Family Vault

How your documents are protected

The Family Vault holds the papers a family cannot afford to lose. This page explains, in plain language, what happens to a document you put in it, who is able to open it, what gets recorded, and — just as importantly — what it does not protect you from.

Last updated September 10, 2026

What happens to a file you add

This is an ordinary document, which is what you get unless you seal it. The scrambling happens on our side before the file is saved, so what actually sits in storage is unreadable on its own. Sealing moves that scrambling onto your own device and changes several of the answers below — it has its own section further down.

  • The moment a file arrives it is scrambled using AES-256-GCM, the same method banks and governments use. Every single file gets its own fresh key, so unlocking one tells you nothing about any other.
  • Those per-file keys are themselves locked with a main key that is not kept in the app at all. It lives in Microsoft Azure's key service, a system built only for holding keys, and the app is handed it at startup. It is not in the database, not in our code, and not in any backup of your family's information. Only the app is allowed to fetch it, every fetch is recorded, and the key cannot be permanently deleted by anyone — including us — for 90 days, so nobody can destroy your documents by destroying the key.
  • The name you give a document and any notes you write on it are scrambled the same way, with their own fresh key, before they are saved.
  • The scrambled file is stored in its own private area of Microsoft Azure that nobody can read from the outside, even with the exact web address. It is saved without a name or file type attached, so nothing about it says "passport".
  • Microsoft encrypts its own disks underneath all of that, and everything travels over a secure connection.
  • When you open a document, it is unscrambled and sent to you with instructions telling your browser and everything in between not to keep a copy.

Who can open it

  • Only parents in your own household. Grandparents, aunts and other family-circle adults cannot see the household's vault, even though they can use the rest of the app. The one thing they can do is collect documents that were deliberately left to them as a Time Capsule keyholder, behind a passcode of their own — and nothing else.
  • A child sees only the documents that are about them and that a parent has specifically ticked. They can read and download those, and can never change or delete anything.
  • Your vault passcode is separate from your password, so a phone left unlocked on the kitchen counter is not enough to open a birth certificate.
  • Five wrong tries and the passcode stops working for fifteen minutes. The passcode itself is stored scrambled in a way that cannot be reversed, so nobody can read it back out, including us.
  • Every request is checked on our servers against your family and your role. Hiding a button in the app is never what keeps anyone out.
  • There is no staff screen anywhere in this app that lists or opens a family's vault documents.
  • A sealed document is narrower still: only the people holding a copy of its key. That is whoever sealed it, any other household parent they chose to let in, and any keyholders they left it to. When a parent seals a document, the other parent is offered a copy by default — but if it was left unticked, that parent sees the document exists and cannot open it, and neither can we. The person who sealed it can hand over a copy later from the document itself.

What gets written down

  • Opening the vault, typing the wrong passcode, viewing, downloading, adding, editing and deleting a document, creating, using or switching off a share link, and giving another parent a copy of a sealed document's key.
  • Each entry records who, what, when, roughly where from, and which browser or phone was used.
  • The list is kept for two years and is visible to the parents in your household. It is your record, not just ours.

Sealing a document, so we cannot open it either

Everything above describes a vault we hold the key to. Sealing is the other option: the document is locked on your own device before it reaches us, with a passphrase we never receive. It is genuinely stronger, and it genuinely costs you things. Both halves matter, so here is each.

  • You choose a separate passphrase — a real one, not the six-digit passcode. Your device turns it into a key and locks a document with it. The passphrase is never sent to us, and neither is the key. What arrives here is scrambled bytes we have no way to unscramble.
  • The file, the name you gave it, your notes and even the file names are all locked. What we can still see is the same short list as always: its kind, its expiry date and who it is about.
  • Because we cannot read the name, a renewal reminder for a sealed document says "A sealed document expires on March 3" and leaves it at that. You still get the reminder; the inbox does not get the name.
  • You are shown a recovery code once, and asked to type it back. It is the only other way in. We store a copy of your key locked by that code, and nothing else — so if the code is lost we cannot show it to you again or work around it.
  • Entering the passphrase opens your sealed documents for as long as the page is open. Reloading asks again, because a key that survived a reload would also survive somebody else picking up the phone.
  • A sealed document cannot be shared by link and cannot be shown to a child in their own view. Both of those work by our server opening the document for someone else, and a sealed one is exactly the document we cannot open.
  • A sealed document cannot be edited either — not its name, not its notes, not its expiry date, and no files can be added. To change anything, delete it and add it again. You can always delete one.
  • Sealing keeps a document from us, not from your family. As you seal it, the other parent in your household is offered their own copy of the key, locked to their passphrase — ticked by default, and yours to untick. If they had not set up a passphrase yet, or you change your mind later, you can give them a copy from the document once you have unlocked it. Nobody needs your passphrase or your device for any of this.
  • It can still be left to your Time Capsule keyholders. When you turn that on, your device gives each keyholder their own copy of the key, locked to their passphrase — so they can open it later without ever knowing yours. Each of them has to have set up a passphrase first, and the vault will tell you by name who has not.
  • If everyone who holds a key loses their passphrase and recovery code, the document is unrecoverable. There is no support request that fixes this. That is not a gap in the design; it is the design.
  • If an account holding the only key to a sealed document is deleted, that document is deleted with it, because at that point it is bytes nobody alive can read.

What this does not protect you from

Every one of these is a real limit. We would rather you knew about them now than discovered one later.

  • An ordinary document is not one only you can open. Because we hold the key, we are technically able to unscramble your files, and so is anyone who breaks into our servers or legally compels us. That is the price of reminders, share links, a child's own view and a document reaching your keyholders. Seal a document and we genuinely cannot open it — but you give up all four of those, and a lost passphrase becomes final.
  • A document's name and notes are scrambled, but its kind, its expiry date and who it is about are not. That is true whether or not it is sealed: those three have to stay readable for a renewal reminder to be sent at all. So a stolen copy of our database would still show that your household has a passport expiring in March — just not whose, or what you wrote about it. For an ordinary document we could still read the name if we were compelled to, so there is no reason to type a full passport or account number into it.
  • Anyone holding a share link can open it until it expires or runs out of openings. Email is not a secure way to send something, and links get forwarded. The short life, the limited number of openings, being able to switch it off, and seeing every opening in your Activity list are what stand in for a lock.
  • Your login is still the front door. The vault passcode is a second lock behind it, but if someone takes over your email account they can work on getting through the first one.
  • Six to ten digits is not a strong secret by itself. The lockout after five wrong tries is what makes it good enough. Please do not reuse a child's sign-in PIN, a birth year, or anything printed on something in your wallet.
  • Deleting a document removes the file and its details straight away, but our database backups keep a copy of the details for up to 35 days before they age out.
  • A file you download becomes an ordinary, unscrambled file in your Downloads folder. Nothing this app does can reach it there.
  • We check that an upload really is a PDF, a photo or a Word document, but we do not scan files for viruses.

What is worth doing on your side

  • Keep the originals. This is a copy you can reach from anywhere, not a replacement for the paper in a fire safe or a safe deposit box.
  • Pick a vault passcode you do not use anywhere else, and do not write it in a note on the same phone.
  • Send a share link for one document rather than giving someone a longer window than they need, and switch it off once they have what they asked for.
  • Look at the Activity list now and then. It is there so you can check, not so we can.
  • Tick "let them see it" for a child only when you would be comfortable with them having their own copy.
  • If you seal anything, write the recovery code on paper and keep it away from the device you sign in on. It is the one thing here that nobody can reissue for you.

Questions, or something that looks wrong

If anything on this page does not match what you see, or you think you have found a weakness, please get in touch. We would much rather hear it from you.

Our general privacy information covers the rest of the app.