🔍 PAGE: FAQv5.8.152📍 8:58:03 AM

Support

Frequently Asked Questions

Everything you need to know about Lock. Can't find what's what you're looking for? Contact our support team.

What makes Lock secure?

Lock uses Zero-Knowledge Encryption (ZKE) with AES-256-GCM - the same encryption standard used by governments and banks. Here's what makes us different: ALL encryption happens on YOUR device BEFORE data reaches our servers. Your master password never leaves your device, and we literally cannot see your passwords even if we wanted to. This is true zero-knowledge security - only you have the keys to decrypt your vault.

Should I enable Two-Factor Authentication (2FA)?

YES - This is CRITICAL! Lock uses Google OAuth for authentication, which means your Google account security directly protects your vault. We STRONGLY RECOMMEND enabling 2FA (Two-Factor Authentication) on your Google account. Go to myaccount.google.com/security and enable 2-Step Verification. This adds an extra layer of protection - even if someone gets your Google password, they can't access your account without your phone/security key. This is your single most important security step! Learn more on our Security Best Practices page.

Do you record or monitor my sessions?

No — never. Lock does not record, replay, or monitor your sessions. We do not use session-replay tools, screen recording, rage-click tracking, or behavioral playback analytics of any kind. While some platforms offer these features, we have made a deliberate privacy-first choice not to enable them. Because Lock uses zero-knowledge encryption, the contents of your vault are encrypted on your device before reaching us — so even a recording would only capture encrypted gibberish. But we go further: we don't record at all. Your activity in Lock stays private, always.

Do you show ads or sell my data?

Absolutely not. Lock is 100% ad-free and we will never sell, rent, or trade your personal information. We make money from subscriptions, not from your data or attention. Your privacy is our top priority.

What is the Security Health Dashboard?

The Security Health Dashboard analyzes all your passwords and documents to identify security risks. It scores each password based on length, complexity, and common patterns. You can see which accounts need stronger passwords and acknowledge the ones you're comfortable keeping as-is. It's like having a personal security advisor!

How does the pricing work?

Lock offers a 3-month free trial for all new users! When you start your trial, you'll enter your credit card through Stripe's secure checkout, but you won't be charged anything for 90 days. After your trial, you'll be automatically charged $19.99 for your first year (or $14.99 for students with a valid .edu email). After year one, there's a small $4.99/year maintenance fee for ongoing updates and support. You can cancel anytime during the trial to avoid any charges.

Can I access my vault from multiple devices?

Yes! Lock works on all devices with a web browser. Your encrypted data syncs across all your devices automatically. You can access your vault from your phone, tablet, or computer.

What if I lose my wallet? 🎒

Lock has a unique 'Wallet Items' feature! Mark which cards and items are in your physical wallet when editing accounts. In an emergency, click the 'Wallet Items' button on your dashboard to see everything you're carrying and get quick access to customer service numbers to report lost cards. Set this up before you need it!

Does Face ID work on mobile?

Face ID and Touch ID are supported, but may occasionally need re-setup on mobile Safari due to browser security limitations. We recommend keeping your master password as a backup. On iPhone, Face ID works best when added to your home screen as a web app.

Do I need a credit card for the free trial?

Yes — a credit card is required to start your 3-month free trial. This is processed securely through Stripe. You won't be charged anything for 90 days, and you can cancel anytime during the trial to avoid any charges. After your trial ends, your card will be automatically charged $19.99 (or $14.99 for students) for your first year.

Can I track my bills and payments?

Yes! Pro accounts include comprehensive financial tracking. Set due dates and payment amounts for any account, and Lock will show upcoming payments on your dashboard. You can also track account balances, create budgets, and monitor your net worth over time.

How do I backup my data?

Your data is automatically backed up to secure cloud storage. You can also export your vault data as an encrypted file for local backup. Pro users get additional backup features and can restore from previous versions.

What about document storage?

Lock can securely store important documents like insurance cards, IDs, contracts, and receipts. Files are encrypted and organized by category. Perfect for keeping digital copies of everything in your wallet or filing cabinet.

Is there a mobile app?

Lock is a Progressive Web App (PWA) with full offline support! When you visit the site, you'll see an 'Install' prompt. Once installed, the app works on your device just like a native app - even without internet connection. On iPhone/Android, you can also 'Add to Home Screen' for quick access. All your encrypted data is cached locally for offline use.

How do I prepare for offline access?

To use Lock offline (like on a plane), you must prepare ahead of time while online: 1. Log in and unlock your vault while connected to wifi/cellular 2. Keep 'Remember this device' checked (it's on by default) - this trusts your device for 30 days 3. Click 'Prepare Offline' button on your dashboard to verify everything is cached 4. You're ready! Close the app, shut down your device if needed When offline, open the app and enter your master password to access your full vault — including the 'View All' password table. You can edit accounts and make changes while offline. Any changes you make will sync automatically to the cloud once you reconnect to the internet. Device trust lasts 30 days, then you need to be online once to refresh.

Why can't I sign out while offline?

IMPORTANT: Do NOT sign out while offline! Here's why: Lock uses base44's authentication system, which requires an internet connection to verify your Google account. When you sign out, it clears your session completely. To sign back in, the app needs to contact base44 servers - which is impossible offline. If you sign out without wifi/cellular, you'll be locked out until you reconnect. We show a warning if you try to sign out offline. This limitation exists because Lock is built on base44's infrastructure, not a standalone offline-first app.

How does offline mode work?

After preparing offline access, all your encrypted vault data is cached locally on your device using IndexedDB. This means you can open the app, enter your master password, and access all your passwords and documents WITHOUT an internet connection. When you reconnect, any changes sync automatically. Your data stays encrypted even when stored offline. The 'Remember Device' feature (30-day trust) allows you to unlock your vault offline even after shutting down your device.

What happens if I forget my master password?

⚠️ Your Recovery Key is your ONLY option — support cannot help recover your vault. Due to our zero-knowledge encryption, we have no access to your data and CANNOT reset your password for you. When you created your vault, you received a Recovery Key (format: XXXX-XXXX-XXXX-XXXX-XXXX-XXXX). This key is your saving grace — you MUST keep it saved somewhere safe (physical safe, trusted family member, secure location). Without it, a forgotten master password means permanent loss of vault access. There are no exceptions.

How do I verify my Master Recovery Key (MRK) is correct?

You can now test your MRK at any time without restoring or changing anything! Here's how: 1. Sign in and click your profile avatar (top-right corner) 2. Select 'Verify Master Recovery Key (MRK)' from the menu 3. Enter the MRK from your printed sheet 4. Click 'Verify MRK' A green checkmark means: ✅ 'Confirmed — you have the correct Master Recovery Key for this email address.' A red X means: ❌ 'Incorrect MRK — please check your printed sheet and retry.' This check runs entirely on your device — nothing is sent to any server. Note: Support CANNOT retrieve or reset your MRK if you do not have the correct one for your account. Your printed MRK sheet is the only record that exists.

Can I share passwords with family?

Currently, Lock is designed for individual use to maintain maximum security. Family sharing features are planned for future updates. For now, you can safely share individual passwords through secure methods outside the app.

How does the smart budget feature work?

Pro accounts can generate smart budgets automatically from your vault data. Lock analyzes your stored accounts with payment amounts and creates a monthly budget breakdown. It can even suggest better category organization and identify missing expenses.

My bank shows multiple accounts during Plaid setup — can I delete the unwanted ones from Lock afterward?

Yes! You can absolutely delete extra accounts from Lock after completing the Plaid setup. Here's what's happening and what to do: Why multiple accounts appear: Banks like Wells Fargo show all accounts previously entitled for Plaid sharing. Grayed-out checkboxes (with messages like 'Disabled checkboxes is account data you previously entitled for sharing') just mean the bank controls which accounts are shareable — it doesn't mean Lock forces you to keep them all. Option 1 — Delete from Lock (Easiest & Recommended): 1. Complete the Plaid connection as normal 2. Go to Transaction Manager in Lock 3. Find the accounts you don't want 4. Delete them — Lock will only show and sync the accounts you keep Option 2 — Remove from your bank (More thorough): 1. Log in to your bank online (e.g., Wells Fargo) 2. Go to Manage Connected Apps 3. Find Plaid and uncheck the accounts you don't want shared 4. This stops the bank from sharing that data with Plaid entirely Recommendation: Go with Option 1. Complete the setup, then delete the unwanted accounts from Lock. It's faster and achieves exactly what you want. Option 2 is only needed if you have privacy concerns about the bank sharing that data with Plaid at all.

Do I need to save my bank username/password in Lock when connecting a bank account via Plaid?

No — Lock never sees or stores your bank username or password. Here's how it works: When you click 'Connect Your First Account' (or 'Connect Another Account'), Plaid opens a secure window. You log in to your bank directly inside Plaid's secure window — not in Lock. Plaid then gives Lock a secure read-only access token (not your credentials). Lock only stores that token, never your bank login details. After the one-time setup, you simply click 'Sync Transactions Now' whenever you want fresh transactions — no re-entering credentials needed. The only exception is if your bank requires periodic re-authentication, which Plaid handles automatically. Note: Plaid may ask you to save your phone number at the end of setup. This is completely optional — simply click 'Finish without saving' to skip it and complete the connection without providing a phone number.

What happens if I change my bank password? Will my Plaid connection break?

Yes — if you change your bank login password, your Plaid connection will need to be re-linked. Plaid maintains a secure, encrypted connection to your bank using your credentials. When those credentials change, Plaid can no longer connect and the link becomes invalid. You'll know this happened if syncing stops working or you see a login error. To fix it: 1. Go to Transaction Manager → Bank Connections tab 2. Click 'Enable Real-Time Balances' next to your bank 3. Plaid will detect the old credentials no longer work and ask you to enter your new bank login 4. Once you re-authenticate with your new password, the connection is restored — with balance access enabled This re-linking happens entirely through Plaid's secure window. Lock never sees or stores your bank password. You only need to do this when you change your bank password — normal syncing does not require re-entering credentials.

Still have questions?

Our support team is here to help. We typically respond within 24 hours.