Security and privacy

What the app protects, and what it does not

Clear limits matter as much as strong encryption.

Encryption format

Lock My Folders asks the macOS hdiutil system tool to create an APFS sparsebundle with AES-256 encryption. The encrypted format and passphrase handling are provided by macOS rather than a custom cryptographic implementation.

Local processing

Core locking, unlocking, verification, and relocking happen on your Mac. No account or app-operated server is required. The app includes no advertising, tracking, remote analytics, or crash-reporting SDK.

Passphrase handling

The passphrase is supplied to the macOS disk-image tool for the current operation. The app does not save it in its managed-vault list or local preferences. A forgotten passphrase cannot be recovered by the app or support.

Copy verification

Before the original can be moved to Trash, the app verifies the copied hierarchy and compares regular files byte-for-byte. Filesystem-created APFS root metadata is excluded only when the source did not contain an item with the same root name.

Threat-model limits

An unlocked vault is available to your logged-in Mac session and to software running with sufficient access. Encryption does not protect files while the vault is mounted, from malware controlling your account, or from someone who knows the passphrase.

Not a backup

A vault can still be lost through disk failure, accidental deletion, corruption, or loss of the passphrase. Keep versioned backups of both important source data and the final locked sparsebundle.