← Blog

Hidden Album vs Photo Vault on iPhone

Comparison of the iPhone Hidden Album and a separate encrypted photo vault

The iPhone Hidden Album and a separate photo-vault app solve related but different problems. The Hidden Album removes items from normal Photos views and is locked by default with Face ID, Touch ID, or the device passcode. A separate vault can move selected files into app-managed storage, potentially with its own password, file encryption, cloud behavior, and recovery model.

Neither option is universally “more secure.” The right choice depends on who you are trying to keep out, whether you use iCloud Photos, and how much data-loss risk you can accept.

Information checked: July 30, 2026.

The short comparison

QuestioniPhone Hidden AlbumSeparate photo vault
Does it remove items from the main Photos grid?YesUsually, after import and after you remove the Photos-library original
Is access locked?Yes by default, using Face ID, Touch ID, or device passcodeDepends on the app; may use biometrics, device passcode, or a separate password
Is it a separate storage container?No; it remains part of the Photos libraryOften, but implementation varies
Does iPhone device encryption still apply?YesYes; every iOS app also runs on top of iPhone Data Protection
Are files additionally encrypted by the app?The distinction is not documented as a separate user-managed vaultDepends on the app; verify its documentation
Can items sync with iCloud Photos?Yes, when iCloud Photos is enabledNot through iCloud Photos if originals are removed, but app data may have separate backup behavior
Can it use a separate password?No separate Hidden Album password; it uses device authenticationSome apps can; others only reuse device authentication
Recovery responsibilityTied to the Apple device/account ecosystemVaries; some providers can reset access, while zero-knowledge or local designs may not
Data-loss riskLower when Photos is synchronized and recoverableCan be higher for local-only vaults if the device, app, password, or recovery material is lost
Best forConvenience and preventing casual browsingSeparate storage, credentials, or cloud boundary

The table deliberately says “depends” for photo vaults. There is no technical rule that every app using the word “vault” must encrypt files in the same way.

What the Hidden Album actually does

Apple says hidden photos and videos are moved to the Hidden collection, no longer appear in the Library or other albums, and can be unlocked with Face ID or Touch ID. The Hidden collection is locked by default, and users can turn off “Show Hidden Album” so it is not visible in Photos. Apple’s Hidden Album instructions

That makes the Hidden Album useful when:

  • you want a photo out of the main grid;
  • you occasionally hand someone your phone to view other photos;
  • you prefer Apple’s built-in workflow;
  • the device passcode is not shared with the person you are concerned about.

It is inaccurate to describe Hidden photos as if they sit on an otherwise unencrypted iPhone. Apple’s Data Protection system encrypts files on the data volume with per-file keys and hardware-backed key management. Apple Platform Security

The meaningful limitation is different: Hidden is an access-controlled collection inside the same Photos library. It does not create a new password, a separate third-party vault, or a per-photo “never sync to iCloud” policy.

What a separate photo vault can change

A photo vault may change four things.

1. Storage location

The app can copy or import selected photos into its own app-managed container. If you later remove the original from Photos, the vault copy is no longer an item in the Photos library.

That separation is useful only if the import is complete and the vault copy is recoverable. An app that merely places an unlock screen in front of ordinary files offers a different model from one that stores encrypted files inside its own container.

2. Credentials

A vault may use a password that is different from the iPhone passcode. This can matter in a household where someone knows the device passcode.

But check the actual recovery path. If the app lets the provider reset the password, the provider may be part of the trust model. If the provider cannot reset it, losing both the password and recovery material may permanently destroy access.

3. Additional file encryption

Some vaults encrypt each imported file or an encrypted database. Others may rely mainly on iOS app isolation and an access lock. Both still benefit from iPhone device encryption; they simply add different layers.

Look for specific answers:

  • Which files are encrypted?
  • Where are thumbnails stored?
  • How is the key derived and stored?
  • Does the server ever receive plaintext or keys?
  • Is the implementation open source or independently audited?

Algorithm names alone are not proof that the complete product is secure.

4. Cloud and backup behavior

A vault can keep selected files out of iCloud Photos because the files are no longer Photos-library items. That does not automatically prove there is no cloud copy anywhere:

  • the app may operate its own cloud backup;
  • iOS app data may be included in iCloud Backup;
  • another backup app may have copied the original before it was removed;
  • the user may have exported a copy to iCloud Drive.

If “no cloud copy” is a hard requirement, review all of those paths.

iCloud encryption needs a fair explanation

Under standard iCloud data protection, Apple says iCloud data is encrypted in transit and stored encrypted, while Apple retains keys for many categories so it can help users recover their data. With Advanced Data Protection enabled, Photos is among the additional categories protected with end-to-end encryption, and Apple cannot recover that protected data for the user. Apple’s current iCloud security overview

This creates two different decisions:

  • Who should hold the decryption keys?
  • Should the file be in cloud storage at all?

Advanced Data Protection can address the first for iCloud Photos. It does not turn iCloud Photos into local-only storage.

Choose by threat model

“I just do not want someone to swipe into a personal photo.”

Use the Hidden Album, keep authentication enabled, and optionally hide the collection itself. It is simple, built in, and likely sufficient.

“Someone who uses my phone knows the device passcode.”

The Hidden Album uses device authentication. A separate vault with a truly separate password may provide a useful additional boundary. Confirm that the app does not silently fall back to the device passcode in a way that defeats your goal.

“I want a few photos outside iCloud Photos.”

Hiding is not enough. Hidden items remain part of the Photos library and hidden status can synchronize across devices. You need to move verified copies outside Photos and then remove the Photos-library originals. Follow the careful process in How to Keep Selected iPhone Photos Out of iCloud Photos.

“I am more worried about losing the photos than cloud storage.”

The integrated Photos and iCloud experience may be the better fit. A local-only vault can create a single point of failure. Privacy and availability pull in different directions; do not solve a low-probability confidentiality concern by creating a high-probability data-loss problem.

“I want to send the photo privately.”

Neither hiding nor local file encryption automatically protects a transfer. Use an end-to-end encrypted transfer or messaging service, verify the recipient, and remember that the recipient can retain the decrypted file.

How to evaluate any photo vault fairly

Before trusting a vault with an irreplaceable photo or video, test it:

  1. Read the storage model. “Private” and “secure” are not technical details.
  2. Check the credential model. Device passcode, separate password, biometrics, recovery key, or provider reset?
  3. Check cloud paths. Provider cloud, iCloud Photos, iCloud Backup, iCloud Drive, and other backup apps.
  4. Import a test set. Include a photo, long video, Live Photo if supported, and files with metadata you care about.
  5. Verify playback and full-resolution export.
  6. Simulate the recovery flow before deleting an original.
  7. Read what happens when the app is deleted.
  8. Look for independent evidence. Public architecture, source code, audits, or reproducible tests are stronger than adjectives.

Where Amazingface fits

Amazingface is designed for the case where selected photos and videos should be stored as encrypted files in a separate local vault rather than kept in an Amazingface cloud photo library. It uses its own vault password and Recovery Phrase model, and its AmazingDrop feature transfers encrypted data through a temporary relay.

That model has a deliberate trade-off: if you forget the vault password and lose the Recovery Phrase, Amazingface says it cannot recover the vault; deleting the app may also delete local Vault data. Read the security model and FAQ warnings before moving important files.

It is not necessary to switch if Apple’s Hidden Album already matches your threat model.

If you are choosing between specific products rather than categories, see our evidence-layered comparison of Amazingface, Apple Hidden Album, Vaultaire, Ente Photos, and LockMyPix.

Bottom line

Use the Hidden Album for convenient, built-in protection against casual browsing. Consider a separate vault when you need a different storage container, credentials, recovery model, or cloud boundary. In either case, keep a strong device passcode and understand exactly how you will recover the files.

To map all five privacy layers before choosing, read How to Protect Private Photos on iPhone.

FAQ

Can someone open the Hidden Album with my iPhone passcode?

Yes. Apple’s Hidden collection can use Face ID, Touch ID, or the device passcode. If another person knows the passcode, the Hidden Album may not address that threat.

Do Hidden photos sync to iCloud?

If iCloud Photos is enabled, hidden photos remain in the Photos library, and Apple states that hidden status is reflected on other devices using iCloud Photos. Hiding is not a per-item cloud exclusion control.

Does a separate vault keep files out of every cloud backup?

Not automatically. It may keep files out of iCloud Photos after the Photos originals are removed, but the vault app may have its own cloud service or may participate in iCloud device backup. Check the app’s documentation and your backup settings.

Which option has more data-loss risk?

A local-only vault can have more data-loss risk because a lost device, deleted app, forgotten password, or lost recovery phrase may remove the only accessible copy. A synchronized Photos library can improve availability but has a different cloud and account threat model.