← Home

FAQ

Common questions about Cryptograph

Pricing

Why isn't it free?

Cryptograph is paid software. The app contains no accounts, analytics, trackers, ads, or transaction fees. One purchase supports development and ongoing updates.

Can I buy, sell, exchange, or trade assets through Cryptograph?

No. Cryptograph is wallet software. It does not provide purchasing, selling, exchanging, swapping, trading, brokerage, lending, staking, custody, or fiat on-ramps or off-ramps. The iPhone prepares unsigned transactions, and only Apple Watch can approve and sign them. Buying Cryptograph in the App Store purchases the app, not digital assets.

Keys & Storage

Where are private keys stored?

On the Apple Watch only. Keys are generated on the watch and stored in its Keychain, encrypted by a key in the Secure Enclave. Keys are never included in iCloud backups, iTunes backups, or any cloud sync.

What happens if the watch passcode is removed?

watchOS permanently destroys all Keychain-stored keys, including your wallet. This is Apple operating system behavior. Restore from your Recovery Sheet or Photo Backup.

Phone vs. Watch

What does the watch do vs. the phone?

Apple Watch generates and stores the keys, decodes requests, asks for approval, and signs. The iPhone displays the portfolio, prepares unsigned requests, handles networking, and relays data. It cannot sign.

Why keep signing keys off the phone?

When one device receives transaction requests and holds signing authority, a compromise can reach both. Cryptograph puts signing authority on Apple Watch. Compromising the iPhone does not provide the signing material held on the watch.

What can a compromised iPhone still do?

It can expose public wallet information, prepare a malicious request, or try to mislead you. It cannot produce a signature. Cryptograph decodes the transaction bytes on Apple Watch so you can review what was actually requested before approving.

How is this different from a dedicated hardware wallet?

Both keep signing authority off the phone. Cryptograph uses a compatible Apple Watch and Apple's software and distribution stack instead of a purpose-built device and vendor firmware. The platform, update, recovery, and physical-security tradeoffs are different.

Does the phone ever see my private keys?

No. Private keys never reach the phone in plaintext. The watch signs; the phone relays.

Recovery

Can I import a wallet protected by a BIP39 passphrase?

Yes. On the watch, choose Recover → Enter Seed Phrase → 24 + BIP39 Passphrase. Enter all 24 words, then the exact passphrase. Cryptograph accepts 1–50 printable ASCII characters with no leading, trailing, or repeated spaces; Unicode characters such as emoji, accents, and smart quotes are intentionally rejected. Every accepted passphrase, including a typo, derives a valid wallet, so confirm the expected address or balance. A Recovery Sheet or Photo Backup created afterward encrypts both the mnemonic and BIP39 passphrase. The Unicode rationale explains why Cryptograph uses this stricter profile.

Are backups encrypted?

Yes. Backups are encrypted on-watch before any data reaches the phone. The phone never sees plaintext recovery data. Encryption uses PBKDF2 (1,000,000 iterations) + ChaCha20-Poly1305, secured with a PIN or passphrase you choose on the watch.

Can iCloud restore my wallet?

No. Keys are stored with kSecAttrAccessibleWhenUnlockedThisDeviceOnly, which excludes them from all backups. Use your Recovery Sheet or Photo Backup.

What happens if I lose my watch?

Your keys are gone with the watch. Restore from your Recovery Sheet or Photo Backup on a new Apple Watch.

What happens if I lose my recovery material?

If you lose both the watch and all recovery material (Recovery Sheet and Photo Backup), your funds are permanently inaccessible. There is no backdoor, no server recovery, no override.

Trust & Security

Can Cryptograph access my funds?

No. Cryptograph is non-custodial. We never see, store, or have access to private keys. We cannot freeze, access, reverse, or recover your funds.

Can Apple access my funds?

No. The Secure Enclave key is hardware-bound and not exportable. Apple cannot extract it. Keys are excluded from all backups. Apple has no mechanism to access, freeze, or transfer your funds.

Can app updates compromise my wallet?

Any updatable wallet must trust its update mechanism. If an attacker compromises the developer's build pipeline, a tampered version of the app can misuse legitimate key-access paths and exfiltrate secrets. Secure Enclave protects keys at rest, not against a compromised version of the app at runtime. Cryptograph reduces this risk by keeping key use narrow and visible, distributing through Apple's App Store (independent friction), and making security-critical code publicly inspectable.

What do I have to trust?

Cryptograph relies on Apple Watch hardware, watchOS, App Store distribution, and Cryptograph's implementation. Network access and market data also travel through external infrastructure. No company-held key or custody service is involved. See How It Works for the full trust model.

What does this not protect against?

Compromised updates (mitigated, not eliminated). A fundamental Apple platform compromise. Loss of all recovery material. Sustained physical coercion beyond your configured Time Lock delay.