AES-256-GCM with a PBKDF2-derived key (150k iterations). There is no password recovery — if you lose the password, the data can’t be recovered.