Overview
NightKeep keeps one local vault per installation and has no NightKeep account, developer cloud, advertising, or analytics service in the reviewed implementation. It encrypts current vault content and metadata, but legacy formats, temporary plaintext, exports, backups, previews, and operating-system storage behavior create important limits described below. Brent Gaddis provides NightKeep. It is a general-audience app and is not directed to children under 13. Privacy questions can be sent through the site form or to support@brentgaddis.com.
Vault content and metadata
NightKeep can store arbitrary imported files plus filenames, folders, tags, notes, media types, hashes, sizes, favorite state, view/export/trash activity, and related vault metadata. Current NKV2 content chunks and the current index use AES-GCM with one vault key. Legacy whole-file objects or plaintext metadata can remain during migration. The legacy password derivation used in older material is not represented as a modern, independently audited password-hardening design. These safeguards reduce risk but do not make the vault unbreakable or guarantee secrecy.
Keys, biometrics, and recovery
The master vault key is stored or wrapped using local Keychain and password/recovery flows. If you explicitly enable biometric unlock, NightKeep uses Apple device authentication and a ThisDeviceOnly/current-biometric-set Keychain item; it does not receive biometric templates. A recovery key or recovery drive wraps the same vault key. Anyone with the password, unlocked device, or usable recovery material can gain access. Brent does not hold a recovery copy and cannot restore a lost password or key.
Imports, previews, exports, and other copies
Import normally keeps the source original. Optional Remove Originals verifies the matching import before requesting source deletion. While the vault is unlocked, plaintext previews or temporary exports can exist; NightKeep clears its preview cache on lock or launch, but operating-system or framework caches can persist. Decrypted exports, shares, backups, screenshots, recovery artifacts, and recipient copies are outside the vault and remain until deleted at each destination. On supported mobile builds, the system photo picker supplies only items you select.
Trash, erasure, and legacy data
Vault Trash keeps encrypted recoverable items until permanent deletion or Empty Trash. Erase App and Start Over clears current app-vault data when the recovery flow permits it, but it does not promise forensic erasure from flash storage, APFS snapshots, backups, caches, exported copies, or recovery media. The reviewed implementation manages one current vault; old DecoyVault data from previous builds is preserved untouched and is not erased by current-vault controls. Removing the app/container clears current local app data but not external copies.
Local processing and service boundaries
No NightKeep account, CloudKit sync, developer backend, advertising SDK, or third-party analytics path was found in the reviewed implementation. Apple still processes App Store distribution, purchase, operating-system, Keychain, biometric, file-picker, backup, and device services under its own terms. A future version that adds a network or cloud service must update this policy before that processing begins.
Security limits and responsible use
NightKeep is a personal organization and access-control tool, not a guarantee against compromise, data loss, legal process, malware, a person with device access, or failures in hardware, software, backups, or recovery media. Keep independent backups of irreplaceable files, store recovery material separately, use a strong unique password, lock the vault before leaving the device, and report a suspected vulnerability without sending confidential vault contents.
Website, support, privacy requests, children, and policy changes
NightKeep’s app-data practices are described above and are separate from its pages on brentgaddis.com. Those pages use first-party aggregate analytics operated through Cloudflare. The site counts page views and allowlisted actions and keeps coarse source, country, device, browser, operating-system, engagement, performance, and reliability totals. It does not store raw analytics events, visitor or session identities, raw or hashed IP addresses, cookie or local-storage visitor IDs, full user agents, full referrers or URLs, form contents, arbitrary text, or a person’s raw click history. Country and source cells below five are suppressed, and aggregates are retained for up to 24 months. Cloudflare still processes request and network metadata to deliver and protect the site. If you contact support, the website, Cloudflare Turnstile, Cloudflare’s delivery services, and the email provider process the app selection, request type, reply email, subject, message, security signals, and delivery metadata you submit. Form contents are delivered to Brent’s monitored mailbox and are not written to website analytics or a website message database. Support email is retained only as reasonably needed to respond, maintain security and support records, resolve disputes, and meet legal obligations, then deleted or de-identified when no longer needed. Do not submit passwords, recovery keys, government identifiers, payment-card data, or unrelated sensitive content. The website does not use cross-site behavioral advertising or sell or share personal information for that purpose, so browser Do Not Track and Global Privacy Control signals do not change its behavior. NightKeep is offered to a general audience and is not directed to children under 13. If Brent learns that a child supplied personal information through a developer-controlled channel without required consent, he will take reasonable steps to delete it. Depending on where you live, applicable law may provide access, correction, deletion, or appeal rights; use the privacy-request form or email support@brentgaddis.com. Identity may be verified, and requests will be handled as applicable law requires. Material changes will be posted on this page with a new effective date, with additional notice or consent when required.
Questions
Contact Brent Gaddis with privacy questions about NightKeep.