WatchVault

Encrypted file vault on a smartwatch.

The watch acts as a dumb encrypted carrier while all cryptography and plaintext handling occur exclusively on the PC. Pairing between the two devices is established via a 6-digit code valid for five minutes. The software is complete, tested, and verified on the Amazfit T-Rex 3 as of release 0.20.3.

Private project, no store release — sideload via the Zepp App Developer Mode.

Stack
Python 3 PC tool (age encryption, scrypt KDF, local HTTP server, pipx CLI) · Zepp OS mini-program (API level 4.0, @zeppos/zml, PIN UI, sandbox storage) · JS side-service bridging HTTP ↔ BLE file transfer
Timescale
14-phase development process, 26.05.2026 → 22.09.2026, verified on the Amazfit T-Rex 3.
Role
Solo build — design to deployment.
Scope
Watch: 6,829 lines of JavaScript, 206 tests · PC: 2,453 lines of Python, 189 test functions (as of 22.09.2026).
WatchVault home screen on the Amazfit T-Rex 3 — real device photo, release 0.20.3.

Asymmetric Security Model

The watch functions as a "dumb" encrypted carrier, while the PC serves as the only location holding key material and plaintext. The system utilizes age encryption with scrypt-based derivation to secure the data. If the watch is compromised, only the age ciphertext is exposed — the passphrase itself is derived via scrypt and never touches the watch.

PIN entry screen on the watch, gating the encrypted file vault.
PIN gate on the watch — the only thing an attacker with the device gets to see.

Multi-hop Transport Chain

The transport chain consists of the PC, the Zepp app side-service on the phone, a BLE transfer, and the watch. The control plane maintains four distinct verbs—STATUS, LIST, PAIR, DELETE—while the binary file path runs separately over ZML transfer. Both directions include a 120-second timeout to ensure the process reports clearly rather than hanging.

Sync-completed confirmation on the watch after a file transfer over the PC-to-phone-to-BLE-to-watch chain.
Sync completed on the watch, end of the PC → phone → BLE → watch chain.

Engineering for a Round Display

Native OS scrolling with inertia replaces the previous pagination system. The SCROLL_LIST widget was deliberately rejected because it caused blanking and displayed remnants of previous pages on real hardware. Rows and headers are indented along the circle’s chord so nothing is cut off at the round edge of the display. Touch targets are at least 44 pixels throughout.

Code, Tests and Bug Fixes

The watch code comprises 6,829 lines of JavaScript, while the PC tool consists of 2,453 lines of Python. The watch test suite contains 206 tests and the PC suite includes 189 test functions. A TOCTOU error was identified and fixed where two concurrent uploads of the same blob ID could overwrite each other. A widget leak was also resolved where the file list created new widgets on every page visit without disposing of the old ones.

Blob overview in the PC tool, the storage layer targeted by the fixed TOCTOU error.
Blob overview in the PC tool — the surface where the concurrent-upload TOCTOU bug lived, now fixed.

PC-Side Concurrency and Permissions

Concurrent uploads of the same blob ID are resolved atomically via os.link, with the second attempt receiving an HTTP 409. Aborted uploads are discarded and never committed to the system. Directory permissions are strictly enforced at 0700.

Maturity and Verification

Distribution is available via Zepp App Developer Mode under ID 255971, version 0.20.3. The software is complete, tested, and verified on the Amazfit T-Rex 3. This status represents a specific device verification and not a long-term trial.

Get in touch

Interested in a walkthrough?

The source code is private, but I am happy to walk through the architecture and the code on a call — NDA-friendly.

Contact