Not because we promise. Because of how it's built — and because every claim on these slides is one you can verify yourself.
Not "encrypted on our servers." Not "in transit." Before. The unreadable version is the only version that ever exists on disk, in iCloud, or on the wire. There is no moment where your photo travels or rests as a photo.
We can't see your photos. Apple can't see your photos. Someone who steals the bytes has noise.
PBKDF2-HMAC-SHA256 · 600k rounds — turns your code into a key, and makes every single guess deliberately expensive.AES-256-GCM, tamper-evident. Thumbnails too. The point is containment: a key leaked from one open file opens that file alone — a viewer bug can't cascade into the vault. (And honestly: if the master key above it ever fell, everything falls — which is why your code gets the 600,000-round treatment.)And it goes to your private iCloud database — Veilbox has no servers. There is nothing of ours to breach, and nothing of ours to subpoena.
Data Not Collected. The app talks to exactly one host: Apple's iCloud, carrying your sealed vault.
"Data Used to Track You" — identifiers and usage data, declared on its own App Store page. A privacy app that tracks you is a contradiction we chose not to ship.
Any vault that promises more than this is lying to you somewhere. We'd rather be trusted for what's true.
Encrypted before it's stored. Synced as ciphertext. Tracked never.
And always free to leave — which is why you'd stay.