Private Vault · User guide

Add a boundary for local content that requires additional protection

Unlock the safe first, then select "Move to Safe" through the "⋮" menu of the file card in the "Complete" list in the Download Center. You can also click three times in succession on the file to quickly move it in, and view and manage it in the "Safe" filter.

Estimated reading time: approximately 5 minutesLast updated: __ month __ 2026

The safe is an exclusive feature of Android and is not equivalent to cloud backup. It cannot replace device passwords, system security settings and independent file backup. This page does not use "military-grade encryption", "absolutely secure", "never lost" and other unproven expressions.

Quick conclusion

01
Android only, native only

The safe is only available in the Android version of Hams. The content is only saved locally and is not uploaded or synchronized across devices.

02
Two separate safes

Private Vaults (VIP) and security safes (SVIP) are two incompatible safes, not two levels of the same safe.

03
There are two paths each for migration and restoration.

The main entrance is the "⋮" menu of the file card: select "Move to Safe" for completed files, and select "Restore" for files in the safe; clicking on a file three times in a row is a shortcut gesture with the same effect.

04
Important content still needs to be backed up independently

Uninstalling apps, clearing data, or forgetting patterns may render the safe unrecoverable.

What is a safe used for?

The safe is used to move downloaded videos or images from the ordinary download area into encrypted storage and manage them separately from ordinary download content. The original description in the app is "Move downloaded files into the safe to reduce file and thumbnail exposure." After the files are moved in, they will be stored in the app's internal directory using block AES-256-GCM encryption. Each file uses an independent 256-bit key. The file name and the MIME type itself are also encrypted; the key is protected by Android Keystore.

Suitable scene

  • I don’t want to see it directly when browsing the Download Center.
  • Don't want files and thumbnails to appear in the system album or file manager
  • I hope to organize some local content separately
  • Want to reduce the likelihood that someone else will see these files when they randomly open Hams

should not be understood as

  • Permanent cloud backup
  • Automatic synchronization across devices
  • File recovery service
  • Security Tools to Counter Devices that Have Been Completely Controlled
  • Legally anonymous storage
  • Absolutely unhackable storage space
  • User's only copy of the file

Not Drive

Vault files are only saved in the native app's internal directory and are not uploaded, synced or restored across devices. The Extreme Vault requires server authorization for each operation, but the server only participates in key authorization and does not receive file content.

Not a replacement for device lock screen

The device itself should still have reliable lock screen and system security protection. The unlocking pattern of the safe is only an access gate and does not participate in file encryption and decryption.

Not a permanent backup

The safe file is stored in the internal directory of the app that does not participate in system backup, and the key is stored in the Android Keystore. Uninstalling apps, clearing data, or forgetting patterns may render the safe unrecoverable.

Not a copyright or access grant

Moving files to the safe does not change the user's copyright, license, or usage rights to the content.

Not an absolute safety promise

All local security capabilities have applicable scope, and the official website does not promise that they will be absolutely inaccessible or lost under any circumstances.

After moving to the safe, Hams will perform a safe cleanup of the original files, but this is only a best-effort effort within the controllability of the mobile device, and does not guarantee that system backup, cloud synchronization or third-party data recovery tools are absolutely irrecoverable.

There is no upper limit on the number of files in the safe, nor is there any upper limit on the total capacity. The only constraint is the internal storage space of the device itself.

Before using a safe, please understand these three restrictions

These three restrictions will directly affect whether you can use it and under what circumstances. They have nothing to do with the membership plan and will not disappear with version adjustments.

Safe is an Android exclusive feature

Both Private Vault and Extreme Vault are only available in the Android version of Hams and are not available on other platforms.

Private Vault does not block screenshots

Only Extreme Vault enables the system to prevent screenshots during the entire browsing process; the file list and preview interface of Private Vault can be screenshotted or recorded.

The only two features that jointly prevent screenshots are the pattern input panel, the clear reset pop-up window, and the automatic deletion setting pop-up window.

Extreme Vault is not available offline

Each operation of the Extreme Vault (except deletion) requires an authorization application from the server. If the application fails, it will be aborted. There is no offline bypass. When the device is offline or the network is restricted, files in Ultra-Secret Vault cannot be opened, exported, or restored.

The Private Vault does not require server authorization and is available offline.

Extreme Vault uses key sharding: the package key required for decryption is derived from both the local shard and the server-side shard. This means that the server holds half of the key material required for decryption, but the server never holds the file contents. Therefore, this page does not claim to be "completely client-side and the server cannot participate", nor does it mean that the server can see your files.

Complete these checks before moving into your safe

The download has actually completed

Confirm in the Download Center that the task appears as completed and that the file opens normally.

If it still shows waiting, downloading, failed or the file is unavailable, enter firstGuide to background downloads and task exceptions.

Confirm it is the correct file

Confirm whether it is the target version through thumbnail, file type, name, size and actual opened content.

Avoid accidentally moving video covers, small thumbnails, page decorations, or incorrect quality versions into the safe.

Confirm device space

When moving in, the encrypted copy will be completely written into the safe first, and then the original file will be erased. Therefore, the same content will temporarily occupy two copies of space during the process.

The safe itself has no upper limit on the number of files or capacity. The only constraint is the internal storage space of the device; however, when the remaining space is exactly equal to the file size, it may not be enough to safely complete the move.

Do not modify files simultaneously

During the migration process, do not use other file managers to move the same file, rename it, delete the original file, clear App data, force stop Hams, or uninstall the app.

Confirm current membership status

The Private Vault requires VIP or SVIP, and the Extreme Vault is only open to SVIP; the regular version does not have a safe entrance, and the safe card will not be displayed on the homepage.

If the benefits are not displayed after purchase, first restore the membership benefits in the app or enter member support, and do not purchase the same plan repeatedly.

Unlock the safe first and move it into the entrance before it will appear.

Both paths assume that the safe has been unlocked. When the safe is locked, "Move to safe" will not appear in the "⋮" menu of the file card, and triple-clicking the file will not move it in. It will only be processed as a normal preview.

You need to set an unlock pattern before using it for the first time; the Extreme Vault needs to complete a system authentication before each entry.

Follow these six steps to move files to Private Vault

  1. 01 · Found

    Find the target file in the "Completed" list of the Download Center

    There is a "All/Video/Image/Safe" filter above the completed list. First confirm the target content by name and file information in "All" or the corresponding type.

    Done flag: The file can be opened normally from Hams.

  2. 02 · Unlock

    First unlock the safe on the home safe card

    Click the safe card on the homepage three times in succession to enter; when the card is hidden, press and hold it for about 2 seconds to display it. It will automatically hide again after 30 seconds.

    • The unlock pattern is a 3×3 grid, connect at least 4 dots
    • For first time use, you need to set the pattern and enter it again to confirm.
    • Extreme Vaults require a system authentication before entry.
    • After unlocking, return to the Download Center to operate
  3. 03 · Move in

    Open the "⋮" menu of the file card and select "Move to safe"

    Open the "⋮" menu of the target file card in the "Completed" list and click "Move to Safe" with the lock icon; this menu item only appears when the safe level is unlocked and the file has not been hidden. You can also click the file three times in succession as a shortcut: the three clicks need to be completed in about 1.5 seconds; one click opens the preview, so the preview of the click will be slightly delayed to determine whether it is a three click.

    • The move in is a real move, not a copy and retention.
    • After moving in, the file disappears from the normal download area and enters the "Safe" filter.
    • In the media preview image or video playback page, triple-click the current content to move it in or out.
    • Do not interrupt the operation during the move

    The original text of the confirmation instructions in the app is "Move downloaded files to the safe to reduce exposure of files and thumbnails."

  4. 04 · Certification

    Complete system certification

    The file key of the safe is protected by Android Keystore, and access to the key requires system authentication. The Private Vault accepts strong biometrics or device lock screen credentials, and one authentication is valid for 60 seconds; the Extreme Vault only accepts strong biometrics, not device lock screen credentials, and requires re-authentication for each operation.

    Do not send unlock patterns, verification codes or biometric information to Hams support. Hams does not hold the keys that can recover the contents of your safe.

  5. 05 · Processing

    Wait for the sealing and saving to complete

    The progress prompt will display "Encrypting and archiving..." "Completing security check..." and "Removing unprotected copies..." in sequence. The app first writes the encrypted copy into the safe and verifies the ciphertext. After confirming that it is correct, the original file is safely erased. If any step fails, the entire file will be rolled back. There will be no intermediate state where the original file has been deleted but there is no content in the safe.

    • Keep Hams available
    • Do not delete original files
    • Modify files without using other apps
    • Do not force stop the app
    • Wait for the final status prompt "Moved into safe"
  6. 06 · Confirm

    Switch to the "Safe" filter and confirm that the files can be accessed normally.

    • Whether the document appears in the "Vault" filter
    • Items appear as lock placeholders instead of actual thumbnails, this is normal
    • Click to see if you can preview normally
    • Has the file disappeared from the normal download area?

    Completion mark: Files in the "Safe" filter can be previewed normally, and the file no longer appears in the normal download area.

Prompt "Moved to safe"

The file has been sealed and the original file has been erased.

Next step:Then manage the file individually in the "Safe" filter.

Prompt "Unable to move into safe"

If the move fails, the entire file will be rolled back, and the original files in the normal location will still be retained.

Next step:Do not repeat the operation immediately, first check the remaining space and network (the Extreme Vault requires server authorization).

There is no "Move to safe" in the menu, and there is no response after three clicks.

When the safe is not unlocked, "Move to Safe" will not appear in the "⋮" menu, and the three-click will be processed as a normal preview; the three-click still needs to be completed within about 1.5 seconds.

Next step:First go back to the homepage to unlock the safe, and then do it again.

In safe but can't open

It could be that the system authentication failed, the security safe is currently offline, or the file does not match the security level of the safe key available on the machine.

Next step:Go to "Exception Troubleshooting" below.

The actual order of moving is "encrypt and write to safe → verify ciphertext → erase original file", not "delete original file first and then write". If the original file fails to be erased, it will be rolled back together with the ciphertext in the safe. If the app is closed during the operation, Hams will continue to process the unfinished move, restore, and export operations the next time it is launched.

How to manage files that have been moved

The operations supported by the safe are: unlocking, viewing hidden files in the "safe" filter, previewing, restoring to the Download Center ("⋮" menu or triple-click), exporting an unprotected copy, and deleting. The app does not provide renaming or recycle bin within the safe.

unlock safe

Enter the unlocking pattern of a 3×3 grid and at least 4 points. The pattern is hashed with a random salt and SHA-256 and stored in the system's secure storage. The comparison uses constant time comparison; it is only used as an access gate and does not participate in file encryption and decryption, nor is it used to derive file keys.

Continuous input errors will trigger a lock and upgrade levels: every 3 accumulated errors, the level will be upgraded, starting from 1 minute and capped for a maximum of 24 hours. There is no mechanism to "automatically destroy the safe after a certain number of errors"; the count is only cleared when the verification is successful or the pattern is reset.

View files

Switch to the "Safe" filter above the completed list in the Download Center to view only hidden files. This filter is conditionally displayed and requires that the safe of the corresponding level has been unlocked and contains contents.

Hidden entries do not display real thumbnails, only lock-shaped placeholders; the titles of Extreme Vault entries will be replaced with "Private Files", and entries that have been exported will be marked with "Exported Unprotected Copy."

Preview file

Click on an entry to preview it. The preview is streamed and decrypted on demand, and the plain text is not written to the normal disk location; closing the preview will clear the cache, and there is a survival limit (2 minutes for Private Vaults, 60 seconds for Extreme Vaults).

Whether it can be played or displayed normally will still be affected by file integrity, format and device compatibility. The safe is not a universal player.

Restore to Download Center

Open the "⋮" menu of the hidden file in the "Safe" filter and select Restore, or click the file three times in a row. After recovery, the file will reappear in the Download Center. The original description in the app is "After restoration, this file will be displayed in the Download Center again."

After the video is restored, it will re-enter the thumbnail generation process, so the thumbnails may not appear until later.

Export an unprotected copy

A copy can be exported to the public download directory in the hidden file menu, and the encrypted original in the safe is retained. The original text of the confirmation pop-up window is "The exported copy will no longer be protected by the safe, please keep it properly."

The exported copy is a clear text file, has left the protection scope of the safe, and will appear in the system like an ordinary downloaded file.

Auto lock

Both safes will be automatically locked after leaving the app, leaving the page where the safe is located, or after an idle timeout. They will also be locked immediately when the membership level changes. The idle timeout is 5 minutes for Private Vaults and 3 minutes for Extreme Vaults.

What's really unique about Extreme Vaults is "system authentication required before each entry" and shorter idle lock times.

Hams Private Vault interface

Private Vaults and Extreme Vaults are two separate safes

They are not two security levels of the same safe, but two side-by-side safes: using different Android Keystore keys, different storage directories, and are incompatible with each other. Sessions unlocked with Private Vault can never open files in Ultra-Secret Vault.

Private Vault (marked "VIP")

The original subtitle in the app: "Move downloaded files into the safe to reduce exposure of files and thumbnails."

  • Available for both VIP and SVIP
  • Pattern unlocking; key operations require system authentication
  • Accept strong biometric or device lock screen credentials, valid for 60 seconds once authenticated
  • Automatically lock after 5 minutes of idle time
  • Available offline
  • Browsing interface does not prevent screenshots

Extreme Vault (marked "SVIP · Ultra-Secret")

Original subtitle in the app: "Device authentication·Automatically locked after leaving"

  • Only available for SVIP
  • Pattern unlocking; system authentication is required before each entry
  • Only strong biometrics are accepted, device lock screen credentials are not accepted, and each operation requires re-authentication.
  • Automatically lock after 3 minutes of idle time
  • Each operation requires server authorization and is not available offline.
  • Enable system anti-screenshot throughout the process
  • Optional enable automatic deletion (self-destruction)

Files in both files are encrypted in the same way: Blocked AES-256-GCM with a separate 256-bit key per file, the file name is encrypted along with the MIME type, and the key is protected by Android Keystore. The difference between the two is not in the encryption algorithm, but in the threshold for accessing the key (authentication strength, authentication validity period, whether server authorization is required), anti-screenshot range, automatic locking duration and whether automatic deletion is provided. There is no upper limit on the number of files or the size of either file.

Regular version

The regular version does not provide any safe capabilities, the safe card will not be displayed on the homepage, and the "safe" filter will not appear in the Download Center.

VIP

VIPs have access to a Private Vault. Two other benefits of VIP are freedom from regular app ads and longer browsing history retention (30 days / 300 items).

VIPs are only exempt from regular app ads; rewarded ads used to preview SVIP features may still appear. Capabilities such as quality, concurrency, and batch downloads belong to SVIP.

SVIP

SVIP can use an Extreme Vault, and also includes VIP rights and capabilities such as high-speed downloads, original quality, and batch downloads of list pages.

The safe is not unlocked after purchase

Sequence: Confirm to use the correct Google Play account → Confirm network connection → Restore member rights in the app → Wait for member status to be synchronized → Re-enter the safe → Contact support if the issue is still not resolved.

If payment has been made but the benefits are not displayed, restore membership benefits first or contact support. Do not purchase the same plan again.

Document processing after membership expiration or downgrade

The files in the safe will not be deleted when the membership expires or is downgraded. The files remain encrypted and remain in place, but the access is temporarily lost: when downgrading to the normal version, the safe session is immediately locked and the safe card is no longer displayed on the homepage; when SVIP is downgraded to VIP, the Private Vault can still be used, and the files in the Extreme Vault are no longer visible and cannot be opened.

Paid benefits will stop when the subscription expires, and there is no expiration grace period; only when the membership service is temporarily unavailable, up to 30 minutes of offline fault tolerance will be reserved for users under automatic renewal.

One-time recovery after SVIP downgrade

After the SVIP is reduced to VIP, the app will provide a one-time recovery entrance, which can "convert the files in the Extreme Vault to VIP protection" or "move out of the safe." Files that are moved are no longer encrypted or protected.

The recovery window is issued by the server and can only be started once. This page does not write the specific number of days.

Before performing these operations, deal with important documents in the safe first

Uninstall Hams

Uninstalling deletes the files in the safe and cannot be recovered. The encrypted files are saved in the app's internal directory that is cleared when uninstalled, and the keys required for decryption are saved in the Android Keystore and are also destroyed when uninstalled.

Hams does not host any keys outside of the device that can recover the contents of your safe.

Clear app data

Clearing app data has the same result as uninstalling: the files in the safe cannot be recovered.

Before entering the safe for the first time, the app will prompt: "Hidden files will be moved from normal storage to the encrypted safe. Uninstalling the app, clearing data, or forgetting the pattern may cause the safe to be unrecoverable."

Forgot to unlock pattern

There is no way to decrypt and retrieve it. The only way out is to "empty the safe and reset the pattern", which will permanently delete the hidden files in the safe and clear the current pattern, after which a new pattern will need to be set again.

Unprotected copies that have been exported will remain on the device and will not be affected by this clearing.

Re-enter biometrics

After fingerprints or faces are re-entered into the system, the key to the Extreme Vault will become permanently invalid and the files in it can no longer be opened. The original text of the prompt in the app is "The device authentication has been changed and the Extreme Vault key is no longer valid."

The key to the Private Vault will not be invalidated by re-entering biometrics.

Replace device

Vault does not provide synchronization or migration capabilities. The file key is bound to the native Android Keystore, and the safe contents on the old device cannot be decrypted after switching to a new device.

Before changing devices, please restore the content you need to keep to the Download Center, or export an unprotected copy and back it up yourself.

Delete Hams account

Hams does not have a traditional account that requires registration and login, and there is no entrance to log out. The safe is not bound to the account. The "Deregister Anonymous ID" in the app only deletes the anonymous ID and does not delete the safe file on the device.

Deleting an account and clearing the safe file on the device are two different things, so please handle them separately. SeeAccount and data deletion.

Before uninstalling Hams, clearing App data, re-entering biometrics, or changing devices, please make sure that important local files in the safe have been restored to the Download Center or exported as a backup according to your needs. Loss caused by these operations cannot be recovered by contacting support.

Deleting files from the safe is irreversible

Please distinguish four different operations first: Preview is only a temporary decryption for viewing; restoring to the Download Center moves the file back to the normal download area; exporting an unprotected copy will retain the encrypted original in the safe; deletion will erase the file itself in the safe.

  • Deleting safe files requires system authentication first, and this is true for both files.
  • Hams does not have a recycle bin, and safe files cannot be restored through the app after being deleted.
  • When deleting, the ciphertext in the safe will be overwritten and erased; this is a best-effort cleanup within the controllable scope of the mobile device, and there is no guarantee that system backup, cloud synchronization or third-party data recovery tools will never be recoverable.
  • Unprotected copies that have been exported will not be cleared when the safe is deleted and need to be processed separately.

Batch delete

  • Multiple safe entries can be selected and deleted at once
  • First pop up a confirmation, and then use a system authentication to cover the entire batch.
  • Safe entries are processed serially one by one, not concurrently
  • Batch deletion progress only counts ordinary files, and safe entries have separate processing progress prompts.

File recovery boundaries

  • There is no recycle bin and cannot be restored through Hams after deletion.
  • Hams does not hold the key to recover the contents of the user's safe
  • Hams support cannot remotely recover deleted local private files from user device

The Extreme Vault can turn on automatic deletion (self-destruction)

This is an optional feature unique to Ultra Security Safes and is turned off by default. After turning it on, if a strict biometric verification of the Extreme Vault is not completed within the set time, the data in the safe will be automatically deleted.

  • It can be set from 1 to 3650 days, and the confirmation phrase needs to be entered verbatim when turned on.
  • The countdown will only reset after passing strict biometric verification via the Extreme Vault, not simply opening the app.
  • At the same time, the system time and device running time are verified. If it is detected that the clock is set back, it is deemed to have expired.
  • When triggered, the entire safe will be emptied and the unlocking pattern will be cleared, while the switch will be automatically turned off.
  • The original text in the app states: "If the device is lost, damaged, restored to factory settings, or the app is uninstalled, we cannot help you recover the data."

Safe not working as expected

There is no safe card on the homepage

The regular version does not have a safe entrance; the card may also be hidden and needs to be pressed and held for about 2 seconds to display. It will automatically hide again after 30 seconds.

Next step:First confirm the membership level, and then try to long press to display the entrance.

The file was not moved to the safe

When the safe is not unlocked, "Move to Safe" will not appear in the "⋮" menu, and the three clicks will only be processed as a normal preview; the three clicks need to be completed continuously within about 1.5 seconds.

Next step:Unlock the safe first, then return to the "Completed" list and use the "⋮" menu or triple-click to repeat the operation.

Pattern is locked

Every 3 cumulative incorrect entries will trigger a lock and escalate gradually, starting from 1 minute and lasting up to 24 hours. The count will only be cleared when the verification is successful or the pattern is reset.

Next step:Wait for the lock to end before typing again. Do not make the waiting time longer by continuous trial and error.

Prompt "Unable to move into safe"

If the move fails, the entire file will be rolled back, and the original file in the normal location will still be available.

Next step:Check the remaining space and network and try again; if the original file is abnormal, stop the operation and contact support.

System authentication cannot be completed

Extreme Vault only accepts strong biometrics, not lock screen PINs, passwords or patterns; the device cannot be entered without available biometrics. After re-entering your fingerprint or face, the key to the Extreme Vault will become permanently invalid.

Next step:Check your system biometric settings; Private Vault can use device lock screen credentials instead.

Unable to open files in Extreme Vault

Every operation of the Extreme Vault requires server authorization. It will fail directly when offline or the network is restricted, and there is no offline bypass.

Next step:Switch to an available network and try again; Private Vault is not affected by this.

File exists but cannot be opened

The file may be incomplete, in an incompatible format, or the file may not match the security level of the safe key available on the machine (for example, viewing an Extreme Vault file in a VIP session).

Next step:Confirm current membership status; enter for general file questionsDownload Center and File Management Guide.

Unable to access after membership expires

The file will not be deleted, only access will be lost. Downgrade your SVIP to VIP to use a one-time recovery option to work with files in your Extreme Vault.

Next step:Do not attempt to recover files by making repeated purchases, clearing data, or uninstalling the app; go to Member Support.

  • Has the file been downloaded completely?
    • No → Process the download task first
    • Already → Continue to next item
  • Is the safe unlocked?
    • No → First, triple-click on the safe card on the homepage and enter the pattern
    • Already → Continue to next item
  • Is it prompted "Moved to the safe" after the operation?
    • None → Check whether there is "Move to safe", three-click rhythm, remaining space and network in the "⋮" menu
    • Already → Continue to next item
  • Can documents be found in the "Safe" filter?
    • Yes → Click to try preview
    • Unable → Confirm the membership level and safe level, and then check the general download area
  • File cannot be previewed
    • Check system authentication, network (high-security safe) and file integrity

After completing the troubleshooting, the file still cannot be accessed

Suggested information
  • At which step does the problem occur?

  • Is it a Private Vault or an Extreme Vault?

  • Is the file still available in the general download area?

  • Whether the file was ever opened normally

  • Prompt text displayed during operation

  • Whether to display corresponding entries in the "Safe" filter

  • Is the membership level displayed as VIP or SVIP?

  • Have you cleared the app data/uninstalled or reinstalled it?

  • Have you changed your device or re-entered your fingerprints and face?

  • Hams version/Android version/Device model

  • Screenshot of blocked status

Do not provide
  • safe unlock pattern
  • Device lock screen PIN or password
  • Verification code
  • biometric data
  • Private video or image original file
  • Unobstructed safe contents
  • Payment password
  • full file name
  • Browsing history not relevant to the question

Screenshots may contain private thumbnails or file names. Please block any content that is not relevant to troubleshooting before sending. To enter the support center from this page, only topic=files_and_vault and source=guide_private_vault are pre-filled. The URL does not carry file name, path, thumbnail, number of safes, email, member user ID or authentication information.

Go to support center Contact hamsbrowser@gmail.com →

Separately manage local content that requires additional protection

Download Hams on your Android device. After completing the file download, use the "⋮" menu of the file card or the three-click gesture in the Download Center to move the content into the safe and encrypt it and save it locally.

Scan the QR code to view Hams on Google Play for Android

Scan the QR code to go to Google Play

Download on Google Play