“Encrypted on this device” means the readable vault never sits in plain localStorage. A PIN-derived key unlocks ciphertext in the browser.
Cloud sync, when enabled, moves the encrypted blob — not your unlocked password list — so a sync target without your PIN stays opaque.
Export a backup before you change devices. Import restores the encrypted package; you unlock with the same PIN you used when you exported.
If you forget the PIN, there is no backdoor. That is the tradeoff of a vault that cannot be reset by a support inbox.
Ready to try it?
Create a free vault and keep logins, mail, and MFA together.
