Skip to content

Your photos. Nobody else's business.

A photograph you upload somewhere else gets read by something. Scanned for faces, indexed for search, kept under terms that can change next July. We hold the panel on the right and nothing else, because the key that turns it back into your photograph is generated in your browser and never leaves it.

NO EMAIL · NO PASSWORD · NO TRACKING

A parent and grandparent running alongside a child learning to ride a bicycle in a park at golden hour.
What you see
What we store

What it actually looks like

Encryption is the part you cannot see, so here is the part you can. Every screen below is the real application, shown in the theme you are reading this in. Open any one of them for a closer look.

What happens to photographs everywhere else

Not hypotheticals. Four things that have already happened to ordinary people's photos in the last three years, on the services most people use.

They are read by something

Google's systems analyse every photo you upload for faces, places and objects, children included. It settled a $100 million biometric privacy claim in Illinois in 2022, and switched on broader scanning of stored photos for AI features in 2025 and again in 2026, enabled by default.

The full comparison

The terms can change under you

In July 2025 WeTransfer granted itself the right to train machine learning models on everything users had uploaded. It reversed the change within days after the backlash. The clause was possible in the first place only because the files could be read.

The full comparison

Someone else decides how long they last

Imgur deleted anonymous uploads wholesale in May 2023, breaking years of links people had assumed were permanent. Content you do not hold the key to lives at the discretion of whoever does.

The full comparison

Protection can be withdrawn

Apple's Advanced Data Protection is real end-to-end encryption. In February 2025 Apple removed it from the United Kingdom rather than build the backdoor the government had demanded. Encryption a company grants you is a feature, and features can be taken back.

The full comparison

None of these were scandals, and none of these companies are villains. Every one of them is the ordinary consequence of a company holding the key to your photographs. Take the key away and none of it is available to anybody, including us.

Whether this is the right thing for you

It genuinely is not for everybody, and we would rather point you somewhere better now than lose your photographs for you later.

This is for you if

  • You are putting family photographs somewhere they will not be grouped by face, indexed, or used to train anything.
  • You share with a small, fixed group. A family, a couple, a team of four. Not the public, and not a link you have lost track of.
  • You would rather have a guarantee you can check in a network tab than a policy you have to take on trust.
  • You do not want a photo library joined to your email address, and through it to everything else that address has signed up for.
  • You accept that being the only holder of the key makes the consequences of losing it yours.

Use something else if

Four steps, and we never hold a key

01

Your browser makes a key

No email, no password. Creating an account generates a keypair on your device. The public half goes to us so other people can share with you. The private half never leaves.

02

You make a tome

A tome is a private space with its own key. Its name and description are encrypted too, so even the label on the box is unreadable to us.

03

You add things to it

Images, video, posts and comments are encrypted in the browser before upload. What arrives at our servers is noise, and stays that way.

04

You invite people in

Inviting someone wraps the tome's key with their public key. Only their device can unwrap it. The key itself never reaches us in a readable form.

What you get

Images

JPEG, PNG, GIF and WebP, encrypted before upload. Thumbnails are encrypted too.

Video

MP4 and WebM, up to 200MB each, decrypted and played in the browser.

Posts

Write alongside your media. Titles and bodies are encrypted like everything else.

Comments

Talk about a photo underneath it. Every comment is encrypted with the tome key.

Invites

Bring people in by username. Their device unwraps the tome key; ours never sees it.

Messages

One-to-one conversations, encrypted the same way as everything else.

The honest part

Encryption this strict costs you things that other services give away freely. You should know what they are before you sign up, not after.

Nobody here can let you back in

There is no password to reset and no inbox to mail a link to. What there is, if you switch it on, is recovery: a passphrase and passcode only you hold unseal a copy of your key that we store and cannot open. Set that up on day one, or export a backup - sealed with a passphrase, if it is going somewhere you would not leave a house key. Do neither and a cleared browser ends the account.

You cannot search inside your media

We can only index what we can read, and we cannot read any of it. You can browse a tome and sort by date. You cannot search for a face, a place or a word inside a photo.

Deleting really deletes

There is no trash to recover from and no thirty-day grace period. When you delete an image, a tome or an account, it is removed, and nobody can bring it back.

We cannot police what is in here

The design that stops us reading your photographs stops us finding anything else. We cannot scan for anything, so we act only on what is reported to us. Unreadable is not the same as unaccountable, and this is not a place to put things that should not exist.

We also publish an audit of our own encryption, including the parts of it that are weaker than the key lengths suggest. Read the security audit.

How this differs from what you use now

Nine comparisons, each with a table, sources for every claim about the other product, and a section on when you should pick them instead of us. That last part is not a formality. Sometimes you should.

If you want the reasoning first

Questions

That depends on what you set up first. Switch on recovery and a passphrase and passcode you hold will bring it back. Export a backup and you can import it anywhere - sealed under a passphrase of its own, if you would rather the file were safe to leave lying around. Do neither and the account is gone, along with everything in it - there is no reset link, because we hold nothing to reset. Pick one on your first day; both take seconds.

No. Encryption and decryption happen in your browser. What reaches our servers is a blob we have no key for. Someone who took a copy of our entire database would have a very large collection of noise.

A password can be phished, reused or leaked, and an email address ties your identity to your content. Here, the keypair in your browser is the account, and there is no password database to breach because no password ever signs you in. A passphrase turns up only where you ask for one - unsealing a recovery copy, or opening a backup you chose to seal - and in both cases it does its work inside your browser. It is never sent to us and it never authenticates anything.

Each tome has its own key. When you invite someone, that key is wrapped with their public key, so only their device can unwrap it. The tome key never reaches us in a readable form.

Images in JPEG, PNG, GIF and WebP, up to 50MB each. Video in MP4 and WebM, up to 200MB per file. Video thumbnails are generated in your browser and encrypted before they are uploaded, like everything else.

Google Photos holds the keys to your library and scans it to power search. Proton Drive is genuinely zero-knowledge and, unlike us, offers general file storage and a much broader product. We now have optional recovery of our own, so that particular gap has closed. We publish a comparison for each of the nine services people most often ask about, including where they beat us.

Less than on a service that can read your uploads, and we would rather say that than pretend otherwise. We cannot scan for anything, because we cannot read anything, so we act on what is reported to us and close accounts when we are told. What we do have is a shape that makes the problem smaller: nothing here is public, nothing is indexed, there is no link to pass around, and every tome is invite-only. There is no audience to reach.

Yes, and you should. Open your browser's network tab while you upload a photo and look at what actually gets sent. That is the only assurance worth having.

Your key is yours and your backup keeps working. Recovery would not, since it depends on our servers handing the sealed copy back - which is a good reason to export a backup even with recovery switched on. We are building export so you can take your encrypted content with you and decrypt it yourself, independent of whether we are still here.

Start with one tome and see how it feels.

Creating an account takes a few seconds and asks you for nothing but a username.

Create an account