Skip to content

๐Ÿ” Cryptomator guide

Cryptomator encrypts files on your own device before they are stored in a cloud service. This guide uses Google Drive as an example. The vault folder you see in the cloud contains encrypted data, and its files should not be edited directly.

๐Ÿ’ป Creating a vault on a computer

  1. Install Google Drive for desktop and make sure Google Drive appears in File Explorer or Finder.
  2. Install and open Cryptomator.
  3. Choose Add vault โ†’ Create new vault (Add Vault โ†’ Create New Vault).
  4. Give the vault a name.
  5. Choose a Google Drive synced folder as the storage location for the vault.
  6. Create a strong and unique password for the vault.
  7. Store the recovery key in a safe place separate from the vault.
  8. Finish the setup. Google Drive will automatically start syncing the encrypted vault folder.

Important: Cryptomator cannot recover a forgotten password without the recovery key.

๐Ÿ“ฑ Creating a vault on a phone

  1. Install Cryptomator on your phone from your app store and open the app.
  2. Add Google Drive as a cloud service and sign in to your Google account. Accept the permissions requested by the app.
  3. Tap the plus button and choose Create new vault.
  4. Choose Google Drive and the folder you want as the storage location.
  5. Give the vault a name and create a strong password.
  6. Store the recovery key in a safe place.

Menu names may differ slightly between Android and iPhone. On iPhone, Cryptomator also works through the Files app.

๐Ÿ”“ Adding and opening an existing vault

On a computer

  1. Wait until Google Drive has synced the vault folder to your computer.
  2. Open Cryptomator and choose Add vault โ†’ Open existing vault.
  3. Choose the vault folder in Google Drive and its vault.cryptomatorfile.
  4. Select the vault from the list, press Unlock and enter the vault password.
  5. Open the virtual drive or folder that appears. Use files only through this unlocked view.

On a phone

  1. Add Google Drive to Cryptomatorโ€™s cloud services.
  2. Tap the plus button and choose Add existing vault.
  3. Find the vault folder in Google Drive and select it.
  4. Tap the vault and open it with the password, biometric authentication, or the device key if you have enabled one.

๐Ÿ“„ Adding and editing files

On a computer

  1. Unlock the vault in Cryptomator.
  2. Open the virtual drive or vault folder shown by Cryptomator.
  3. Drag or copy files into the unlocked vault just like you would with a normal folder.
  4. Open and edit files with your usual applications. Save changes normally.
  5. Cryptomator encrypts the changes, and Google Drive syncs the encrypted files to the cloud.

On a phone

  1. Open the vault in Cryptomator.
  2. Create a folder, import a file from the device, or use the share sheet to add a file to the vault.
  3. Open the file from Cryptomator in a compatible application.
  4. Save the edited file back into the vault. Not all apps can save directly back to the same file, so the edited version may need to be imported back separately.

๐Ÿ—‘๏ธ Removing files and moving them out of the vault

  • Deleting: Open the vault and remove the file or folder from the unlocked virtual drive or the Cryptomator app. Do not delete individual encrypted files directly from the Google Drive vault folder.
  • Moving out on a computer: Move or copy the file from the unlocked vault to a normal folder. If you copy the file, remove the original from the vault separately if you do not want to keep it there.
  • Moving out on a phone: Select the file and use the Export-, Share- or Save to device action. Remove the original from the vault separately if needed.

Note: A file moved or exported out of the vault is no longer protected by Cryptomator.

๐Ÿ”’ Closing the vault

On a computer

  1. Save and close all files that are open from the vault.
  2. Wait a moment so your applications have time to write changes to disk.
  3. Return to Cryptomator and press Lock (Lock).
  4. Wait until Google Drive has synced the changes before shutting down the computer.

On a phone

  1. Return to Cryptomator and close the open vault with the lock button.
  2. You can enable automatic locking in the settings so the vault closes when you leave the app or after a set amount of time.

โš ๏ธ Important things to remember

  • Keep the vault password and recovery key safe. Neither the cloud service nor Cryptomator support can open the vault for you.
  • Do not rename, move, or edit the encrypted files inside the vault directly in Google Drive.
  • Back up the vault. Cloud syncing alone is not a backup.
  • Before locking the vault, make sure the files are no longer open in other applications.
โฌ… Back to guides