Sanctum Support
Last updated: 2026-09-18
Sanctum is a photo and video vault for iPhone and iPad. It encrypts media before syncing through your iCloud account.
Contact support@sanctum.photos or use the contact form. Sanctum support reviews abuse reports within 7 days of receipt. Resolution can take longer if we need more information.
Report Content or a Person
Use a shared album’s report controls to report media, a comment, a reaction, the album, or a participant. Participant controls are available through Members.
- Open the relevant Report action.
- Choose a reason and explain the concern in 10–4000 characters.
- Add a reply email if you want support to contact you.
- Choose whether to include the offered text or image evidence.
- Review the recipient and complete submission, then send the report.
The preview identifies support@sanctum.photos and shows the report ID, date, reason, explanation, target details, and any selected evidence. Text evidence is optional. An optional reduced JPEG image is limited to 256 KiB; the app does not send a video file or your whole vault.
Cloudflare and Brevo process the submission and forward it to support. Support and these providers can read what you send. The report does not include your vault password, recovery phrase, or encryption keys. It is not posted to the album or automatically sent to the reported person.
Check Report Status
“Accepted for forwarding” means our email service accepted the submission. It does not confirm inbox delivery or human review. Keep the report ID for follow-up.
If submission fails, the app keeps the report encrypted for your vault on this device. Retry the existing report so its ID and evidence stay the same. Pending reports remain available after you leave the album or a member is removed.
You can delete a locally saved report. Deletion stops future retries but cannot recall a request already sent or remove the copy in support’s inbox. To ask about delivery or request deletion of that copy, email support with the report ID.
Without a reply email, support cannot ask you for details or send a response. We retain resolved reports, attachments, and correspondence for 90 days after resolution, unless law requires longer retention.
Reports Created in Older Versions
Older reports may remain inside a shared album and be readable by its participants. They are not automatically sent to support. Older unsent reports become encrypted drafts and require your review before submission through the private support flow.
Archived album reports remain available in Settings → Archived album reports after sharing ends. These archives are not support submissions.
Review Shared Media Before Publication
New photos and videos from members need the album owner’s approval. Pending uploads are encrypted for their author and the owner. Other members can see them only after approval. Your personal original stays in Library.
- Owners: open the album menu and choose Review Submissions. Open the full photo or video, then approve or reject it.
- Members: choose My Submissions to check progress. A rejected upload stays unpublished. If the album key changed, use the offered resubmission action after checking your access.
- Owners publish their own media directly and must follow the same content rules.
For an older album, open Members → Upgrade sharing and read the confirmation. All participants need an updated app. Upgrades preserve published media and verified members from the current private-invitation format. Older public-invitation albums require fresh invitations. Outstanding links, comments, reactions, and member display names reset.
Block Someone or Leave an Album
Open Members in the shared album and use the person’s blocking action. Blocking hides their shared media, comments, reactions, and profile on this device. It also hides joined albums owned by that person. Your personal Library remains available.
Blocking alone does not remove anyone’s album membership or revoke their access. If you own the album, Block & Remove also attempts to remove the person. Check the result and retry removal if it fails.
If another person owns the album, you can block them and leave the album. Use Settings → Blocked Users to unblock a person. Blocks apply on this device and do not synchronize to your other devices.
Removing a member rotates the album key. It cannot erase screenshots, exports, or copies the person already kept. Leaving an album also does not retract contributions other members already received.
Support reviews the information you choose to provide and helps with these controls. Support cannot inspect encrypted albums, centrally ban an account, or remotely delete another person’s copies.
Password and Recovery
Your vault uses a Sanctum password, separate from your Apple account password and device passcode. You can enable Face ID or Touch ID in Settings for everyday unlocking.
After unlocking, open Settings → Show Recovery Phrase and store the phrase securely. Anyone with the phrase and your encrypted data may be able to open your vault. Never send the phrase to support.
If you forget the password, choose Use recovery phrase on the lock screen. Follow device authentication, enter your saved phrase, and select Unlock with phrase. The app can check the phrase against local media when such media is available. A new installation without local media cannot establish that match immediately.
If biometric unlock still works, unlock the app and save your recovery phrase before changing devices or authentication settings. Reinstalling requires both available encrypted data and access to the matching key, through synced key material and your password or your recovery phrase. Support cannot replace a lost key.
Import, Capture, and Export
Importing copies media into Sanctum. Review the Delete originals choice separately, and check Photos and Recently Deleted if you want to remove the source copies.
Sanctum’s camera saves captures into the vault without adding them to Photos. Capture, editing, playback, and export can still create temporary readable files on your device. The app attempts to clean them up after use.
Personal media shares a vault encryption key, with fresh random nonces for encryption. Shared albums use separate album keys. Membership, permissions, identifiers, and other technical sharing metadata are not all encrypted.
Exports through the system share sheet create readable copies outside your vault. Encrypted .sanctum bundles remain protected by the export passphrase. Check your destination and sharing settings before exporting.
Sync and Missing Media
- Check your internet connection, iCloud sign-in, and available iCloud storage in Apple Settings.
- Open Settings → iCloud Backup & Sync in Sanctum.
- Use Back up now or Force Sync Now, then check the result.
- Use Re-verify iCloud backup to check recorded backups.
Keep the app installed if it reports media that is not backed up. Resetting sync or reinstalling can lose content that exists only on this device.
For a missing shared album, confirm that you accepted the invitation and that the owner still lists you as a member. Check Settings → Pending invitations and your block list. A blocked owner’s album is hidden until you unblock that identity.
If an original remains unavailable, contact support with the visible error and app version. The advanced Recover unavailable originals tool checks for usable iCloud copies and preserves files it cannot recover. Check its result before taking further action.
Delete Items or Erase the Vault
Deleting an item requests deletion through the app and iCloud synchronization. Shared views update as devices sync. Completion depends on connectivity and successful synchronization.
Expiring comments depend on app activity and successful cleanup. Expiry is not a guarantee that every cached or exported copy disappears at the same instant.
Erase All Data
This removes your private vault and owned shared albums from this device and the current iCloud account. It also leaves albums owned by others.
- Unlock Sanctum and open Settings → Erase All Data.
- Read both confirmations, then choose Erase Everything.
- Keep the app installed, open, and connected until Erasure complete appears.
- If cleanup pauses, follow the message and choose Retry erasure.
- After completion, close Sanctum from the app switcher and reopen it to set up a new vault.
Keep Sanctum closed on other devices until their local app data is cleared. Those devices can retain copies and upload them again. The erasure request belongs to the iCloud account that started it.
Recover Originals During an Incomplete Erase
If Recover remaining originals or Pause and recover originals is available, you can authenticate and export personal originals still on this device. iCloud and sharing stay paused.
Recovery does not undo cloud deletion or finish erasure. It excludes shared media and becomes unavailable after local files and keys are removed. Close recovery and follow the erasure screen to continue cleanup.
Uninstalling alone does not erase iCloud content. Erasure also cannot remove copies retained by other participants, exported files, or messages already sent to support. Email support to request deletion of support correspondence.
Contact Support
Use this form for technical issues, abuse reports, privacy questions, or data requests. The form sends your name, email, topic, and message through Cloudflare and Brevo to support@sanctum.photos. See our Privacy Policy.
You can email support@sanctum.photos directly if the form is unavailable. If you refer to an in-app report, include its report ID.
Armlab BV · Enterprise no. BE0899277201 · Belgium