Cryptomator
Cryptomator 1.19.3 is a client-side encryption tool for cloud-synchronized folders that protects file names and contents inside an encrypted vault on Windows, macOS and Linux.
What Cryptomator provides
Cryptomator creates an encrypted vault that can live inside a cloud-sync directory. The desktop client unlocks the vault locally so applications can work with readable files while the sync provider stores encrypted names and content. The cloud account, device, sync timing and other service metadata still require their own protection.
Password, recovery and conflict boundaries
The vault password is a core credential. Store recovery material separately and rehearse a restore before moving the only copy of a vault. Wait for synchronization to finish before changing devices, and avoid concurrent edits to the same file because sync conflicts can create multiple versions.
Platform and migration notes
Version 1.19.3 is archived here for Windows x64, macOS Intel or Apple Silicon and Linux x64. Test Chinese names, large files, lock and restore behavior in a copy before migrating a working vault. Review date: 2026-08-23.
Save to your cloud drive
Open the cloud drive to get the file directly, or save it for convenient access on another device.
Quark Cloud Drive
RecommendedSave Cryptomator to this cloud drive
Baidu Netdisk
Save Cryptomator to this cloud drive
Cryptomator 1.19.3 vault creation and cloud sync guide
Create a small local test vault, verify password and recovery handling, let synchronization finish and then test a second device before moving real files.
Before you start
- Select the Windows, macOS or Linux package for the device and prepare separate local and synchronized directories.
- Plan independent storage for the vault password, recovery material and cloud account.
- Prepare test data that includes a Chinese name, a larger file and a normal document so sync behavior is observable.
Installation steps
- 01
Install the matching 1.19.3 package
Use the Windows x64 MSI, the matching macOS DMG or the Linux x64 AppImage, then verify the version and permission prompts.
- 02
Create and unlock a test vault
Choose a local or synchronized directory, create a strong password, save recovery material separately, write a test file, lock the vault and unlock it again.
- 03
Verify synchronization and conflicts
Wait for the cloud client to finish, open a copy read-only on a second device and observe conflict behavior before allowing edits from both devices.
Quick start
- 01
Separate vault scopes
Keep work, archive and shared material in separate vaults or directories to reduce the amount of data exposed by one unlock operation.
- 02
Lock before leaving the device
Lock all vaults, confirm cloud upload completion and sign out of the sync account on shared computers before clearing temporary files.
- 03
Rehearse recovery
Copy a vault to an isolated directory, unlock it with the recovery material and inspect representative files across the supported platforms.
Usage tips
- Encryption hides readable file content and names from the sync provider, but account, timing, file-count and device metadata remain separate concerns.
- Wait for synchronization before switching devices and avoid simultaneous writes to the same file.
- Keep password, recovery material and cloud credentials in separate protected stores.
Troubleshooting and uninstall
What should I do when a vault shows a sync conflict?
Pause further editing, let each device finish syncing, keep the conflict copy and compare the versions manually before merging or removing duplicates.
Why will an unlocked file not open?
Check synchronization completion, disk space and permissions, then copy a small file to a local test directory. Avoid bulk moves while the sync client is still processing.
- Lock and verify the vaultLock every vault, confirm synchronization and use recovery material to verify a backup copy before removing the application.
- Uninstall without deleting encrypted dataRemove Cryptomator through the operating system and handle vault directories and recovery material under their own retention policy.
Frequently asked questions
What can a cloud provider see after a vault is encrypted?
The provider normally sees encrypted objects, synchronization activity and account metadata; exact metadata varies by version and service. File names and contents are stored in encrypted form.
What happens if I forget the vault password?
Check the recovery material saved when the vault was created and test a backup copy. A cloud account password is not automatically a vault recovery key.
Does the download require an extraction code?
The Quark entry does not require one; the four-character code for the Baidu entry is shown beside its download entry.