Best Private Photo Vault Apps for iPhone (2026)
Amazingface, Apple Hidden Album, Vaultaire, Ente Photos, and LockMyPix can all reduce casual exposure of selected photos, but they do not protect the same copy in the same place. Some keep an encrypted vault primarily on your device. Some remain inside the system photo library. Others are designed around end-to-end encrypted cloud backup.
“Best” here means best fit, not a single winner: these products do not protect the same copy in the same place, so the right one depends on what you are trying to keep private and from whom. This comparison weighs storage boundaries, published cryptography, recovery, cloud paths, developer-reported privacy labels, source access, and independent audits — every claim links to its primary source.
Facts checked: August 7, 2026. Product behavior and App Store labels can change. Verify the current app, settings, documentation, and recovery flow before moving or deleting important files.
The short answer
- Apple Hidden Album is the simplest built-in option when you want items removed from normal Photos views and accept the iPhone’s Face ID, Touch ID, or device-passcode boundary.
- Vaultaire is a current iPhone vault option for people who want a pattern-derived local vault, a user-held recovery phrase, and optional encrypted iCloud backup. Its reviewed documentation publishes AES-256-GCM and PBKDF2-HMAC-SHA512 at a documented 600,000 iterations, but no public source code or independent product audit was found.
- Ente Photos is the strongest fit in this group for people who prioritize open source, published architecture, independent audits, cross-platform access, and end-to-end encrypted cloud backup. It is a cloud photo service by design, not a local-only vault.
- LockMyPix may fit people who want an established encrypted vault, fake-vault features, and iOS/Android availability. Its current App Store label also reports identifiers used for tracking, so the privacy trade-off should be considered separately from file encryption.
- Amazingface may fit people who want a local encrypted vault, no Amazingface cloud photo library, published Argon2id parameters, and provider-independent recovery—while accepting that the released app is iPhone-only, closed source, has no public independent audit, and keeps linked service records for accounts, subscriptions, quota, routing, referrals, reports, and encrypted delivery.
There is no universal winner. Cloud backup can reduce device-loss risk while adding an account, a remote service, and new recovery paths. A local vault can reduce provider-cloud exposure while making device loss, app deletion, and lost recovery material more consequential.
How to read the evidence
Each claim below uses one or more of these evidence types:
- Amazingface implementation disclosure A specific statement published by the Amazingface team about the current implementation. It is first-party evidence, not an audit.
- Official product documentation A statement published by the product or platform owner. It describes the vendor’s documented design, not an independent finding.
- Developer-reported App Store label A privacy disclosure submitted by the developer. Apple states that this information has not been verified by Apple.
- Public source code Code outsiders can inspect. It does not prove that the store build is identical or vulnerability-free.
- Independent audit A dated report by a named outside reviewer. It only supports the versions, components, and scope actually examined.
- Not publicly stated The reviewed official sources did not provide enough detail. This does not mean the feature is absent or insecure.
- Hands-on test not performed We did not run a standardized test for this observation and do not present it as a result.
Six decision factors
| Decision factor | Amazingface | Apple Hidden Album | Vaultaire | Ente Photos | LockMyPix |
|---|---|---|---|---|---|
| Storage model | Imported media becomes encrypted files in an app-managed local vault. No Amazingface cloud photo library.
| A locked collection inside Apple Photos; not a separate user-managed vault container.
| Encrypted local vault on iPhone; optional encrypted iCloud backup.
| Media is encrypted on-device and backed up to Ente’s cloud; local copies can also exist or be cleared after backup.
| Encrypted local vault. Vendor documentation says imported files are stored locally and are not transmitted to LockMyPix servers without user consent; encrypted backup files are available.
|
| Published encryption and key derivation | XChaCha20-Poly1305; Argon2id. iOS default m=64 MiB, t=3, p=4; macOS default m=256 MiB, t=3, p=4; 64-byte output. Each vault stores its own parameters in its manifest.
| Apple publishes platform and iCloud security architecture, but not a separate Hidden Album cipher or KDF specification.
| AES-256-GCM for files; PBKDF2-HMAC-SHA512 with a per-vault salt, documented at 600,000 iterations. ChaCha20 is described separately for metadata.
| XChaCha20 and XSalsa20 with Poly1305; Argon2id. The key hierarchy, architecture and client source are public.
| AES-CTR for imported files and for encrypted backups. The reviewed official sources did not state a complete password key-derivation configuration.
|
| Unlock and recovery | Separate vault password plus a user-held recovery phrase. Amazingface cannot restore access if both are lost.
| Face ID, Touch ID, or the device passcode; no separate Hidden Album password.
| A drawn pattern derives the encryption key, plus a 12- or 24-word recovery phrase described by the vendor as a second user-held path to the same vault key.
| Account password plus a 24-word recovery key; Ente says support cannot recover encrypted data without it. Optional trusted-contact recovery can be configured.
| LockMyPix says it does not store or know the vault password. It also offers optional e-mail-based password recovery, in which LockMyPix stores the password encrypted on its own servers without linking it to a specific vault; users can deactivate and delete this option in settings. How that stored password relates to the file-encryption key is not described in the reviewed sources.
|
| Cloud or backup path | No Amazingface cloud photo library. AmazingDrop separately relays end-to-end encrypted transfer ciphertext for a limited time (24/48/72 hours by plan).
| Hidden items remain in Photos and sync through iCloud Photos when it is enabled. Advanced Data Protection can extend end-to-end encryption to Photos for eligible accounts and regions.
| Optional encrypted iCloud backup, encrypted before upload with key material derived from the pattern. This remains a vendor claim unless independently tested.
| End-to-end encrypted provider cloud backup is the core service model, with multi-device sync and self-hosting available.
| Vendor privacy documentation says files are not sent to LockMyPix servers or stored on backup servers without the consent of the user (cloud backup only). If the user enables LockMyPix Cloud, backup files go to the Google Drive or Dropbox account the user provides, not to a LockMyPix-operated server.
|
| Developer-reported App Store privacy label | “Data Linked to You”: Purchases, Identifiers, and Usage Data for App Functionality; no data reported as used for tracking — developer-reported, not verified by Apple.
| Not applicable as a separate third-party App Store listing; Hidden Album is a feature of Apple Photos.
| “Data Not Linked to You”: Usage Data and Diagnostics — developer-reported, not verified by Apple.
| “Data Linked to You”: Contact Info and Identifiers. “Data Not Linked to You”: Diagnostics — developer-reported, not verified by Apple.
| “Data Used to Track You”: Identifiers. Purchases, Identifiers, Usage Data and Diagnostics are also reported as not linked to identity. The vendor privacy page separately names Google AdMob, AppLovin and Facebook for ads, and Google Analytics and Firebase for monitoring, with ads absent in the Premium version.
|
| Public source code and independent audits | Closed source. No public third-party app security audit.
| Extensive public platform-security documentation. This comparison did not identify a Hidden Album-specific source release or independent product audit.
| No public source repository or independent product audit was found in the official sources reviewed.
| Fully open source. A 2023 cryptography audit by Cure53 with Symbolic Software covered the architecture and client implementations; a 2025 Cure53 audit, sponsored by CERN, covered server-side code and infrastructure. Both disclose scope and findings.
| No public source repository or independent product audit was found in the official sources reviewed.
|
The table compares documented models and evidence boundaries—not a one-dimensional security score. An App Store privacy label is not an audit. An audit is not a lifetime guarantee. An algorithm name is not a complete product assessment.
1. Which copy is being protected, and where does it live?
Amazingface creates an encrypted copy inside an app-managed local vault. Its provider does not host that vault as an Amazingface cloud photo library. AmazingDrop is separate and handles encrypted transfer data for limited-time delivery. Amazingface Security
Apple Hidden Album moves an item out of normal Photos views but keeps it inside the Photos library. Apple says the Hidden and Recently Deleted collections are locked by default and use Face ID, Touch ID, or the device passcode. If iCloud Photos is enabled, hidden items remain part of that synchronized library. Apple: Hide photos and videos
Vaultaire describes an encrypted local iPhone vault with optional encrypted iCloud backup. That optional backup is a different trust and availability path from keeping the only copy on the phone. Vaultaire encrypted iCloud backup
Ente Photos is an end-to-end encrypted cloud photo service. Files and metadata are encrypted before upload, and encrypted copies are stored by the service for backup and multi-device access. This is a different product model from a local-only vault. Ente architecture
LockMyPix describes encrypted local storage and says files are not sent to LockMyPix servers or stored on backup servers without the user’s consent (cloud backup only). Its documentation also supports encrypted backups that the user creates. LockMyPix privacy · LockMyPix backup FAQ
Before choosing, identify the exact copy you want to protect: the item in Apple Photos, a separate encrypted vault copy, a provider-hosted encrypted backup, or all three.
2. What cryptography and key derivation are publicly described?
Amazingface publishes XChaCha20-Poly1305 for vault media and Argon2id for password-based derivation. It also publishes the current m, t, p, and output length for iOS and macOS creation defaults, plus the rule that each vault keeps its saved parameters. This is an Amazingface implementation disclosure, not an independent review. Amazingface Security
Apple publishes extensive platform-security and iCloud documentation. Its user documentation explains how Hidden Album is locked, but it does not present Hidden Album as a separate vault with its own user-selected cipher, KDF, and recovery phrase. Apple Platform Security
Vaultaire publishes AES-256-GCM and PBKDF2-HMAC-SHA512 with a per-vault salt, documented at 600,000 iterations. Its pages describe ChaCha20 separately for metadata. Vaultaire security architecture
Ente Photos publishes XChaCha20 and XSalsa20 with Poly1305, Argon2id, its key hierarchy, public source code, and external review history. That is the broadest public verification surface in this group. Ente security FAQ · Ente source
LockMyPix states AES-CTR in its current iOS listing and encrypted AES-CTR backups in its documentation. The reviewed official sources did not state a complete password KDF configuration, so this comparison stops there. LockMyPix on the App Store · LockMyPix backup FAQ
XChaCha20-Poly1305, AES-GCM, and other correctly implemented authenticated-encryption designs can all be strong. More disclosure improves evaluability; it does not automatically prove a better implementation.
3. Who can restore access after a lost credential?
Amazingface uses a separate vault password and user-held recovery phrase. The provider cannot restore the vault if both are lost.
Apple Hidden Album follows the Apple device authentication boundary: Face ID, Touch ID, or device passcode. It does not create a separate Hidden Album password.
Vaultaire says the pattern derives the encryption key and a 12- or 24-word phrase provides a second user-held path to the same vault key. Vaultaire secret phrase
Ente Photos uses an account password and 24-word recovery key. Ente says support cannot recover encrypted data if the user is logged out everywhere and lacks both. Ente also offers an optional trusted-contact recovery feature; users enabling it should understand its delay and trust model. Ente recovery FAQ · Ente Legacy
LockMyPix documents password, PIN, pattern, and biometric access. Its privacy documentation says it does not store or know the vault password, and separately describes an optional e-mail-based password recovery feature in which LockMyPix stores that password encrypted on its own servers, without linking it to a specific vault; users can deactivate and delete this option in settings. How that stored password relates to the file-encryption key is not described in the reviewed sources, so this page does not claim who ultimately can or cannot restore file access. LockMyPix privacy
Convenient recovery can reduce data-loss risk while adding another account, person, device, or provider to the trust model. Neither “recoverable” nor “non-recoverable” is universally better.
4. What cloud or backup path exists?
Amazingface does not host the private vault as a cloud photo library. AmazingDrop is an encrypted transfer path with limited relay retention (24, 48, or 72 hours depending on plan), not permanent album storage. AmazingDrop
Apple Hidden Album remains part of Photos. When iCloud Photos is enabled, hidden items sync with the library. Advanced Data Protection can extend end-to-end encryption to Photos for eligible accounts and regions, but the storage model remains iCloud-based. Apple: Advanced Data Protection
Vaultaire offers optional encrypted iCloud backup. Its documentation says the vault is encrypted before upload using key material derived from the pattern. This remains a vendor claim unless independently tested. Vaultaire encrypted iCloud backup
Ente Photos is designed around end-to-end encrypted cloud backup and multi-device access. It is also open source and self-hostable, but using the hosted service still means depending on its account and availability model. Ente Photos
LockMyPix says it does not send files to its own servers or store them on backup servers without the user’s consent (cloud backup only). Its LockMyPix Cloud backup destination is the user’s own Google Drive or Dropbox account, not a LockMyPix-operated server. Verify where a backup file is stored, who controls that destination, and how the key is recovered before relying on it.
“No provider cloud photo library” does not mean “no copy can exist in any cloud.” iCloud Photos, iCloud device backups, exported files, third-party backup tools, and recipient devices must be reviewed separately.
5. What does the App Store privacy label report?
The App Store label is useful because it is easy to inspect and uses Apple’s standard categories. It is still a developer-submitted disclosure. Apple explicitly states that the information has not been verified by Apple, and the word “collect” follows Apple’s definitions.
As checked on August 7, 2026:
- Amazingface: “Data Linked to You”: Purchases, Identifiers, and Usage Data for App Functionality; no data reported as used for tracking — developer-reported, not verified by Apple.
- Apple Hidden Album: Not applicable as a separate third-party App Store listing; Hidden Album is a feature of Apple Photos.
- Vaultaire: “Data Not Linked to You”: Usage Data and Diagnostics — developer-reported, not verified by Apple.
- Ente Photos: “Data Linked to You”: Contact Info and Identifiers. “Data Not Linked to You”: Diagnostics — developer-reported, not verified by Apple.
- LockMyPix: “Data Used to Track You”: Identifiers. Purchases, Identifiers, Usage Data and Diagnostics are also reported as not linked to identity. The vendor privacy page separately names Google AdMob, AppLovin and Facebook for ads, and Google Analytics and Firebase for monitoring, with ads absent in the Premium version.
These rows describe the public labels, not independently observed network behavior. Read the linked privacy policy and compare it with the app’s account, subscription, support, analytics, and backup features.
6. What can outsiders inspect or audit?
Ente Photos leads this comparison on public verification surface. Its client and server code are public. A 2023 cryptography audit by Cure53, working with Symbolic Software, covered its architecture and client implementations. A 2025 audit by Cure53, sponsored by CERN, covered server-side code and infrastructure, disclosing 15 findings with 12 fixed during the audit period. Both reports still apply only to their stated scope and time. 2023 audit · 2025 audit
Amazingface publishes its current storage, recovery, transfer, algorithms, and Argon2id parameters, but remains closed source and has no public third-party app audit.
Apple publishes extensive platform-security documentation, but this comparison does not treat that as a dedicated external audit of Hidden Album as a separate vault product.
Vaultaire and LockMyPix publish useful first-party product details. No public source repository or independent product-specific audit was found in the official sources reviewed for this page.
Absence of a public audit does not prove insecurity. A published audit does not prove that every later build is safe. The useful questions are who reviewed what, which version, when, what they found, and what was fixed.
Checks you can run yourself
Use disposable, non-sensitive files. Record the app version, iOS version, settings, and test date so someone else can repeat the observation.
| Check | How to run it | What it can show | What it cannot prove |
|---|---|---|---|
| App Store privacy label | Open the current App Store page and expand App Privacy. | The developer-reported collection, linkage and tracking categories. | Accuracy, cryptographic quality, absence of network traffic, or absence of all third-party code. |
| App Privacy Report | Turn on Settings → Privacy & Security → App Privacy Report; use the app normally for up to seven days; inspect Data & Sensor Access and App Network Activity. | Domains contacted and protected resources accessed during the observed period. | Payload contents, domain ownership, end-to-end encryption, inactive code paths, or what happens outside the observed period. |
| Airplane Mode workflow | Import disposable media, lock, unlock, browse and export while offline. | Which tested functions can operate without a network connection. | That no cloud copy exists, that all features are local-only, or that the implementation is secure. |
| Recovery rehearsal | Create a disposable vault or account, save the prescribed recovery material, then follow the forgotten-credential flow. | The user-visible recovery path and whether another device, email, provider or trusted contact is involved. | The complete backend key model without supporting documentation or code review. |
| Backup-location check | Review the app backup toggle, iCloud Photos, iCloud Backup, Files destinations and any provider cloud setting separately. | Which configured destinations may contain a protected or unprotected copy. | Whether every historical copy has been deleted, or whether every provider implements its claims correctly. |
| Source and audit check | Follow the source repository and the original dated audit report; record version, scope, findings and remediation. | What code is public and what the auditor actually examined. | That the App Store binary matches the source, or that unreviewed versions and components are free of vulnerabilities. |
Apple says App Privacy Report shows domains contacted and protected data or sensors accessed during the past seven days after the report is enabled. Do not label its output a penetration test or network-content audit. Apple: App Privacy Report
Which option may fit your priorities?
Choose Apple Hidden Album when…
You want the simplest built-in workflow, accept the device-passcode boundary, and want tight Photos and iCloud integration. It may be a poor fit if someone else knows your device passcode or if you need a separate vault password and recovery boundary.
Consider Vaultaire when…
You want a current iPhone-focused encrypted vault with pattern access, a user-held recovery phrase, optional encrypted iCloud backup, and decoy or duress-oriented features. Verify its KDF work factor, backup behavior, and destructive features before relying on them.
Consider Ente Photos when…
You want open source, independent audits, automatic end-to-end encrypted cloud backup, multi-device access, Android, desktop, web, sharing, or self-hosting. It may be a poor fit if your primary goal is to avoid a provider cloud photo library altogether.
Consider LockMyPix when…
You want an established encrypted vault, iOS and Android availability, fake-vault features, and user-managed encrypted backups. Review its current advertising, tracking, recovery, and backup disclosures alongside its encryption claims.
Consider Amazingface when…
You want a local encrypted vault, no Amazingface cloud photo library, separate recovery material, published Argon2id parameters attached to each vault, no ads, and no cross-app tracking. It may be a poor fit if you need Android, a released desktop app today, provider cloud backup, open-source code, an independent audit, provider-assisted recovery, or a service with no linked operational metadata.
Other options considered
The primary table is limited to five products that represent distinct current models. These additional products remain relevant and may fit different needs:
They are not excluded because they are necessarily weaker. A five-product table is already dense on mobile; these products can receive separate, source-linked comparison pages later if search demand and maintenance capacity justify them.
Methodology and limitations
We reviewed public official documentation available on August 7, 2026, current App Store privacy labels, public source repositories, and published audit reports. We compared six factors that materially change storage exposure, password-guessing cost, recovery authority, cloud dependency, disclosed data handling, and outside review.
We did not install every product, inspect app containers, capture traffic, reverse-engineer binaries, test paid features, audit servers, or verify that App Store builds match public source code. Vendor documentation is cited as vendor documentation. App Store labels are cited as developer-reported labels. Independent audits are identified separately with their date and scope.
We do not assign a numerical security score. The right choice depends on your threat model, acceptable cloud exposure, platform needs, recovery plan, and tolerance for data loss. “Not publicly stated” means that the reviewed official sources did not provide enough detail; it does not mean a feature is absent or unsafe.
Corrections
Products and documentation change. If a factual statement is outdated or a primary source provides more detail, email support@amazingface.app with the exact claim and source URL. We will review documented corrections and update the facts-checked date when the page materially changes.
Sources reviewed
Amazingface
Standards and evaluation tools
- RFC 9106: Argon2
- OWASP Password Storage Cheat Sheet
- Apple App Privacy Details
- Apple App Privacy Report
Apple Hidden Album
Vaultaire
- Encrypted iCloud backup
- Security architecture
- Secret phrase
- Pattern encryption
- Vaultaire on the App Store
Ente Photos
- Ente architecture
- Security and privacy FAQ
- Public source repository
- Ente Legacy (trusted contacts)
- Ente Photos
- Ente Photos on the App Store
- 2023 cryptography audit
- 2025 server and infrastructure audit