Paranoid, offline file encryption with XChaCha20 and Argon2id.
About this app
Picocrypt-NG encrypts files locally — a community-maintained continuation of Picocrypt. No accounts, no cloud, no telemetry, no network access (the app does not request the INTERNET permission).
XChaCha20 for encryption, with the key derived from your password by Argon2id. Every volume is authenticated, so tampering or corruption is detected on decryption.
Features:
- Encrypt a single file, multiple files, or a folder - Optional keyfiles, with an option to require them in a fixed order - Paranoid mode: extra cipher cascade and harder key derivation - Reed-Solomon error correction to recover volumes from limited corruption - Deniability mode: the encrypted volume appears as random data - Optional compression - Comments stored with the volume - Optional verify-before-write integrity check - Long operations continue in a foreground service when the app is backgrounded
Volumes are cross-platform with the desktop app (Windows, macOS, Linux). A multi-file or compressed volume contains a single .zip inside; Android saves it without extracting.
Free software under GPLv3. The Android app is built from source: the native library is compiled from the Go sources in this repository, with no prebuilt binaries committed.
Licensed under GPL-3.0-only, by Picocrypt-NG.
What's New in v2.18
Imported from the F-Droid repository index.
- v2.18
- - Android release builds are prepared for F-Droid source and reproducible-build verification.
- - Updated Go image dependency with TIFF decoder security fixes.
Version history
Jul 1, 2026 · 11.2 MB · Android API 24–36 · code 218004
Imported from the F-Droid repository index.
- v2.18
- - Android release builds are prepared for F-Droid source and reproducible-build verification.
- - Updated Go image dependency with TIFF decoder security fixes.
SHA-256 21e805e4e3a5f7138ce2ba9015b615910244adf540118cd51b91a386628b85b5
Jul 1, 2026 · 10.8 MB · Android API 24–36 · code 218003
Imported from the F-Droid repository index.
SHA-256 eb55892821559a3a10dc6ddda8cfdad1cfa9b7c06e3f3121568917d3378cfb88
Jul 1, 2026 · 10.9 MB · Android API 24–36 · code 218002
Imported from the F-Droid repository index.
SHA-256 d84d18f67501ccb204985a844ed51cbc882e0314d78c3970afaf0daa177c6c0c
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be io.github.picocrypt_ng.picocrypt_ng is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 2.18 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Picocrypt-NG first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Picocrypt-NG, and a listing is removed when the evidence for it stops holding up.
Get Picocrypt-NG
Every source we list for io.github.picocrypt_ng.picocrypt_ng is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
21e805e4e3a5f7138ce2ba9015b615910244adf540118cd51b91a386628b85b5
Signing certificate
e2f2a971231aa0b86882c63b87b689c71632c6d55168b1ce856952d07f6172b7
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
More Security Privacy apps
More from F-DroidReport a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.