Want to try it? My vault is an app for DevQuake members. Create an account or sign in, then subscribe to the app.
My vault · User manual
How to use your vault
My vault keeps private information encrypted. Each entry opens only with its vault key and the answers to three questions you choose. It can stay yours alone, or reach people you trust when you have not used DevQuake for a while.
1. Getting started
- Sign in on devquake.com (or create an account and confirm your email).
- Open Your account → Available projects and Subscribe to “My vault”.
- Open the app and choose New entry.
2. What an entry can hold
Every entry has a note, secret fields (a label and a hidden value) and files, all encrypted together. For example:
- Logins and passwords: online banking, email, the password manager’s master password hint.
- Crypto and recovery: wallet seed phrases, two-factor recovery codes.
- Bank and finance: account and card details, PINs, safe or alarm codes, insurance and pension policy numbers.
- Identity and documents: ID and passport numbers, scans of a will, deeds or contracts (files).
- Wishes and instructions: a letter, where important things are, who to call first (lawyer, notary, accountant).
- Anything else private: a diary page, health information, photos or a short voice message.
The title and category are not encrypted: they appear in lists and in the email to recipients. Keep the title general (“For the family”, not the PIN).
Or start from a suggested type: a form with the right fields, encrypted like everything else in the entry:
- Car: make, model, plate, VIN; RCA, ITP, rovinietă and CASCO with their dates; a service log and a fuel or charging log, with the costs per km and the consumption worked out.
- Papers: ID cards, passports, driving licences, insurance, warranties, subscriptions and contracts, with their numbers, expiry and “cancel before” dates and what renewals cost in a year.
- Health: blood type, allergies, conditions, doctor and emergency contact; medicines, measurements (blood pressure, weight, blood sugar…), appointments and vaccinations.
When the entry is open, Coming up lists its dates (expiring papers, ITP, refills, appointments). The vault cannot email you about them, because it never reads what is inside.
3. Entries only for you
An entry without recipients is private forever: nobody is ever sent its key, and the server does not even keep it. Good uses:
- Your own backup of recovery codes and seed phrases, apart from your devices.
- Things you do not want in an ordinary notes app: health notes, a diary, a secret you keep.
- Sensitive documents you keep for yourself: contracts in negotiation, scans of papers.
- A “letter to my future self”, or drafts you may share later: you can add recipients at any time.
4. Create an entry
- Content: a title, a category, and the note, secret fields and files.
- Questions: three questions and their right answers (see below).
- Vault key: the app makes a random key (52 characters). Copy or download it and keep it safe; tick that you saved it.
- Recipients (optional): people who receive the key if you become inactive.
- Encrypt and save: the entry is encrypted on your device and only then uploaded.
5. The three questions
- Each question has a type: a date, text, a number, one choice or several choices (you write the choices, one per line).
- You enter the right answer; it is never stored in readable form, only as a check.
- Text answers ignore capitals, accents and extra spaces (“Érdi Anna” = “erdi anna”); numbers ignore leading zeros.
- The questions are shown to whoever opens the entry, so choose ones only the right people can answer.
Make at least one answer hard to guess, like a serial number or a private memory; a birth date alone is easy to find out.
6. The vault key
The vault key is shown once, when you create the entry. The entry opens only with the key and the three answers.
Nobody can recover a lost key, DevQuake included. Keep it in a password manager or on paper in a safe place. Dashes, spaces and small letters do not matter when you type it.
7. Recipients and the release
- Recipients are people from your DevQuake referrals (people you invited or who invited you). They need a DevQuake account, not the app.
- Choose after how many days or months without activity the key is sent. Activity is any use of DevQuake: signing in, any page or app.
- Optionally, a day before which nothing is sent even if you are inactive.
- A few days before the release you get a warning email; signing in or opening any DevQuake page postpones it.
- At the release, each recipient gets an email with the vault key and a link. They open the entry with the key and the answers to your three questions.
To change recipients later, open the entry (or type its key) on its page and save the recipients again. After the release they can no longer change.
8. Opening an entry, and the tries
- Type the vault key and answer the three questions; the content is decrypted on your device.
- Every try is recorded: who, when, and for wrong ones the answers given.
- After 3 wrong tries the entry is locked for 36 hours and you get an email. On the entry’s page you see who tried and what they answered, and you can unlock it earlier.
- As the owner you can also change the content; it is encrypted again with the same key and answers.
9. How it is protected
- The content is encrypted in your browser (AES-256) with a key made from the vault key and the three answers. The server stores only the encrypted content.
- The answers are stored only as a slow check value, and the key only as a check value.
- For entries with recipients, the server also keeps the vault key, sealed with its own secret key, because it must be able to send it without you. Someone with full access to the server could therefore try to guess the answers: this is why at least one answer should be hard to guess.
- Private entries (no recipients) keep no key on the server at all.
10. Your data
When you delete your DevQuake account or unsubscribe from the app, your entries, their tries and your place as a recipient on others’ entries are deleted for good.
Questions or ideas? Write to contact@devquake.com.