Create and protect an account
- Generate a random account number on the sign-up page; no name, email address, phone number, or identity document is required
- Copy the complete 16-digit number and store it away from the device
- Accept the Terms and acknowledge that Cloak cannot recover the number
- Sign in, choose a plan, and download the client when it is available for your platform
Private Drive workflow
- Choose folders to synchronize and confirm Private Drive is enabled
- Wait for the transfer state to show that the initial upload is complete
- Test a download and a version restore before relying on the vault
- Set a trash-retention period and keep a separate backup
Connect an S3 client
After Object access is approved, create a narrowly scoped access key and save the secret when it is shown. Configure the S3 endpoint shown in your access confirmation with AWS Signature Version 4 and path-style addressing.
Choose the right encryption
Use Private Drive when you want Cloak to receive only encrypted file content and names. Use Object for S3 compatibility. Add client-side encryption to Object when the gateway must not receive plaintext.
Troubleshooting information
When contacting support, include the approximate time, client version, operating system, affected feature, and a request identifier if one is displayed. Remove file paths and personal data from logs. Never send your full account number, recovery key, secret access key, share password, or unencrypted file.