Red flags 1–3: the business model shows through
One: ads inside the app. Ad SDKs exist to collect and transmit; whatever the privacy policy says, a data pipeline lives inside your vault app. Two: a required account for a purely local job. Local encryption needs no identity; accounts exist for the vendor’s funnel, and every account is one more place your usage is recorded. Three: "recover your PIN by email." Genuine encryption cannot be recovered by a support desk — an app offering it is telling you it holds keys to your content.
Red flags 4–5: the technology is a mystery
Four: no encryption details anywhere. "Military-grade" and a padlock icon are not documentation. A trustworthy vault names the algorithm, where keys come from, and what happens on wrong PINs — details a fake cannot fill in convincingly. Five: cloud upload you did not ask for. If files leave the device "for backup" or "for processing" by default, the vault’s security became the vendor’s server security, and you were not asked.
Red flags 6–7: the details nobody checks
Six: plaintext leftovers. Imported photos that remain in the camera roll without a warning, thumbnails visible in the app switcher, previews readable in a computer backup — sloppiness where content escapes the encryption boundary. Seven: no stated limits. Every security tool has failure modes; a vendor that lists none is either unaware of them or hiding them. Honest documentation of limits is the strongest single trust signal this category has.
Two minutes with a vendor’s website answers most of these. If the answers are missing, the answer is no.