Skip to content
Ownfold
Esc
navigateopen⌘Jpreview
On this page

Lost access and device failure

Exact recovery outcomes when devices, Recovery Kits, secrets, browser storage, accounts, or encrypted server data are lost.

Ownfold has no maintainer master key, hosted recovery service, or backdoor. Recovery outcomes are therefore determined by the material the user still controls.

Remaining material Outcome
At least one working authorized device Unlock locally, enroll a replacement through pairing, revoke lost devices, and create a current Recovery Kit.
Recovery Kit and correct secret Restore on a trusted browser, register it as a new device, then review and revoke older devices.
Recovery Kit but forgotten secret No bypass exists. Password guessing is intentionally expensive and may never succeed.
Secret but no Recovery Kit file The secret alone contains no root key and cannot restore the vault.
No authorized device and no usable Kit plus secret Encrypted data is permanently unrecoverable. Account or application-password reset does not change this.
Authorized device storage cleared Use another device or the Kit. IndexedDB deletion, private-browsing cleanup, origin changes, and site-data clearing can remove the device identity.
Server metadata lost but encrypted records remain Recovery material alone may open record keys, but the host must restore trustworthy vault/key-version and ownership coordination metadata before normal operation.
Encrypted records deleted or corrupted Keys cannot recreate ciphertext. Restore an intact application backup.

Account reset and deletion

Authentication password reset must not silently recover encrypted data or reuse the account password as a Recovery Kit password. After an account identity change, the host must preserve the stable ownership mapping or perform an explicit, authenticated migration while the user still controls an authorized vault key.

Account deletion should clearly distinguish deleting server ciphertext and metadata from removing local browser keys. Coordinate retention and deletion across backups. Warn that deletion is irreversible once ciphertext and every usable local copy are gone.

Support guidance

Support staff should verify account ownership through the host’s normal process but must never ask for a Recovery Kit, recovery secret, decrypted content, or browser-storage export. They can explain the available paths, inspect non-secret error codes and metadata, and help restore application availability. They cannot decrypt or reset a vault.

Last updated on August 4, 2026

Was this page helpful?