-
Notifications
You must be signed in to change notification settings - Fork 0
Data Storage & Backups
hughk edited this page Oct 3, 2026
·
1 revision
Pin Vault is built around a zero-trust, offline-first data persistence model.
- SQLite & Room ORM: All cards, categories, folders, and grid configurations are stored in an encrypted local database.
- Zero Cloud Footprint: The application does not include any third-party analytics, crash trackers, or cloud sync services.
- Auto-Lock on Backgrounding: Whenever the user navigates away from the app or locks the device, the UI immediately locks and clears unsealed secrets from memory.
Pin Vault allows users to safely backup and restore their vault across devices without relying on cloud services:
-
AES-256-GCM Encryption:
- Backups are serialized into JSON and encrypted using AES-GCM with a 256-bit key.
- The key is derived from a user-supplied master passphrase using PBKDF2 with SHA-256 and high iteration counts.
- Includes authenticated data tags to prevent ciphertext tampering.
-
Android Storage Access Framework (SAF):
- Backups are written directly to a location chosen by the user (USB drive, local downloads, or private SD card) via Android's file picker.
- Pin Vault never requests broad storage permissions (
MANAGE_EXTERNAL_STORAGEorREAD_EXTERNAL_STORAGE).
-
Android Backup Service Disabled:
-
android:allowBackup="false"is explicitly set inAndroidManifest.xmlto prevent unencrypted ADB or Google Cloud backup extraction.
-
Pin Vault — Hardware-backed visual steganography for PINs and OTP codes. Licensed under GPL-3.0.
- Home
- Visual-Steganography-Engine
- Artist-Fingerpaint-Mode
- TOTP-Authenticator
- Hardware-Biometric-Security-&-OAEP
- Data-Storage-&-Backups
Repository: hughk/PinVault
Version: 0.997 (Beta)
License: GPL-3.0