Fixed in https://github.com/badbundle/vault-app/pull/670 (merged as 76f03c5f).
- Saved exports and auto-backups are padded to a fixed size: 32 KiB minimum, then the next power of two that fits. The padding is inside the encrypted payload (
obfuscationPadding), so the file size, the PDF's QR-code count and its page count all come in steps, and each step covers a wide range of vault sizes. - The encoder pads, compresses and measures, then adjusts the padding and repeats, stopping when the encrypted data lands within 16 bytes of the target. It aims for the middle of that window, so it usually needs one or two tries.
- Device transfer keeps random padding. Both phones are in the same hands, so a fixed size gains nothing there, and the QR codes stay quick to scan.
docs/on-device-encryption.mdnow has a "Backup sizes" bullet, and the CHANGELOG has an entry.