Questions, answered honestly
Including the uncomfortable ones. If something isn't covered here, the Security page goes deeper.
Security & privacy
Can anyone at ShareMyVault see what's inside my vault?
No. Your data is encrypted on your own device before it's ever saved. Our servers only ever hold scrambled data we have no way to read — that's what "zero-knowledge" means. There is no server-side decryption path in the product at all.
Is my data safe if your servers are breached?
Yes. Anyone who reached our servers would find only encrypted blobs and no keys to open them. The keys never leave your device.
What encryption do you use?
AES-256-GCM for data, Argon2id for turning your passphrase into a key, and a 24-word BIP-39 phrase for recovery — all via open-source, audited libraries. The full detail is on our Security page.
Could you be forced to hand over my data?
We could only ever hand over what we hold: ciphertext and the metadata needed to run the service. We cannot decrypt your vault for anyone, because the keys exist only on your devices.
Account & recovery
What's the difference between my password and my vault passphrase?
Your account password signs you in — it's a normal login. Your vault passphrase is separate and unlocks the encryption itself. Signing in shows your vault exists; only the passphrase can open what's inside.
What if I forget my vault passphrase?
Your 24-word recovery phrase unlocks your vault and lets you set a new passphrase. That's exactly what it's there for — keep it somewhere safe, like with your important papers.
What happens if I lose both my passphrase and recovery phrase?
Because only you can open your vault, only you can recover it. If both are lost, your data can't be restored — not by us, not by anyone. We're upfront about this because it's the trade-off that keeps your vault truly private.
Does my vault lock itself?
Yes. After 10 minutes of inactivity the key is wiped from memory and the vault locks. You can also lock it instantly from the sidebar.
Sharing & family
How do beneficiaries work?
You name the people who should receive your information and invite them by email. They create their own account — your keys are never sent to them or to us.
What do invitation emails contain?
Only who invited whom and a signup link. No vault content ever travels by email — the email system physically can't read your data.
Can I remove someone's access?
Yes, at any time, from the Beneficiaries or Trustees section of your vault.
Plans & billing
Do I need a credit card to start?
No. You can create a vault and start saving what matters right away — no credit card required, and the free plan never expires.
Is the paid plan more secure?
No — every plan gets identical zero-knowledge encryption. Paying unlocks more features (assets, documents, unlimited beneficiaries), never more security.
What happens to my data if I cancel or downgrade?
Nothing is deleted and nothing is ever decrypted by us. Sections beyond your plan's limits become read-only until you upgrade again.
How does payment work?
Billing is handled entirely by Stripe's hosted checkout and billing portal — we never see or store your card details.
Ready when you are.
Create your free vault