What Lockpic is designed to resist.

Borrowed phone

Someone using your unlocked phone cannot open the vault without its separate pattern or configured biometric approval.

App storage copy

Copied media, thumbnails, metadata, and key wrappers are encrypted and authenticated rather than stored as ordinary gallery files.

Casual inspection

There is no visible list of real vaults and no “wrong pattern” response identifying which patterns matter.

Ordinary capture

Release builds ask Android to block screenshots, screen recordings, and recents previews.

What remains observable.

Lockpic does not make itself disappear. An examiner can see that the app is installed, estimate total encrypted storage, and observe that encrypted files exist. Larger encrypted indexes may reveal coarse size buckets.

A person watching the screen can observe a pattern. Android, device firmware, accessibility services, keyboards, or malware may observe activity if the operating system is compromised.

Where the boundary ends.

  • A rooted or compromised device reading Lockpic while a vault is unlocked.
  • Someone who knows or observes the real pattern or recovery phrase.
  • Privileged screen or GPU capture that ignores Android's secure-window request.
  • Plaintext originals in another gallery, cloud backup, Android trash, exported folder, or provider cache.
  • Denial of service, app deletion, phone destruction, or storage failure.
  • Recovery after loss when no valid encrypted backup exists.
No security theatre

“AES-256” does not compensate for a compromised phone, an observed secret, or a missing backup. Lockpic treats those as separate risks with separate controls.

Duress is destructive, not magical.

A configured duress pattern opens its own vault and destroys the wrapped keys needed to decrypt other vaults. The operation resumes after interruption, but it cannot overwrite flash cells reliably or erase copies outside Lockpic.

Cloud copies, exported media, Android trash, and plaintext originals remain wherever they were stored. The feature cannot be undone and should only be configured after understanding that consequence.

Privacy and availability pull in opposite directions.

Lockpic has no server-side reset. That removes a recovery backdoor, but it also means the developer cannot rescue a forgotten pattern or lost device.

For pattern loss on the same phone, retain the recovery phrase. For phone loss, uninstall, or factory reset, retain both the phrase and a verified encrypted backup.

See how the backup and recovery design works →