Short answer

If someone knows your iPhone passcode, assume they may be able to unlock Apple’s Hidden and Recently Deleted collections. A separate photo vault with a different PIN creates an additional boundary, but changing the exposed device passcode is still the most important step when it is safe.

Why the Hidden album may not be separate enough

Apple locks Hidden and Recently Deleted by default on current iOS versions. They open with Face ID or Touch ID, but the device passcode is part of the same authentication system. This is convenient for the phone owner and less useful when the privacy problem is a person who already knows that code.

The goal is not to stack random privacy features. It is to separate the credentials: one code unlocks the phone, another unlocks the small library that needs a stronger boundary.

A practical privacy checklist

  1. Decide whether it is safe to change the iPhone passcode.If yes, use a new code the other person cannot infer. Do not reuse the new code in a vault.
  2. Review who and what has account access.Apple Safety Check can review sharing, connected devices, app permissions, trusted numbers and Apple Account access.
  3. Check biometric access.Review Face ID or Touch ID setup if another person may have been added. Apple Safety Check can help update device authentication information.
  4. Create a separate private-vault PIN.Use a code unrelated to birthdays, addresses, the device passcode or common sequences.
  5. Import and verify the sensitive files.Open the encrypted copies at full size before deleting any original.
  6. Remove the verified originals from Photos.Remember that Recently Deleted keeps recoverable copies for up to 30 days unless you remove them permanently.
  7. Reduce casual discovery.Use a utility cover if helpful, hide sensitive notification previews, and avoid leaving the vault visible in the app switcher.
A private vault does not secure the entire iPhone.
Someone with the device passcode may access messages, mail, passwords, account settings and other apps. Treat the separate vault as one layer, not a substitute for recovering control of the device and Apple Account.

What to look for in a separate vault

A truly separate PIN

The app should accept its own PIN instead of relying only on the device passcode. VaultBox’s biometric path uses biometric-only authentication; if Face ID is unavailable, the user returns to the VaultBox PIN rather than an iOS passcode fallback.

Clear file handling

The app should say whether imported media is copied or moved, where encrypted files live, and whether originals remain in Photos. VaultBox keeps originals until you choose deletion after a successful import.

Decoy access for coercive situations

A decoy PIN opens a separate harmless vault. It can reduce exposure when refusing to open the app is difficult, but it is not a guarantee against a determined person who controls the device.

Discretion without false invisibility

A calculator or notes cover can reduce casual discovery. On iPhone, alternate icons do not erase the real app from App Library, Search or Settings. Read the calculator disguise guide before relying on one.

If the passcode issue is part of controlling behavior

Make changes from a device and location that are safe for you. Account or sharing changes can sometimes be noticed by another person. Apple’s Personal Safety User Guide includes a Quick Exit control and explains Safety Check for reviewing or stopping access.

This page is general technical guidance, not personal-safety or legal advice. If you are in immediate danger, contact local emergency services or a trusted support organization using a safe device.

Common questions

Can someone use my iPhone passcode after Face ID fails?

For Apple’s Hidden album, Apple documents Face ID, Touch ID or the device passcode as valid authentication. VaultBox uses its separate PIN when its biometric authentication does not succeed.

Should I use the same PIN for convenience?

No. Reusing the exposed device passcode removes the separation you are trying to create.

Will an app disguise stop someone who searches Settings?

No. A disguise is for casual visibility. A person actively inspecting installed apps may still identify it.

Sources

Create a PIN separate from the phone.

VaultBox adds an encrypted library with its own PIN, biometric-only authentication and optional decoy access.

Download VaultBox