A browser is not a VPN. A forgotten App Lock passcode cannot be recovered, and that does not hide your IP address from sites you visit or from your network operator. Tracking protection is list-based and not absolute. The passcode is never stored. It becomes the key. If forgotten, data sealed under it is permanently inaccessible, by you or by us. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.
People write to support asking for a reset link the way they would for email. There is no link. There is no hash sitting in a table we could compare. The six-digit App Lock passcode is never stored. It becomes the key. Forgotten passcodes cannot be recovered. That sentence is not a policy we might relax for a nice customer. It is the mechanism. If we could open the lock without the code, anyone who pressured us could too.
App Lock with that passcode and Face ID is free for everyone in the shipping default. The irreversibility is part of the free door, not a Stealth Suite twist. This article is the honest version of a support conversation: what Face ID can still do, what reinstall cannot do, what the vault and the decoy cannot save, and how to choose a code you can live with. The feature itself is described in App Lock With Passcode and Face ID.
Why there is no reset
A conventional PIN verifier stores something: the PIN, a hash, or a token on a server that will email a reset. That design is convenient. It is also a copy of the secret, or a way to replace the secret, sitting somewhere other than your head. Private Browser Incognito has no accounts, no sign-in, and no app server for browsing. The App Store privacy label is Data Not Collected. There is no analytics SDK, no ads in the app, and no third-party SDKs. There is nowhere to send a recovery email from, and nowhere to store a verifier.
The passcode derives the encryption that seals what the lock is meant to protect. Without the digits, the sealed material does not unlock. We cannot “look it up.” We cannot scramble a new code onto an old key. Support can explain the design. Support cannot reach into the phone. If that feels severe, it is working. A private browser that forgot a history file but kept a master override would be telling two different stories.
Erase, Auto-Erase, panic, and self-destruct are also permanent. Erased data cannot be recovered, by you or by us. A forgotten key is the same ending reached by a different path: the bits are still on the device in a form you cannot open, or they are gone after you delete the app. Either way, we are not holding a spare.
What Face ID can and cannot save
If Face ID is enabled you can still unlock with it after you have forgotten the six digits. That is the remaining door. Use it, then set a new passcode you will actually remember. Face ID is a convenience on the free lock, not a second account we store, and not a cloud identity. If the sensor fails, if you disabled Face ID, or if iOS will not match, you are back to the digits. There is no third door.
Do not treat Face ID as a backup of the key. It is a way to type the key without typing. The key is still the passcode. If you turn Face ID off later, only the digits remain. If you forget the digits while Face ID still works, change the code the same day. Waiting until the sensor is unavailable is how people lock themselves out for good.
Wrong attempts at the lock screen are a lock problem. In Stealth Suite they can also become a timestamped break-in log, an optional Intruder Photo, or a self-destruct wipe, depending on what you turned on. None of those features recover a forgotten real code. Intruder Photo is off until enabled. Camera permission is asked when you turn it on, never at the lock screen. Local law still applies. Photos of failed unlocks will not email you the digits you lost.
Reinstall is a new app, not a recovery
Deleting Private Browser Incognito and installing it again lets you start fresh. You will set a new lock if you want one. You will not get the old tabs. Every tab is a private session in memory. There is no browsing history feature and no history file to import from iCloud. Vault files in Stealth Suite are AES-256, with no plain copy on disk, excluded from backups. Session erase does not clear the vault. Uninstall does. Panic does. A forgotten key with no Face ID path does, in practice: the files remain sealed or they leave with the app.
Keep a separate copy of anything irreplaceable before you depend on a vault that can vanish. That is also true of panic and of self-destruct’s optional vault wipe. The cipher name AES-256 is not a promise that we can reconstruct a file after the key is gone. For how that store is built, see An Encrypted Download Vault on iPhone.
Apple can refund a Stealth Suite purchase through the usual App Store process. A refund does not unseal a forgotten passcode. If a subscription lapses, protections you already enabled keep working and the vault stays accessible. A lapse is not a reset. The key is still the six digits you set.
Stealth Suite does not add a back door
Stealth Suite is optional Apple IAP: monthly $4.99, yearly $19.99 with a 7-day trial, or lifetime $49.99. It adds a decoy passcode, a panic code, a break-in log with optional Intruder Photo, self-destruct, the vault, and icon colors (Midnight, Ocean, Ember). Icon colors recolor the shield. They are not calculator, notes, or weather disguise icons. None of those extras stores the real key.
A decoy you remember opens a clean, empty browser. Real tabs stay hidden. The decoy does not unlock data sealed under a forgotten real passcode. If you can only remember the decoy, you can show an empty window. You cannot retrieve the real session. That is the same design described in Decoy Passcode: A Second Browser That Shows Nothing. Panic, if you still remember it, will wipe rather than recover. Do not type panic hoping it is a reset. It is the opposite.
Self-destruct after too many wrong guesses destroys saved tabs, and optionally the vault. Guessing your own forgotten code is how you might fire it. If you know you have lost the digits, stop guessing and use Face ID if it still works, or accept a fresh install. Guessing is not recovery. It is a way to empty the app on purpose or by accident.
How to choose a code you can live with
Pick six digits you will remember without a note in the same bag as the phone. Avoid obvious birthdays in a shared house. Avoid repeating digits because they are fast. Avoid a panic code or decoy that sits one key away from the real lock. If you must write a distinction down, put it somewhere that is not the lock screen and understand that the note is now a map.
The free product around the lock is still a forgetful browser: on-device Disconnect lists, one-tap erase, HTTPS-Only Mode, search with Google, Bing, DuckDuckGo, Wikipedia, or a custom engine, suggestions off until you ask. A forgotten passcode does not change those facts. It also does not hide your IP. Sites and the network operator still see what they saw. We do not claim fingerprint spoofing, Tor, a proxy, or IP hiding. The app is iOS only.
If you are deciding whether this design is acceptable, a compact table is more useful than hoping support will make an exception.
| Situation | What we can do | What we cannot do |
|---|---|---|
| Forgot the six digits, Face ID still on | Explain that Face ID can unlock so you can set a new code | Read or reset the old passcode |
| Forgot the six digits, Face ID off | Explain that reinstall starts a new app | Restore sealed tabs or vault files |
| Remember only the decoy | Explain that the decoy opens an empty browser | Use the decoy as a master key |
| Want a reset email | Explain that there are no accounts | Send one |
The 17+ rating still means unrestricted web access. You are responsible for what you visit and for using the app lawfully. The lock is for the person holding the phone. The missing recovery is for everyone else, including us. Choose a code you can remember, treat Face ID as a temporary path if you slip, and do not buy Stealth Suite expecting a back door. The key is yours. When it is gone, it is gone.
Frequently asked questions
Can Private Browser Incognito recover my passcode?
No. Nobody can, and that is deliberate. The passcode is never stored, not even as a hash. It becomes the key that seals data under App Lock. There is no reset, no recovery email, and no back door for us or anyone else. Forgotten passcodes cannot be recovered. Data sealed under a forgotten code is permanently inaccessible.
What if I forget my passcode but Face ID still works?
If Face ID is enabled you can still unlock with it, then change the six-digit passcode while you have a path in. Face ID is a convenience on the free lock, not a cloud identity. If Face ID is off and the code is gone, the sealed data stays sealed. Reinstalling lets you start a new app. It does not restore what the old key protected.
If I reinstall the app, do I get my tabs back?
No. Deleting and reinstalling starts fresh. Tabs live in memory as private sessions. There is no history file to import. Vault files are excluded from backups. Panic, erase, and a forgotten key all end in the same place for sealed data: it cannot be recovered, by you or by us.
Does Stealth Suite add passcode recovery?
No. Stealth Suite adds a decoy passcode, a panic code, a break-in log with optional Intruder Photo, self-destruct, an encrypted vault, and icon colors (Midnight, Ocean, Ember). It does not add a reset email or a stored copy of the real key. The real passcode is still never stored. A decoy you remember does not unlock data sealed under a forgotten real code.
Why is there no passcode reset email?
There are no accounts and no sign-in. There is no app server for browsing. The App Store privacy label reads Data Not Collected. A reset email would mean we held a way back in. The product refuses that. The six-digit code is the key. If we could email you a new one, someone else could too.