Locka — Password Vault
A free Android password vault. Local-first. Hardware-encrypted. Offline. No ads. No accounts. No cloud. Your passwords never leave your phone.
A Password Manager You Can Actually Trust
The idea for Locka came from a simple frustration. Every password manager on the Play Store either wants a monthly subscription, pushes your data to a server you can't see, asks you to create yet another account, or locks essential features behind a paywall.
We asked ourselves a basic question: why should protecting your passwords require trusting someone else's server?
Password managers exist because humans are terrible at remembering unique passwords. The average person reuses the same three or four passwords across dozens of apps. When one site leaks, every account that shares that password is instantly compromised.
The correct solution is simple: use a different, strong, random password for every account. But nobody can memorize fifty random strings. So you need a vault — one that is available offline, encrypted, fast, free, and private.
Locka delivers on all five, because it was designed from the ground up to be a local-first, hardware-encrypted, offline vault with no cloud, no accounts, and no compromises.
Three Layers of the Password Problem
Most tools only address one. Locka solves all three.
The Memory Layer
You can't remember unique passwords. You need storage. Locka stores them — cleanly, quickly, and securely.
The Security Layer
If you store passwords, they must be encrypted — genuinely encrypted with a key only the user holds. Locka uses Android's hardware-backed Keystore with AES-256-GCM.
The Friction Layer
Even a secure vault is useless if opening it is annoying. Locka cuts unlock to a single tap — biometric — while still protecting the fallback PIN with strong encryption.
Five Things. Done Right.
No server. No cloud. No account. Just a vault that works.
Stores Passwords Securely
Each credential has a name, username, password, category, and timestamp. Encrypted with AES-256-GCM using a key that lives inside the Android Keystore — hardware-isolated.
Locks Behind a PIN
On first launch, you create a 6-digit PIN. Locka stores only a SHA-256 hash in encrypted preferences — never the PIN itself.
Biometric Unlock
Enable fingerprint or face unlock via Android's BiometricPrompt. Biometric data never enters the app.
Autofills Into Other Apps
Tap a login field in any app — Android shows your saved Locka credentials. Autofill is entirely local.
Detects New Passwords
When you type a password into a new app for the first time, Android tells Locka — and Locka asks if you want to save it.
How Security Works
Every layer explained — from encryption at rest to clipboard auto-clear.
The 5-Step Pipeline
User Types a Password
The password is never stored in plaintext anywhere.
Random 12-byte IV Generated
A unique initialization vector ensures encrypting the same password twice produces different outputs.
AES-256-GCM Encryption
The password is encrypted with a key stored in the Android Keystore.
IV + Ciphertext Base64-Encoded
The combined blob is encoded into a single string for storage.
Written to Room Database
Local SQLite database. If extracted, the attacker gets only ciphertext.
Six More Layers
No Network Transit
There is no transit. Locka never sends anything over the network.
PIN Protection
SHA-256 hash stored in EncryptedSharedPreferences. PIN cannot be recovered — a feature, not a bug.
Biometric Protection
Android's BiometricPrompt handles matching. Locka never receives biometric data.
Screenshot Protection
Every screen uses FLAG_SECURE. Screenshots, screen recordings, and task switcher previews are blocked.
Auto-Lock
Configurable interval — 1, 5, 15, or 30 minutes, or immediately.
Clipboard Auto-Clear
Copied passwords are automatically cleared from the clipboard after 30 seconds.
Only What's Needed
Four permissions. Every one has a direct user-facing purpose.
What Locka Requests
4 Permissions- VIBRATEHaptic feedback on wrong PIN, successful unlock, and password generation.
- USE_BIOMETRICRequired to enable fingerprint or face unlock.
- INTERNETRequired only to open external links — like the "Visit Awan IGD" button.
- POST_NOTIFICATIONSUsed by autofill to show "Password saved" or "Password updated" toasts.
What Locka Does NOT Request
Zero Access- Contacts
- Calendar
- Location
- Camera
- Microphone
- Storage
- QUERY_ALL_PACKAGES
Component Overview
A native Android app — Java + Jetpack libraries (AndroidX).
The launch screen with animated logo entrance.
The gatekeeper. 6-dot PIN indicator, hidden EditText, biometric button.
Dashboard with stats card, search bar, credential list, and FAB.
Create or edit a credential. Live password strength meter and generator.
Full view with masked password, strength meter, added date.
Minimal settings — biometric toggle, autofill activation.
App information, parent company, founder, contact.
Detects login fields by autofill hints and resource IDs.
Data layer. Room database, encryption/decryption logic.
Singleton wrapper around EncryptedSharedPreferences for PIN hash.
Deliberately Minimal
Clean palette. Emerald teal accent. Subtle motion. Nothing overstays its welcome.
Light Background
Reduces eye strain and keeps focus on content.
Emerald Teal Accent
Color #00D9A3 — evokes security, trust, and technology.
Bold Typography
No thin fonts, no decorative serifs. Readable at a glance.
Subtle Motion
Every screen has entrance animations — 400 to 600ms per element.
8dp Grid
Cards and spacing follow an 8dp grid.
Premium Feel
Not a free utility aesthetic. A premium security product.
What Happens If...
Because Locka handles sensitive data, edge cases matter.
User Forgets PIN
Vault is permanently inaccessible. This is intentional — recovery would be a vulnerability.
User Rotates Phone
All activities are locked to portrait. No data loss, no state glitches.
Phone Is Rooted
Database file can be extracted, but contains only ciphertext.
App Killed by OS
Session state is checked on next launch. If auto-lock expired, the vault stays locked.
User Uninstalls
All data is wiped. There is no cloud backup because there is no cloud.
App Crashes
The vault remains locked until the user explicitly unlocks it again.
Syncing Passwords Is Fundamentally Harder
Modern users expect everything to sync. Photos sync to the cloud. Documents sync to Drive. Bookmarks sync to browsers. So why would anyone choose a password manager with no sync?
Because syncing a password vault is fundamentally harder to secure than syncing photos.
To sync passwords, you need a server, network encryption, server-side encryption, key management, and recovery. Every one of those steps is a potential failure point.
Locka sidesteps all of it. There is no server, no sync, no key management problem. The only attack surface is the phone itself.
The tradeoff is that users cannot access their passwords on multiple devices. Locka is built for those who value privacy over convenience.
Free. Forever.
Locka is free, and there are no plans to change that. It exists as a public-good project — a way to demonstrate that enterprise-grade security can be delivered to consumers without a business model that treats user data as inventory.
The app is funded entirely by Awan IGD's other products and services. If users want to support the project, the About screen includes a welfare donation link.
Future Ideas
None of these are promised. Each feature is added only when fully designed and tested.
Encrypted Export / Import
JSON export with optional password protection on the exported file.
Custom Categories
Currently credentials default to "Personal" — future versions may allow tagging.
Password Health Checks
Flag weak, reused, or old passwords locally — no internet needed.
Optional Encrypted Sync
End-to-end, user-controlled key, opt-in, open source.
Wear OS Companion
View-only credentials on smartwatches.
Lessons From Building Locka
Constraints Force Good Design
Because we couldn't rely on a server, we thought carefully about what could live on the device.
Privacy Is a Feature, Not a Tradeoff
Removing the "sync" checkbox didn't reduce the app's usefulness — it sharpened it.
Motion Makes an App Feel Finished
A screen that appears instantly feels cheap. A screen that slides in over 400ms feels intentional.
Simplicity Is the Hardest Thing
Locka's file structure is small — around a dozen classes. Every screen does one thing.
The Weakest Interaction Defines the App
A strong encryption scheme doesn't matter if the unlock flow is annoying.
Built by Awan IGD
Intelligent Grid Development — Technology for Everyone, Welfare for All.
Who We Are
Awan IGD (Intelligent Grid Development) is an independent software studio based in Tial, PO Jabri, Khanpur, Haripur, KP, Pakistan — founded by Bilal Rasheed.
The studio builds AI platforms, Islamic knowledge systems, enterprise solutions, and community welfare technology. Locka is the studio's first consumer security product.
Credits
Locka is designed and built by Awan IGD.
Special thanks to the Android security team for the Android Keystore, the AndroidX team for BiometricPrompt and EncryptedSharedPreferences, and the Room team for making SQLite almost pleasant to work with.
And thanks to everyone who cares enough about their passwords to use a tool that doesn't sell them.
A Vault, Locked by You, for You
Locka isn't trying to be the biggest password manager. It's trying to be the one you can actually trust — because it can't do anything except what it says.
No servers. No accounts. No tracking. No tricks. Just a vault, locked by you, for you.
That's the whole idea. Everything else is implementation.
Your Passwords Deserve Better
Locka is built by Awan IGD as part of our mission to make useful, private technology free and accessible to everyone.