Encrypted atlas · Android

An ordinary inventory shows a thief where your valuables are.

TimeVault Atlas encrypts the place as well. What you own, where it is, what it looks like — all of it stays on this one device, behind a key that is never created anywhere else.

What it is for

For anything whose location deserves as much protection as the thing itself.

Valuables and hiding places

Jewellery, coins, watches, heirlooms — with a photo, a note, and the place they actually are. Including the place you would not tell anyone.

Documents and keys

Where the deed is, where the spare key hangs, which combination opens which lock.

What comes after you

A record that matters when it has to — as long as it stays in your hands and not in a provider's.

No account. No registration. No server. In normal use the app sends nothing — there is no other end for it to send to.

How the key is made

Encryption is not a label. Here is what actually happens, so you can check it rather than believe it.

Argon2id Cryptography

The key is derived on the device from your password with a memory-hard function. It stays expensive even for someone attacking it in parallel on rented graphics cards.

Bound to a place Cryptography

A vault can be bound to one place. The key is then derived from your factors and from that place — away from it, the key does not exist. There is nothing for a modified app or a spoofed GPS to bypass. No coordinates are written into the file.

Key files instead of a password

Any files can form the key instead of a password — one at a time, in a set order, or as a group of which only part needs to survive.

Two equal vaults

One file can hold two vaults with separate passwords. From the outside the file looks the same whether you use one or two.

The full security model — limits included — is on its own page.

What this app does not do

The uncomfortable part most product pages leave out. It belongs here, because a security promise is worth only as much as what is said alongside it.

Not a password manager

No logins, no autofill, no one-time codes. An entry has a title, a place, a note and photos — nothing more.

No backup on our side

A forgotten password means the data is gone. There is no recovery by us, because that would require a back door.

A place is not a password

A place carries little entropy. Someone who knows which town you live in has already narrowed the search a great deal. Place binding is an additional factor to a strong password, never a replacement.

No defence against a compromised phone

No app can help against malware with deep privileges on an unlocked device. Encryption protects a file, not a running system.

Three locks, and they combine

A vault decides who gets to look. Two further locks come on top — and neither of them is a question the app asks.

Time

Time capsules

Seal a note to a day in the future — it does not open before then. Not for you either, and not with a clock set forward. The key is released by two independent beacons when the moment comes: the public randomness network drand and a key server at beattime.live.

Sealing works offline. Only opening needs a connection.

Place

Place-bound notes

A note that opens only where you wrote it. Its key is derived from the grid cell you were standing in — anywhere else it does not exist. Nothing about the place is stored: no coordinates, no cell, no radius.

Both at once is possible: the day and the place.

Evidence

Time certificates, collected

For any photo taken inside the app you can request a proof of time — only the checksum leaves the device, never the picture. Every proof appears in its own register, next to the photo and the entry it belongs to.

Search by entry, file name or checksum.

Getting it

Through Google Play only. This site deliberately offers no APK download: an installer from a website is exactly how people end up with a forged version.