Security isn't a slogan —
it's a series of verifiable gates.

Keepspire draws its product boundary around privacy, and labels the current state honestly: v3 Vault entries are stored on your device with AES-256-GCM envelope encryption. The Android Internal Alpha is in closed testing; public download, public fundraising and store submission are not open, and a third-party human security audit is not yet complete.

How it fits together

From your master password
to every single record

A simplified view of the key and data flow in Keepspire's v3 Vault. Tap each step for a plain-language explanation; each step describes only what is already implemented.

Master password / passphrase

Keepspire can generate a high-strength random passphrase as your master password, which you must store safely offline. Only you hold it — Keepspire, the developer and the cloud cannot retrieve it for you.

Where the encrypted data goes

On-device storage

Vault entries are stored on your device by default.

Encrypted backup (SNCB3)

You can create an encrypted backup and restore it; only a backup you export or share yourself ever leaves the device.

Biometrics (optional)

On supported Android devices, unlock material is protected via the Android KeyStore; your master password still applies.

The diagram is simplified. Keepspire has not completed a third-party human security / cryptography audit — please don't treat it as an audited product.

Current security model

What's implemented,
listed clearly.

Below are only the things already implemented; what isn't done yet is listed clearly under “Open items” on this page.

Implemented

v3 Vault encryption architecture

v3 Vault entries are stored on your device with AES-256-GCM envelope encryption.

Implemented

Argon2id key derivation

The v3 Vault derives keys with Argon2id; master-password material is never stored in plaintext on the device.

Implemented

Encrypted backup & restore

You can create an encrypted backup (SNCB3 format) and restore your vault; moving to a new phone also goes through the encrypted backup-and-restore flow.

Implemented · optional

Biometrics

On Android devices that support and pass the secure-hardware check, biometrics protect unlock material via the Android KeyStore; not using it doesn't affect the app, and your master password still applies.

Screen & clipboard

Screen & clipboard protection

Screenshot protection is on by default (screenshots and screen recording are blocked) and can be turned off in Settings; Keepspire tries to clear sensitive content copied by the app on timeout, lock or going to the background.

Screenshot protection on by default

Screenshots and screen recording are blocked.

Can be turned off in Settings

You decide whether to keep it on.

Sensitive content cleared

On timeout, lock or going to the background, it tries to clear sensitive content copied by the app.

No back door

No backdoor — not even the developer can recover your master password.

!

You are the sole keyholder.

Forgetting your master password can make data permanently unrecoverable. Store your master password / passphrase safely in a trusted, offline way, and we recommend making regular local backups as your fallback if you lose it. Biometrics are only for everyday device unlock — they do not replace your master password.

01

Zero-knowledge direction

Without the master password, no key can be derived; the developer should not be able to decrypt user content.

02

Auto-lock in the background

The app re-locks after leaving the foreground, reducing the chance of someone seeing content directly.

Offline-first

Offline-first

Core features don't rely on a Keepspire account or a constant network connection. Device transfer is currently unavailable.

Data stays on the device

Everyday use doesn't rely on cloud sync; your data stays on your device.

No sign-up at any point

No account; everyday use doesn't rely on a network.

Privacy policy

Offline. No accounts. No data collection. Read the full policy →

Before public release

Before public release,
gates still to clear.

Internal Alpha is approved, but public download and store submission still wait on the following.

Not done yet

Independent third-party audit

The product has not completed a third-party human security / cryptography audit; this will be arranged before public release.

Not done yet

iOS verification

iOS is not yet verified; for now only Android is supported.

Not done yet

Store & documentation

Pre-release documents such as the privacy policy, store assets and support process.

Security FAQ

You might ask

v3 Vault entries are stored on your device with AES-256-GCM envelope encryption. The Android Internal Alpha is in closed testing; public download, public fundraising and store submission are not open, and a third-party human security audit is not yet complete.

No. Keepspire, the developer and the cloud cannot retrieve your master password for you. Back up your master password / passphrase safely, and we recommend making regular local backups as your fallback if you lose it.

Everyday use doesn't rely on cloud sync; your data stays on your device. Device transfer is currently unavailable.