Put a lock on your cloud: Take the security of your data into your own hands
About this app
With Cryptomator, the key to your data is in your hands. Cryptomator encrypts your data quickly and easily. Afterwards you upload them protected to your favorite cloud service.
Cryptomator requires a license key, which you can obtain from https://cryptomator.org/android/
EASY-TO-USE
Cryptomator is a simple tool for digital self-defense. It allows you to protect your cloud data by yourself and independently.
• Simply create a vault and assign a password • No additional account or configuration needed • Unlock vaults with your fingerprint
COMPATIBLE
Cryptomator is compatible with the most commonly used cloud storages and available for all major operating systems.
• Compatible with S3- and WebDAV-based cloud storage services • Create vaults in Android’s local storage (e.g., works with third-party sync apps) • Access your vaults on all your mobile devices and computers
SECURE
You don't have to trust Cryptomator blindly, because it is open source software. For you as a user, this means that everyone can see the code.
• File content and filename encryption with AES and 256 bit key length • Vault password is secured with scrypt for enhanced brute-force resistance • Vaults are automatically locked after sending app to background • Crypto implementation is publicly documented
AWARD-WINNING
Cryptomator received the CeBIT Innovation Award 2016 for Usable Security and Privacy. We're proud to provide security and privacy for hundreds of thousands of Cryptomator users.
CRYPTOMATOR COMMUNITY
Join the Cryptomator Community and participate in the conversations with other Cryptomator users.
• Follow us on Mastodon @cryptomator@mastodon.online • Like us on Facebook /Cryptomator
Licensed under GPL-3.0-only, by Skymatic GmbH.
What's New in v1.12.3
Imported from the F-Droid repository index.
- - Fixed possible man-in-the-middle attack with tampered Cryptomator Hub vault config (GHSA-876q-q3mm-fcvj)
Version history
Mar 19, 2026 · 19.6 MB · Android API 26–35 · code 3030
Imported from the F-Droid repository index.
- - Fixed possible man-in-the-middle attack with tampered Cryptomator Hub vault config (GHSA-876q-q3mm-fcvj)
SHA-256 d5cb6c0bb40b5a82fe4ea5689599aa871bb725c25f0d6d1bde44120b696073b9
Oct 10, 2025 · 19.6 MB · Android API 26–35 · code 3020
Imported from the F-Droid repository index.
SHA-256 a9cf6137960d710ed8dd5f229787e0431eddf221eaaaf849661f2eea2d2a9209
Oct 5, 2025 · 19.6 MB · Android API 26–35 · code 3016
Imported from the F-Droid repository index.
SHA-256 e6ed29420abd4854a09a376f0390565c84bead5ef713aa80d679605cc628cb2d
Will it run on your device?
78%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be org.cryptomator.lite is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 1.12.2 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Cryptomator first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Cryptomator, and a listing is removed when the evidence for it stops holding up.
Get Cryptomator
Every source we list for org.cryptomator.lite is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
d5cb6c0bb40b5a82fe4ea5689599aa871bb725c25f0d6d1bde44120b696073b9
Signing certificate
f7c3ec3b0d588d3cb52983e9eb1a7421c93d4339a286398e71d7b651e8d8ecdd
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.