OneVault is a local-first Android password manager. Your vault is stored only on your device, encrypted at rest, and never leaves the phone unless you explicitly export or back it up. There is no OneVault account and no server.
- Encrypted at rest — an SQLCipher database whose passphrase lives in the Android Keystore, plus per-item AES-256-GCM keyed by a PBKDF2-stretched (210k) derivation of your master password, with a post-quantum KEM (ML-KEM-768 via BouncyCastle) layer on v3 payloads.
- Local-first — no analytics, no telemetry. The
INTERNETpermission is used only by two opt-in features: crash reporting (off by default) and optional encrypted cloud backup. - Autofill + hover — an Android autofill service (ranked by requesting domain) and an optional floating quick-access bubble.
- Screenshot-protected (
FLAG_SECURE), auto-locking, root-aware.
OneVault protects against device theft while locked and offline brute-force of the vault
file (PBKDF2 stretching + Keystore-bound SQLCipher key + ML-KEM/AES payloads). It deliberately does
not defend against a compromised OS/rooted device (a warning is shown on unlock), an
"evil-maid" attacker with the vault already unlocked in front of them, or a forgotten master
password — the master password is the only key, it is never stored or transmitted, and there is
no recovery or backdoor. Losing it means the data is gone by design; keep an encrypted export.
A more detailed analysis lives in docs/THREAT-MODEL.md, and the note that
the "quantum" layer is a defense-in-depth addition (backup confidentiality does not rely on it).
Prerequisites: JDK 17, Android SDK (platform 36, build-tools 36), a local.properties with
sdk.dir. The Gradle wrapper is pinned (AGP 9.1.1 needs Gradle ≥ 9.3.1).
# Debug APK
JAVA_HOME=/opt/homebrew/opt/openjdk@17 ./gradlew :app:assembleDebug --no-configuration-cache
# Unit tests (run separately — assembleDebug rejects a --tests flag)
JAVA_HOME=/opt/homebrew/opt/openjdk@17 ./gradlew :app:testDebugUnitTest --no-configuration-cacheDebug APK: app/build/outputs/apk/debug/app-debug.apk.
See docs/RELEASE.md for the full runbook (you generate the signing key; we
never store it), R8 notes, and the Play data-safety answers. Short version:
# after creating keystore.properties (see docs/RELEASE.md):
JAVA_HOME=/opt/homebrew/opt/openjdk@17 ./gradlew :app:assembleRelease --no-configuration-cache
JAVA_HOME=/opt/homebrew/opt/openjdk@17 ./gradlew :app:bundleRelease --no-configuration-cacheTo install OneVault from the APK: on your Android phone, open the APK file. Android will ask to allow installing from this source — enable it for your browser/file manager, then tap Install. OneVault is signed with a developer key, so Play Protect may show a one-time warning; choose "Install anyway". On first launch you'll create a master password — there is no recovery if you forget it, so store it safely and export an encrypted backup.
See docs/PRIVACY.md. In short: your data stays on your device; we collect
nothing; uninstall or Settings → Erase all data removes everything.