Hello ligu
If you tab on a file it is downloaded and the encrypted version is cached. So you don't have to download it again if you have made no changes to it. These files are stored on your external storage (mostly the SD-Card). You can find it by browsing to /sdcard/Android/data/com.boxcryptor.android/cache/crypt.
After your file is downloaded BoxCryptor decrypts the file and stores the decrypted file in /sdcard/Android/data/com.boxcryptor.android/cache/plain so that other apps can open it. After the other app is closed BoxCryptor deletes the decrypted file from the plain cache. So your files are only stored decrypted while it is opened.
Your password can not be restored in any way. If you don't let BoxCryptor remember your password you always have to type in your password when BoxCryptor starts. Remember: Pressing the Home button does not quit an app. So you should "Exit" BoxCryptor from the option menu to quit BoxCryptor. Even if you forgot to "Exit" BoxCryptor your password can not be restored.
To hide your files even if BoxCryptor is running in the background we additionally included the App Unlock feature. This a PIN code which always have to be typed in when BoxCryptor comes to the front. This means if you don't "Exit" BoxCryptor and press the Home button and then again start BoxCryptor you have to know the correct PIN.
The most secure way to use this app is to have a strong password on the encrypted folder which is not remembered by BoxCryptor and additonally use the App Unlock PIN. To further increase security you should always go to the options menu and "Exit" BoxCryptor after usage (Doing this also deletes the plain cache again to make sure there is nothing left in this folder). In this case the only security risk is a brute force attack on your password which can be very hard if it is strong enough!
Best regards
Boris