Join us

Your keys, your control

Local encryption, your master password, and why a copy of the app's data alone cannot unlock your funds.

Merlin Guild is built so that your wallets are usable only by you, on your device, with your master password. This page explains the protections you can rely on, in plain language.

Encrypted on your device

Your wallet secrets are encrypted locally. The plain, usable form of a private key exists only briefly in memory while you are actively using it, and is discarded when the session locks.

Your master password is the key

The app uses your master password to unlock your vault, and that password is never stored anywhere. Because of this, a copy of the app’s data on its own is not enough to access your funds: without your password on your device, the data stays locked.

Recover access if needed

The app provides a way to recover access so you are not permanently locked out by a forgotten setup, while still keeping your secrets protected. Keep any recovery information you are given somewhere safe.

It works offline

Merlin Guild does not depend on calling out to a server to let you in. It does not phone home or silently change things behind your back; you stay in control of when anything happens.

What this means for you

  • A stolen data copy is not enough: your password and your device are both required.
  • Nobody can reset your password for you: that is the cost of nobody else holding it; keep it safe.
  • Secrets are short-lived in memory: locking the app clears them.

Good practices

  • Choose a long, unique master password and store it in a password manager.
  • Keep any recovery information offline and separate from your everyday machine.
  • Lock the app when you step away.