At a glance.
| Question | Lockpic | LockMyPix |
|---|---|---|
| Encryption | AES-256-GCM, Argon2id, Android Keystore pepper, and public architecture details | Official materials state per-file AES encryption and identify AES-CTR in product copy |
| App internet access | No internet permission | Supports optional Drive/Dropbox cloud and documented analytics/advertising services |
| Account | No identity account | No contact details required for basic local use; optional email recovery is documented |
| Advertising | None at either tier | Free version may display ads; Premium removes advertising |
| Feature maturity | Focused photos, videos, albums, recovery, backup, and duress | Broader features including SD card support, disguises, intruder capture, and themes |
| Track record | New; not independently audited | 10M+ Play downloads and 331K+ reviews at source check |
The honest case for LockMyPix.
LockMyPix has substantial social proof, a mature Android feature set, local per-file encryption, optional user-controlled cloud destinations, and years of compatibility experience. Features such as SD-card storage, disguise choices, and intruder capture are not present in Lockpic's launch build.
Its privacy policy also documents analytics, Firebase monitoring, and advertising providers, with controls or Premium behaviour described there. Those components may be acceptable to users who value the larger feature set.
What Lockpic changes.
Lockpic narrows the system: no internet permission, ads, identity account, app analytics, camera permission, or provider cloud. It publishes the KDF, key separation, authenticated encryption, backup framing, and limitations rather than relying on a general encryption label.
Its separate-pattern model also avoids a stored master list of valid vault patterns. The cost of that restraint is fewer convenience features and a much shorter public track record.
Which should you choose?
You value maturity, a large installed base, SD-card support, disguises, intruder capture, and optional cloud convenience.
You want no app network permission or advertising SDK, a documented authenticated-encryption design, and user-managed portable recovery.