Your phone does not get the vault key.
It receives a revocable token for one grant. Your trusted node decrypts only that slice and records every read.
Pairing requires HTTPS. The web client stores a revocable refresh token on this phone; the native client will move it into Keychain.
Search results stay within this grant.