← Home

Recovery Sheet: An Encrypted QR You Can Print

Recovery starts with an object you can find again.

The Cryptograph Recovery Sheet is a printed page containing an encrypted QR code and a short verification code. It can sit in a safe, a deposit box, or another place reserved for important paper. Its continued existence does not depend on a Cryptograph account, a cloud subscription, or a company-held copy.

The QR code contains encrypted recovery data. It does not print a list of seed words, and the restoration flow does not ask you to type one into a phone or computer.

That distinction matters. A physical backup can remain simple to store without turning the wallet mnemonic into readable text.

What the sheet contains

Cryptograph uses a BIP-39 mnemonic. The mnemonic exists because the wallet needs a deterministic way to derive the same accounts again during recovery. It is generated on the watch during normal wallet creation, protected at rest, and part of a wallet whose keys are secured by the Secure Enclave.

The Recovery Sheet gives you a way to preserve that recovery capability without handling the mnemonic as a word list.

When you create a sheet, the watch asks you to choose a recovery PIN or passphrase. The watch uses that secret to encrypt the recovery payload before anything is sent to the iPhone. The phone receives opaque ciphertext. It can turn those encrypted bytes into a QR code and prepare the page for printing, but it does not receive the mnemonic or the recovery secret.

The printed verification code identifies that particular encrypted payload and serves only as a comparison fingerprint. During setup and restore, the watch uses it to let you confirm that the page in your hand matches the recovery data being handled.

The result is a piece of paper with two useful properties. It carries the data needed to restore the wallet, and that data remains encrypted when the page is viewed, copied, or stored.

Why paper still matters

Paper has modest virtues that are unusually useful for recovery.

It is offline once printed. It does not need a battery, an account session, or a compatible cloud plan to remain where you put it. A sheet can be placed in a fire-resistant safe, a deposit box, or a sealed envelope held under a clear family or estate plan.

Paper is also inspectable. You can confirm where the sheet is, whether the print is still readable, who can reach it, and whether a second copy exists. Those are physical questions with physical answers.

The format is conspicuous by design. A Recovery Sheet should look like an important document so the person responsible for it knows to preserve it. That clarity also means it should be stored with care. A visible QR code can be photographed, copied, or stolen. The page belongs wherever you would keep cash, jewelry, or another bearer-like object.

Paper has ordinary failure modes. Fire, water, fading, accidental disposal, and an inaccessible safe can all defeat a single copy. Reprinting lets you make deliberate redundancy. Each copy should remain readable, controlled, and separate from the recovery secret.

The Recovery Sheet is a storage object under your control. Cryptograph provides no storage service for it and cannot retrieve a sheet after it is lost.

Creating and checking the sheet

The flow begins on Apple Watch.

You choose Recovery Sheet and create a recovery PIN or passphrase. The watch encrypts the recovery data locally, then passes the encrypted payload to the iPhone. The iPhone shows the printable sheet and opens the system print flow.

After printing, the watch asks you to check a letter from the verification code on the page. That small step confirms that you have access to the current sheet before onboarding continues. If the code does not match, you can return to the print step and make another copy.

The recovery credential should be preserved separately from the page. Anyone who obtains both a valid Recovery Sheet and its PIN or passphrase can restore the wallet. Anyone who forgets the credential has no reset path through Cryptograph.

Credential strength matters because a stolen encrypted backup can be tested offline. A short or predictable PIN offers less resistance than a longer, uncommon passphrase. High-value wallets deserve a strong recovery secret, stored in a different place from the sheet.

The Recovery Sheet does not need to be connected to the internet after printing. It does need to remain complete and readable. Folding around the QR code, poor print quality, ink damage, and aggressive scaling can make scanning harder. The verification step and an occasional physical inspection are practical checks against those failures.

Restoring from the printed QR

Restore also begins on the watch.

You choose Recover, then Scan Recovery Sheet. The iPhone camera scans the QR code and passes the encrypted payload to the watch. The phone is acting as a scanner and transport surface. It does not decrypt the payload.

The watch asks for the Recovery Sheet PIN or passphrase. It decrypts and validates the recovery data there, then reconstructs the wallet. The watch displays the verification code so you can compare it with the code printed on the sheet before accepting the restore.

The watch accepts a restore only after authenticated decryption succeeds. Wrong credentials and damaged or altered encrypted data fail instead of being accepted as recovery material. Repeated credential attempts are rate-limited on the watch.

At no point in this path do you type the wallet mnemonic into the iPhone. The mnemonic remains part of the wallet architecture, but the Recovery Sheet turns recovery into a scan-and-confirm flow rather than a word-entry ceremony.

This also keeps the company outside the restore loop. There is no Cryptograph login to recover, no support agent with a master key, and no customer backup database to query. The page and the recovery secret are the authority.

Recovery Sheet and Photo Backup are separate methods

Cryptograph offers a second recovery method called Photo Backup. It uses ordinary JPEG images as carriers for encrypted recovery data.

The Recovery Sheet remains a printed QR code on paper. Photo Backup remains encrypted data hidden inside images. They share a recovery purpose and preserve the same watch-side boundary, but they solve different storage problems.

Paper is direct. It is easy to place in a known physical location and easy to include in an estate or emergency plan. Photo Backup is discreet and easy to duplicate in places where image files already belong.

Using one method does not turn it into the other. A printed page should be managed as an important physical document. Photo Backup files should be preserved as original image files because editing or recompressing them can damage the hidden data.

Some recovery plans may use both. Separate carriers can reduce the chance that one fire, one lost device, or one storage mistake removes every path back to the wallet. Each artifact still depends on the recovery secret, and Cryptograph cannot replace either one.

The responsibility stays with the holder

An encrypted sheet remains a self-custody responsibility.

If someone obtains the page and the recovery secret, that person can restore the wallet. If every sheet is lost and no other recovery method remains, Cryptograph cannot recreate the encrypted payload. If the recovery secret is forgotten, there is no company override.

The practical posture is straightforward. Print clearly. Verify the code. Store the sheet like a valuable document. Keep the recovery secret elsewhere. Check the paper occasionally, and make intentional copies when one physical location is not enough.

An encrypted object that you hold, inspect, and preserve can provide recovery without an account workflow or a plaintext list of words.

Cryptograph is available now on the App Store.

The Cryptograph Team

← All posts