Who controls the keys?
The user controls the recovery phrase or imported private key. Aperture does not maintain a custodial copy that can authorize transactions or reset wallet ownership.
Self-custody, without euphemisms
Aperture is a self-custody crypto wallet for iPhone and iPad. The user controls the wallet credentials; Aperture cannot move funds, reverse a transaction, or recover a lost recovery phrase.
The label is useful only when the product explains who can authorize a transaction, where secrets are stored, and what happens when a device is lost.
The user controls the recovery phrase or imported private key. Aperture does not maintain a custodial copy that can authorize transactions or reset wallet ownership.
Sensitive wallet material is handled through Aperture’s iOS Keychain vault with this-device-only protection where applicable. The local wallet database stores opaque Keychain references rather than recovery phrases or private keys.
The app constructs and signs an authorized transaction locally. The resulting signed transaction can then be sent to the selected blockchain’s infrastructure for broadcast.
Public addresses, transaction data, balance queries, market requests, and signed transactions may cross the network boundary as required by the feature. Private signing material does not need to accompany those public requests.
Aperture cannot recover a lost recovery phrase, private key, or BIP-39 passphrase. Recovery depends on the method the user deliberately preserved before loss or replacement.
Aperture cannot reverse or guarantee reversal of a confirmed blockchain transaction. Recipient, network, asset, amount, and fee review must happen before authorization.
The best wallet is the one whose security model, network support, recovery choices, and operational limits you understand and can verify.
Each recovery method protects against a different failure and introduces its own responsibility.
| Recovery phrase | Portable deterministic recovery. Anyone with the phrase—and the optional BIP-39 passphrase, if used—can derive the wallet. |
|---|---|
| Private key | Network-specific import for supported credential formats. It may restore only the account controlled by that key, not a complete multi-network wallet. |
| Encrypted iCloud backup | An optional encrypted backup in the user’s iCloud environment. It is not a server-side Aperture recovery account. |
| Direct iPhone transfer | An optional local encrypted transfer between compatible iPhones without using an Aperture storage server. |
Plain-language answers about non-custodial and self-custodial wallets.
The terms are commonly used for software where the provider does not control the credentials needed to move funds. The concrete authorization and recovery model matters more than the label.
No. Aperture can help explain documented recovery routes, but it cannot recreate a lost recovery phrase, private key, or BIP-39 passphrase.
No. A wallet can keep signing keys under the user’s control while still using internet services for public balances, prices, fee estimates, history, and transaction broadcast.
No. It changes who controls authorization. Users must still protect credentials, verify recipients and networks, avoid malicious tokens and phishing, and maintain a recovery method they understand.
Go deeper with the product pages, Journal explainers, and machine-readable sources that support this page.
Download Aperture from the official App Store listing, verify the product identity, and understand your recovery method before moving funds.