MystSafe overview

MystSafe Support

Find an answer. Get help when you need it.

Search common questions about your vault, trusted devices, synchronization, Family Shared, Share Once, subscriptions, and privacy.

Private support search

Search answers already on this page.

Your search stays in this browser. It is not sent to MystSafe or saved in browser storage.

Keep sensitive information out of search. Never enter passwords, vault exports, private keys, recovery information, live QR codes, or complete Share Once or pairing links.

24 answers available.

Browse by topic

Narrow the knowledge base.

Choose a topic or leave All topics selected. Topic filters and search work together.

Knowledge base

MystSafe answers

Vault and devices

What should I do if a trusted device is lost, sold, or replaced?

If you still have the device, first confirm another trusted device has current data, remove the old device from that other device’s Trusted Devices list, and then use Delete Local Vault on the old device before handing it over. If it is missing, remove it from another trusted device and run Sync until the removal completes; also use Apple’s lost-device controls and review access at the vault’s Google Drive or GitHub provider. Removal cannot remotely erase an encrypted vault already stored on that device.

Link to this answer

Vault and devices

Can MystSafe recover my vault or reset a master password?

MystSafe has no vault master password or account password for us to reset. Recovery is device-based: another Active trusted device can pair a replacement, and a usable vault export can be imported. A Google or GitHub login and Restore Purchases do not restore vault contents or keys; without another trusted device or a usable export, MystSafe cannot recover decrypted contents.

Link to this answer

Vault and devices

How do I add another iPhone, iPad, or Mac?

On an existing unlocked device, open Trusted Devices and choose Add Device. On the new installation, choose Join an existing vault, then follow the prompts to show or scan the short-lived QR code. Compare the five words on both devices and continue only when they match exactly; keep both apps open and online until activation and the initial synchronization finish.

Link to this answer

Vault and devices

What should I check if Face ID, Touch ID, or local authentication does not unlock MystSafe?

Confirm that an iPhone or iPad passcode, or a macOS account password, is enabled and working, then bring MystSafe to the foreground and retry without dismissing the system prompt. Restart the device if Apple reports that authentication is temporarily unavailable. Do not delete the vault as a first troubleshooting step; if the problem continues, preserve another trusted copy and send support the app version and exact non-sensitive error text.

Link to this answer

Vault and devices

What is the difference between deleting a local vault and erasing synchronized vault data?

Delete Local Vault guarantees deletion of the encrypted vault and protected keys on the current device. When another Active device exists, MystSafe makes a bounded attempt to retire the deleting device through the selected provider, but an offline or failed provider can leave remote encrypted objects or an Active-looking device entry. Local deletion does not erase another device’s vault and does not guarantee physical removal from provider history, so verify trusted-device removal and synchronization separately before treating remote data as retired.

Link to this answer

Sync and providers

Why is my vault not updating, and what should I check after provider authorization fails?

On the receiving device, unlock MystSafe and run Sync; on iPhone or iPad you can also pull down on the Secrets page. Confirm network access and that the vault’s selected Google Drive or GitHub connection is available. If setup or reconnection authorization fails, retry with the intended provider account and complete the requested access flow; do not delete provider files or the local vault. If it still fails, note the provider, platform, app version, and exact non-sensitive error for support.

Link to this answer

Sync and providers

Can one vault use Google Drive and GitHub at the same time?

No. A connected vault identity is bound to exactly one synchronization provider: Google Drive or GitHub. MystSafe does not combine them, fall back from one to the other, or migrate the same identity between providers. Disconnecting retains the contents under a fresh local-only identity that may later configure either provider from scratch; that is not a provider migration.

Link to this answer

Sync and providers

Does MystSafe store my synchronized vault on a MystSafe server?

No. Each trusted device keeps an encrypted local vault, and encrypted synchronization objects use the provider you selected: Google Drive app data or a dedicated private GitHub repository. MystSafe’s separate Pairing Service can carry short-lived opaque encrypted rendezvous messages for one pairing direction, but it is not a normal vault or synchronization server.

Link to this answer

Pairing

What should I do if a pairing session expires?

Leave the expired flow on both devices and start Add Device again to create a fresh session and QR code. Do not reuse a saved image or copied value from the old session. MystSafe supports one active pairing session at a time; if the trusted device reports cleanup still pending, keep it online and let that cleanup finish before retrying.

Link to this answer

Pairing

What information should never be sent in a support ticket about pairing?

Never send a live QR code, its full decoded value, a complete pairing link, provider credential or token, private key, vault export, or recovery information. Do not send active comparison words while a session is in progress. Support can work from the device roles, pairing direction, provider, app versions, approximate time, and exact non-sensitive error text.

Link to this answer

Family Shared

Can the Family Plan owner open a member’s private vault?

No. Every participant has an independent personal vault, keys, trusted devices, and synchronization state. The owner cannot decrypt, search, edit, recover, or enumerate a member’s private vault, and members cannot open the owner’s or one another’s private vaults. Only secrets deliberately placed in Family Shared cross that boundary.

Link to this answer

Family Shared

Who can see Family Shared secrets, and what does a new member receive?

Every active Family Plan participant can view every current Family Shared secret. A later member is shown the existing-secret count during enrollment and receives the retained current contents after activation. Family Shared does not provide per-secret recipient selection; personal items remain private unless someone explicitly copies or moves them into Family Shared.

Link to this answer

Family Shared

What happens when a Family member is removed?

After the removal is accepted and the former member’s app processes it, MystSafe clears that device’s local Family Shared state and blocks future accepted shared changes from it. Existing Family Shared secrets remain for the family, and the former creator attribution is retained. Removal does not delete the person’s private vault and cannot retract information they already revealed, copied, saved, photographed, or otherwise retained.

Link to this answer

Share Once

Does a Share Once recipient need MystSafe?

No. A recipient can open the complete link and choose to view it securely in the first-party browser viewer. Loading or previewing the page alone does not claim the share; an explicit View securely or Copy to clipboard action begins the claim. Installing MystSafe is optional if the recipient wants to save a verified copy in a vault.

Link to this answer

Share Once

What does one valid Share Once claim mean?

The first valid claim wins and every other claimant is excluded. The winning app or browser may retry the same encrypted response until acknowledgement or expiration so interrupted delivery can finish. It means one winning protocol claim—not a guarantee that only one person viewed, copied, or retained the revealed information.

Link to this answer

Share Once

What happens after a Share Once link expires, is canceled, or is consumed—and can the recipient retain it?

The link no longer accepts a new claim after it expires, is canceled, or completes its single winning claim. Expiration and cancellation do not recall information that was already retrieved. A recipient can copy, photograph, screen-capture, record, save, or disclose revealed information, so Share Once should not be treated as a way to force deletion on the recipient’s device.

Link to this answer

Plans and billing

How do I restore Pro, and what happens if I cancel or downgrade?

In MystSafe settings, open MystSafe Pro and choose Restore Purchases to reconcile an eligible Apple purchase. Restoration recovers the commercial entitlement, not vault contents or keys. Cancel or manage billing through Apple; after paid entitlement ends, Free limits apply, but existing vault data is not deleted, hidden, or re-encrypted, and MystSafe does not migrate or delete the selected provider’s data. Compare the plans or review the Terms for the current plan rules.

Link to this answer

Plans and billing

What is the difference between Standard and Premium support?

Free and Pro use the same knowledge base and can submit the same support form. Premium support gives a self-declared Pro request priority queue handling; all support remains best effort, with no guaranteed response time or service-level agreement. It does not change encryption or provide a different level of security protection. See plan details.

Link to this answer

Import and export

Where are import and export available, and which formats are currently supported?

On iPhone and iPad, use Settings → Vault Controls; on Mac, use Settings → Vault Data. Import Vault is also available during first-run setup. All three Apple platforms import and export MystSafe encrypted .mystsafe files and readable .mystsafe.json files; Mac additionally imports Keeper Desktop JSON without attachments. Family Shared content is not silently included—save a private copy to your vault before exporting it.

Link to this answer

Security and privacy

How do I report a security concern or submit a privacy or deletion request safely?

Use the support form and choose Security concern or Privacy request. MystSafe may need reasonable verification for a privacy request, but do not send extra identity documents in the initial form. Never include passwords, decrypted vault contents, vault exports, private keys, recovery information, live QR codes, provider credentials, or complete Share Once or pairing links. Review the Privacy Policy for privacy-request details.

Link to this answer

Still need help?

Send a support request.

The same knowledge base and request form are available to Free and Pro users.

Pro support requests receive priority queue handling. All support is provided on a best-effort basis without a guaranteed response time.

If the form is unavailable, email help@mystsafe.com directly. This link never includes your form message.

Protect your vault. Do not submit passwords, vault exports, private keys, recovery information, live QR codes, or complete Share Once or pairing links. MystSafe does not need decrypted vault contents to provide ordinary support.

The complete form is limited to 16 KiB. Very long text that uses multi-byte characters can reach that limit before the character counter does.

By submitting, you ask MystSafe to use this information to respond to your request. Review the Privacy Policy and Terms of Use.

Other inquiries

Not a product-support request?

General business inquiries, partnerships, media, legal notices, and non-product corporate correspondence continue to use info@mystsafe.com.

Security concerns

Choose Security concern in the form or email help@mystsafe.com. Begin with non-sensitive scope and reproduction details. Do not send live credentials, private keys, vault exports, live QR codes, or active links. MystSafe does not currently promise a bug bounty.

Privacy requests

Choose Privacy request in the form. MystSafe may need reasonable verification, but do not send extra identity documents in the initial request. The Privacy Policy explains available rights and how requests are handled.