Help

How can we help?

Answers to the most common questions about your Vault, signing in, monitoring, and backups. For step-by-step product guides, see the docs.

Your Vault and encryption

Your hosts and SSH credentials are sealed in a Vault that is encrypted on your device. The Vault is protected by a Vault password that only you know — it never reaches our servers, so we cannot read your credentials and we cannot recover them for you.

Because the Vault password is the encryption key, it is the only thing that can unlock your synced hosts. When you set up your Vault you are shown a one-time recovery key: save it somewhere safe and offline. If you ever forget your Vault password, the recovery key is the only other way back in.

If you lose both your Vault password and your recovery key, the data in your Vault is permanently lost. This is by design — it is what keeps your credentials private even from us.

Signing in with Google or Apple

You can sign in with email and password, Google, or Apple — they all lead to the same account (we match by your email address), so your hosts follow you across sign-in methods.

Signing in with Google or Apple proves who you are, but it does not hand the app your Vault password. So the first time you sign in a new way, the app asks for your Vault password (or recovery key) to unlock your hosts. If your host list looks empty after a social sign-in, it just means the Vault is still locked — enter your Vault password to unlock it.

Changing or resetting your password

Changing your login password does not change your Vault password — they are separate. Your Vault stays unlocked and your hosts are unaffected.

If you forget your login password, you can reset it by email as usual. Resetting your login password does not touch your Vault; you will still need your Vault password (or recovery key) to unlock your hosts.

Monitoring your hosts (Pro)

Monitoring is configured per host. Open a host's menu (the three-dot button in your host list, or the host panel on the Activity screen) and choose Configure monitoring to set the check interval, which containers to watch, and the alert rules for that host.

Server-side monitoring connects to your host on a schedule even when the app is closed. Because our service has to make that connection for you, the monitoring credential you provide is stored so that our infrastructure can decrypt it at connection time — unlike your Vault, which we can never read. Only hosts you explicitly enable for monitoring are handled this way.

Scheduled backups (Pro)

Define backup jobs per volume with a schedule, a destination, and a retention window. You can run any job on demand and watch its progress from the app. Recent backup activity and status also appear on your dashboard.

Still need help?

Email us at support@dockerhq.app and we'll get back to you. For legal details on how your data is handled, see the Privacy Policy and Terms of Service.