A private file does not have to remain loose in Downloads. OGAD (Off Grid AI Desktop) lets you store a file as an attachment inside its encrypted local Vault. Give the entry a clear title, unlock the vault when you need it, and retrieve the file on your own computer.
Download OGAD for Mac or Windows

What would you like to do with Off Grid AI?
Have a feature or use case you would like us to support? Tell us what you want to do and which device you use.
Write to support@offgridmobileai.co, join our Slack community, or talk to us on Reddit.
This is useful for a small private document, a licence file, or a configuration file you want to keep in a locked store. Vault is a Pro feature. It does not require a cloud storage service or an AI model to add and retrieve files.
What kinds of files can you keep there?
The File entry stores the selected file’s bytes inside the encrypted vault. The interface can preview supported text and images. Other file types can be saved back to disk when you need to open them in another app.
The file limit is 25 MB per attachment in the release covered here. Use this for small sensitive files, rather than treating it as a full-disk archive or a place for large media collections.
| File use | Why a vault entry helps |
|---|---|
| A software licence file | Keeps it with a title you can search later |
| A private text configuration | Stores an encrypted copy outside the working project folder |
| A small reference document | Gives it a deliberate unlock-and-retrieve path |
| A personal image | Keeps the stored copy inside the encrypted database |
The workflow is included in OGAD 0.0.51, including the shipped Windows Pro package.
Adding a file makes a vault copy
When you choose or drop a file into a new entry, OGAD stores a copy of its contents in the vault. It does not automatically remove the original file from Downloads, your project folder, or a synced folder.
That is an important part of the workflow. First verify that you can reopen the vault entry and retrieve the expected file. Then decide what to do with the original and any other copies under your own file-retention needs.
A local encrypted copy does not erase earlier copies from backups, cloud folders, email attachments, or other computers. Keep the scope of the change clear: you are choosing where this copy is stored.
Getting started with one file
Set up Vault, then test the attachment flow with a harmless small file. Once you know how it behaves, add the file you intended to protect.
- Open Vault with Pro active.
- Create a master password if needed and store the recovery phrase safely outside the vault.
- Choose New entry → File.
- Enter a title and choose a file, or drag the file into the form’s drop area.
- Select Save.
- Lock the vault, unlock it again, and open the saved entry.
The selected file’s name and size are shown in the entry. Check them before saving, especially when several similar versions exist.
Do not use the entry title for sensitive contents. A title such as “Private project configuration” can identify the file without exposing a secret value in the list.
Preview or retrieve the saved file
Open the file entry after unlocking. Supported text and image formats can appear in the preview. For other formats, use the file’s download control and choose where to save it.
A text preview can be shorter than the full file. The preview is capped so a large text attachment does not overwhelm the interface; downloading retrieves the stored attachment itself.
When you save a file outside the vault, that new copy is no longer protected by the vault’s encryption. The destination folder, operating-system permissions, and any folder sync now apply to it. Save it somewhere appropriate for its contents.
This is also why the first verification should use harmless data. You can learn the difference between previewing inside the vault and creating a normal file outside it without spreading sensitive copies.
What does the encryption cover?
The stored vault database is encrypted in KDBX form using your master password and a device-derived key. The attachment is held inside that database rather than merely listed as a link to its original location.
When the vault is unlocked, the app must access the attachment to preview or retrieve it. Use Lock vault when you finish. Do not assume that closing the preview locks the database.
The vault is not a defence against every action on an already compromised, unlocked computer. Keep the computer and account protected, and treat retrieved files as normal sensitive files outside the vault.
Keep a usable recovery path
Store the recovery phrase separately and retain a suitable backup of the vault data and required recovery material. A phrase cannot recreate a missing database or missing attachment.
The device factor also means a copied database is not simply a password-only file you can unlock anywhere. Use the recovery workflow when moving or restoring it with the necessary data.
Before replacing an older stored file, make sure you know which version you need. This guide does not assume automatic file watching, version history, or that changing the original file updates the vault attachment.
Put one sensitive file behind a deliberate unlock
Download OGAD, test a small File entry, and verify that it survives a lock-and-unlock cycle. Then add the private file you want to keep there. You get an encrypted local copy with a clear retrieval path, without requiring cloud storage.