Sep 15, 2026 · by Gerhard Petermeir · View source

PhraseVault 3.0

Now lock one sensitive phrase at a time with a PIN

PhraseVault 3.0

Editorial analysis

The snippet manager your support desk actually needs

Cross-border sellers live inside text boxes. Amazon Buyer-Seller Messaging replies, Shopify order-note macros, Temu dispute templates, TikTok Shop affiliate outreach DMs, supplier emails in three time zones — the same 60 sentences get retyped thousands of times a month, and every retype is a small chance to fat-finger a tracking number, paste the wrong refund policy, or leak a warehouse address into the wrong thread. So when a tool like PhraseVault ships a version that lets you PIN-lock a single sensitive phrase instead of the whole vault, that’s not a productivity-tool footnote. It’s a governance primitive for the messiest part of your operation: the copy-paste layer.

What PhraseVault 3.0 actually is

PhraseVault is a local-first text expander and snippet manager for Windows and macOS, built by Gerhard Petermeir under the SPQRK handle. This is the third Product Hunt hunt for the product — the prior launches landed on September 24th, 2024 and again on February 21st, 2026 — and 3.0 is being pushed with a 20% discount auto-applied through the hunt window, no code required.

The headline change in 3.0 is narrow and, for once, well-scoped: you can now lock one sensitive phrase at a time with a PIN, rather than choosing between a single vault-wide password or leaving everything in the clear. The app stays local, ships as source-available, and runs on Windows and macOS. That’s the whole pitch. No cloud sync, no team seats, no AI layer bolted on top.

The most useful signal in the whole thread isn’t from the maker — it’s from reviewer Gal Dayan, who nailed the design tradeoff in one paragraph: “most snippet managers make you choose between one vault-wide password that gets annoying to unlock constantly, or leaving everything in the clear. Locking just the bank details and leaving everyday replies and SQL snippets frictionless is a much better tradeoff.” Dayan also flagged the obvious gap — there’s currently no way to see that a locked phrase exists without unlocking it, so locked entries just vanish from search results instead of showing a placeholder.

And then there’s the unanswered question. Blair asked, four hours before this scrape: “Is the phrase locked with a PIN encrypted when saved, or is it only hidden from view on the screen?” As of the source, that question has no reply from the maker. Hold that thought — it matters more for cross-border operators than for the average Product Hunt browser.

Why this category matters more to sellers than to developers

The copy-paste layer is where your compliance lives

Most operators I talk to have a stack for everything except the text they actually send. They’ve got Helium 10 or Jungle Scout for research, Klaviyo or Omnisend for lifecycle email, Gorgias or Zendesk for support tickets, Loop or Returnly for returns. All of that is process. The snippet library is content — and content is what creates liability.

Think about what actually sits in a mature seller’s snippet vault:

Half of that is fine to paste into a chat window in a co-working space. The other half is not. A vault-wide password model forces you to pick a lane for everything, which is why so many operators end up with the worst outcome: no lock at all, everything in the clear, and a bank_details.txt sitting in a notes app.

Where the math breaks

The per-phrase PIN model has a real cost, and it’s not the PIN itself. It’s the interaction tax. Every locked phrase you insert now costs you a keystroke sequence plus a PIN entry, and that friction only pays for itself if the phrase is (a) genuinely sensitive and (b) used rarely enough that you’re not unlocking it twenty times a day.

For a support desk sending 300 order-status replies a day, locking the order-status macro is pure overhead. For a founder who pastes their Payoneer details into a supplier email twice a week, the PIN is basically free. The right mental model is: lock the credentials, not the conversation. If you find yourself unlocking the same phrase more than a handful of times per shift, it shouldn’t be locked — it should be behind a different control entirely (a password manager, or a policy that says only the finance lead sends bank details at all).

The encryption question is not pedantic

Blair’s unanswered question is the one I’d want answered before putting anything real into this. A PIN that gates visibility in the UI and a PIN that derives a key for encryption at rest are completely different security postures. In the first case, anyone with file-system access — a shared Mac in a fulfillment center, a laptop that gets stolen, a contractor you gave a login to — can read the locked phrase by opening the underlying store. In the second, the PIN is load-bearing.

The maker’s framing (“lock one sensitive phrase at a time with a PIN”) doesn’t distinguish between the two, and the review thread doesn’t resolve it. For a source-available app, that’s actually an advantage: you don’t have to take anyone’s word for it. You can read the code. But until you do, treat the lock as a UI convenience, not a security boundary, and don’t put anything in PhraseVault that you wouldn’t be comfortable seeing in a screenshot.

How it stacks up against the incumbents

The obvious comparison, and the one the reviewer made, is TextExpander. TextExpander is the category’s default answer: subscription-priced, cloud-synced by default, team-oriented, and mature. If you’re running a five-person support team across Manila and Lisbon and you want shared snippet libraries with permission tiers, TextExpander is probably still the right call, and PhraseVault isn’t trying to be that.

The other comparisons worth naming:

  • Espanso — free, open source, cross-platform, and the closest thing to a philosophical sibling. Espanso’s configuration is YAML-first, which is great for engineers and miserable for a VA who just wants to paste a return label link.
  • aText and Alfred snippets — the macOS-native camp. Fast, cheap, deeply integrated into the OS, and essentially Windows-hostile. If your team is split across Mac and Windows, you’re maintaining two systems.
  • Raycast snippets — excellent if you already live in Raycast, but it’s a feature of a launcher, not a product with its own security model.
  • Password managers as a workaround — plenty of operators stuff sensitive templates into 1Password or Bitwarden and just accept the clunky insertion flow. That’s the real incumbent PhraseVault is competing with for the sensitive half of the vault, and it’s a much harder fight than the TextExpander one, because password managers already have a credible answer to Blair’s encryption question.

Where PhraseVault’s positioning is genuinely differentiated: local-first, source-available, one-time-feel pricing (with a hunt discount rather than a mandatory subscription), and Windows + macOS parity. For a solo operator or a two-person DTC brand, that’s a coherent package. For a 40-person agency running shared inboxes, it’s the wrong shape.

Why Amazon sellers should care more than Shopify ones

Shopify merchants mostly talk to customers through a branded helpdesk, and the helpdesk owns the macro library. Amazon sellers don’t have that luxury. Amazon Buyer-Seller Messaging is its own walled garden with its own rules, and the templates you send through it are subject to scrutiny in a way that a Shopify order-confirmation email simply isn’t. Get the language wrong and you’re looking at a policy violation, not a bad CSAT score.

That asymmetry cuts two ways. It means Amazon sellers have a stronger reason to want a curated, version-controlled snippet library — and a stronger reason to be nervous about where that library lives. A snippet manager that stores your pre-cleared messaging templates in plaintext on a shared warehouse PC is a different risk profile than one storing your Shopify discount codes.

Where a snippet vault fits in the tooling stack

If you’re already running an automation layer — Zapier, Make, or a native Shopify Flow setup — you might reasonably ask why you need a text expander at all. The answer is that automation handles triggered messages and snippets handle improvised ones. The order-shipped email fires automatically. The “hey, my package says delivered but it’s not here” reply does not. That second category is where the volume is, and it’s where a snippet library earns its keep.

What cross-border sellers can borrow from this

Three things, and none of them require you to buy PhraseVault.

First, segment your snippet library by sensitivity, not by topic. Most operators organize macros by function — “shipping,” “returns,” “affiliates.” That’s the wrong axis. Organize by blast radius: what happens if this string ends up in the wrong hands or the wrong thread? Credentials and payment details go in one bucket. Policy language goes in another. Casual replies go in a third. Once you’ve done that sort, the tooling question answers itself.

Second, version-control your compliance-facing copy. Your Amazon messaging templates and your refund language are legal artifacts. They should have a changelog, an owner, and a review cadence. Most sellers update them reactively, after a policy warning, and then can’t remember which version was live when a dispute was filed. A snippet manager with a local store at least gives you a file you can back up and diff.

Third, treat the PIN as a policy tool, not a security tool. The most valuable thing about per-phrase locking isn’t the cryptography — it’s the signal. A locked phrase tells a new hire “this is not for you to send.” That’s organizational communication, and it’s worth having even if the underlying store turns out to be plaintext.

Where my judgment says it falls short

The honest read: PhraseVault 3.0 is a well-scoped improvement to a niche product, and the hunt thread surfaces two unresolved issues that matter.

The first is the encryption ambiguity. Until the maker answers Blair’s question — and ideally documents the storage model — anyone storing payment details or credentials in PhraseVault is making an assumption. “Source-available” is a partial mitigation, but it shifts the burden onto the operator to audit code, which most sellers won’t do.

The second is the discoverability gap Dayan flagged. Locked phrases disappearing from search results is a real usability problem in a tool whose entire value is recall. A placeholder result that says “locked phrase — unlock to view” costs nothing to implement and would meaningfully reduce the “wait, did I delete that?” panic.

Beyond the thread: there’s no team tier, no shared vault, no audit log of who unlocked what. For a solo operator that’s fine. For any seller with a support team larger than two, the lack of an unlock audit trail is a governance hole — you can’t answer “who accessed the bank details last Tuesday,” which is exactly the question you’d need to answer in a fraud investigation.

And the pricing model deserves a caveat. A 20% hunt-window discount is a launch tactic, not a business model. Before you migrate a real library into any snippet tool, know what it costs in month thirteen, not just in launch week.

What I’d watch / test next

This week, do three things.

Audit your own snippet library before you evaluate any tool. Open whatever notes app or shared doc currently holds your macros and tag every entry as public / internal / sensitive. If the sensitive bucket is bigger than five entries, you have a governance problem that no text expander will solve on its own.

Ask the encryption question directly. If you’re considering PhraseVault, post in the hunt thread or reach the maker through the product page and get a straight answer on whether the PIN derives an encryption key or just gates the UI. If the answer is “just gates the UI,” decide accordingly — and consider keeping credentials in 1Password or Bitwarden where the security model is documented.

Test the friction math on your highest-volume macro. Install PhraseVault, lock your most-used sensitive phrase, and count how many times you unlock it in a single shift. If it’s more than five, the per-phrase PIN model is wrong for that phrase — either it isn’t actually sensitive, or it needs a different control. That single test will tell you more about whether 3.0 fits your operation than any feature comparison will.

Ready to Create Your Own?

Join thousands of brands creating high-performing video ads with VEONIB. No editing skills required.

Start Creating for Free