don’t have to take on faith.

Download Sealby and keep your data unreadable to everyone but you.

Download on the App Store

iPhone & iPad · iOS 17+ · Free