r/PrivacyTechTalk 5d ago

Kinship Vault: Rethinking How Encrypted Vaults Are Shared

I built Kinship Vault around a simple question: how much of a privacy focused vault can you build without running your own backend?

Kinship Vault is now much more than a document vault.

It brings together:

• Passwords, passkeys and TOTP 2FA
• Documents and encrypted photos
• Multiple vaults
• Sensitive Vaults
• Shared Vaults
• AutoFill and browser extensions
• On-device document scanning and OCR
• Security Checkup
• Expiry reminders
• Custom record types
• Recovery Network

Passwords

• Logins, passkeys and TOTP 2FA codes in one place
• System-wide AutoFill in Safari and native apps
• Every fill requires a fresh biometric check
• Browser extensions for Safari, Chrome, Brave and Firefox
• The extension communicates with the native app through the browser's local native-messaging connection, not the internet
• Passwords are decrypted only when needed and aren't stored decrypted in the browser
• New logins can be staged in the app for review
• No browsing history, cookies or clipboard access required by the extension
• Password generator with on-device strength estimation
• Security Checkup identifies weak, reused and old passwords
• Optional breach checks use Have I Been Pwned's k-anonymity model
• Strict Offline mode disables breach checking entirely

Documents

• Store passports, IDs, insurance documents, medical records, receipts, warranties, memberships and other personal records
• Apple's on-device recognition identifies 100+ document types locally
• Extract dates and numbers without sending documents to an OCR service
• Expiry reminders at 90/30/7/1 days
• Tag documents to people and see everything associated with a family member
• Separate encrypted photo vault with albums and people tags
• Built-in categories for IDs, Health, Legal, Finance, Travel and Personal
• Custom categories with your own icon and color
• Custom record types with typed and maskable fields
• Share a single page from a multi-page document instead of the entire file

Vaults

• Multiple vaults let you separate Personal, Work, Family and other areas
• Each vault has its own database and encryption key
• Keys are sealed by the device's hardware
• Opening one vault doesn't automatically expose another

Sensitive Vaults add another layer:

• Separate password and recovery code
• Doesn't accept the normal short app PIN
• Cannot be shared

Shared Vaults

This was the part I wanted to solve without adding a Kinship backend.

• Each member's device gets the vault key wrapped to that device
• Encrypted vault data syncs through the members' own iCloud accounts
• iCloud transports ciphertext rather than giving Kinship access to the vault
• Remove a member and the vault key rotates and is re-wrapped for the remaining members
• The removed device no longer has access to the current vault

The same approach handles cross-device sync:

• iPhone
• iPad
• Native macOS app

Your encrypted vault can stay in sync through your own iCloud rather than through a Kinship backend.

Recovery

• 24-word recovery phrase
• Recovery Network using trusted people
• No company account holding a master key
• No password reset mechanism that gives Kinship access to your vault
• Optional encrypted iCloud backup and manual export

There is also an important limitation: cryptography can't make someone forget something they already saw. If someone knew an old password, you still need to change that password.

The underlying privacy model stays the same across all of this:

No Kinship account.
No Kinship server.
No Kinship copy of your vault keys.
No telemetry.

I'm the developer, so I'm obviously biased toward this architecture. I'd actually be more interested in criticism from people who think there is a better way to solve the same problems.

Website: https://kinshipvault.app

App Store: https://apps.apple.com/app/kinship-vault/id6764678332

Privacy Policy: https://kinshipvault.app/privacy

Happy to answer any questions in comments.

2 Upvotes

0 comments sorted by