That’s a fair concern. The Trash in Xsilent is intentionally kept inside the same protected encryption boundary as the private vault rather than being treated as a plain recovery folder or cloud-backed holding area. I deliberately avoid publishing the exact key-management layout or where individual key material is anchored, because those implementation details are part of the app’s security design rather than something users need to rely on. The important property from the user’s perspective is that items in Trash remain encrypted throughout the recovery window and are not intentionally exposed as plaintext outside the vault. So yes, key handling is treated as part of the threat model — but I prefer to describe the security guarantees publicly rather than disclose the internal key topology