Your photos. Nobody else's business.
A photograph you upload somewhere else gets read by something. Scanned for faces, indexed for search, kept under terms that can change next July. We hold the panel on the right and nothing else, because the key that turns it back into your photograph is generated in your browser and never leaves it.
What it actually looks like
Encryption is the part you cannot see, so here is the part you can. Every screen below is the real application, shown in the theme you are reading this in. Open any one of them for a closer look.
What happens to photographs everywhere else
Not hypotheticals. Four things that have already happened to ordinary people's photos in the last three years, on the services most people use.
They are read by something
Google's systems analyse every photo you upload for faces, places and objects, children included. It settled a $100 million biometric privacy claim in Illinois in 2022, and switched on broader scanning of stored photos for AI features in 2025 and again in 2026, enabled by default.
The full comparisonThe terms can change under you
In July 2025 WeTransfer granted itself the right to train machine learning models on everything users had uploaded. It reversed the change within days after the backlash. The clause was possible in the first place only because the files could be read.
The full comparisonSomeone else decides how long they last
Imgur deleted anonymous uploads wholesale in May 2023, breaking years of links people had assumed were permanent. Content you do not hold the key to lives at the discretion of whoever does.
The full comparisonProtection can be withdrawn
Apple's Advanced Data Protection is real end-to-end encryption. In February 2025 Apple removed it from the United Kingdom rather than build the backdoor the government had demanded. Encryption a company grants you is a feature, and features can be taken back.
The full comparisonNone of these were scandals, and none of these companies are villains. Every one of them is the ordinary consequence of a company holding the key to your photographs. Take the key away and none of it is available to anybody, including us.
Whether this is the right thing for you
It genuinely is not for everybody, and we would rather point you somewhere better now than lose your photographs for you later.
This is for you if
- You are putting family photographs somewhere they will not be grouped by face, indexed, or used to train anything.
- You share with a small, fixed group. A family, a couple, a team of four. Not the public, and not a link you have lost track of.
- You would rather have a guarantee you can check in a network tab than a policy you have to take on trust.
- You do not want a photo library joined to your email address, and through it to everything else that address has signed up for.
- You accept that being the only holder of the key makes the consequences of losing it yours.
Use something else if
-
You need to search your own library, or find every photo of one person.
Ente does this on your device -
You want recovery handled for you, rather than resting on a passphrase you have to keep.
Proton has a recovery phrase -
You need to send something to a person who will never create an account.
A transfer link is the honest tool -
You need certifications an auditor will accept, or an administrator who can recover a colleague's files.
Tresorit is built for that -
You want a photograph to be seen publicly, or hotlinked into a forum post.
That is what Imgur is for
Four steps, and we never hold a key
Your browser makes a key
No email, no password. Creating an account generates a keypair on your device. The public half goes to us so other people can share with you. The private half never leaves.
You make a tome
A tome is a private space with its own key. Its name and description are encrypted too, so even the label on the box is unreadable to us.
You add things to it
Images, video, posts and comments are encrypted in the browser before upload. What arrives at our servers is noise, and stays that way.
You invite people in
Inviting someone wraps the tome's key with their public key. Only their device can unwrap it. The key itself never reaches us in a readable form.
What you get
Images
JPEG, PNG, GIF and WebP, encrypted before upload. Thumbnails are encrypted too.
Video
MP4 and WebM, up to 200MB each, decrypted and played in the browser.
Posts
Write alongside your media. Titles and bodies are encrypted like everything else.
Comments
Talk about a photo underneath it. Every comment is encrypted with the tome key.
Invites
Bring people in by username. Their device unwraps the tome key; ours never sees it.
Messages
One-to-one conversations, encrypted the same way as everything else.
The honest part
Encryption this strict costs you things that other services give away freely. You should know what they are before you sign up, not after.
Nobody here can let you back in
There is no password to reset and no inbox to mail a link to. What there is, if you switch it on, is recovery: a passphrase and passcode only you hold unseal a copy of your key that we store and cannot open. Set that up on day one, or export a backup - sealed with a passphrase, if it is going somewhere you would not leave a house key. Do neither and a cleared browser ends the account.
You cannot search inside your media
We can only index what we can read, and we cannot read any of it. You can browse a tome and sort by date. You cannot search for a face, a place or a word inside a photo.
Deleting really deletes
There is no trash to recover from and no thirty-day grace period. When you delete an image, a tome or an account, it is removed, and nobody can bring it back.
We cannot police what is in here
The design that stops us reading your photographs stops us finding anything else. We cannot scan for anything, so we act only on what is reported to us. Unreadable is not the same as unaccountable, and this is not a place to put things that should not exist.
We also publish an audit of our own encryption, including the parts of it that are weaker than the key lengths suggest. Read the security audit.
How this differs from what you use now
Nine comparisons, each with a table, sources for every claim about the other product, and a section on when you should pick them instead of us. That last part is not a formality. Sometimes you should.
vs Google Photos
Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.
Mainstream cloud photosvs iCloud Photos
Apple's end-to-end encryption is opt-in, platform-locked and withdrawn in the UK. Ours is the only mode we have.
End-to-end encrypted storagevs Proton Drive
Proton is a general encrypted drive with an account you can recover through email or a phrase. We are an encrypted media space where recovery is optional and depends on secrets only you hold.
Mainstream cloud storagevs Dropbox
Dropbox encrypts the disk. We encrypt the file, in your browser, with a key Dropbox's architecture has no equivalent of.
End-to-end encrypted photosvs Ente Photos
Ente is an encrypted photo library with on-device intelligence. We are an encrypted shared space with no email address and discussion built in.
File transfervs WeTransfer
WeTransfer is a delivery van with a window. We are a locked box that only the recipient has a key for.
If you want the reasoning first
Encrypted photo sharing
The difference between encryption at rest and end-to-end, and five questions that reveal who holds the key.
Encrypted video sharing
Why streaming needs a server that can watch your video, and how thumbnails are made on your device instead.
Zero-knowledge encryption
What the term means, how to test a provider's claim, and why regulators keep circling it.
How our encryption works
The key hierarchy in full, and an honest account of what this design will not protect you from.
Questions
That depends on what you set up first. Switch on recovery and a passphrase and passcode you hold will bring it back. Export a backup and you can import it anywhere - sealed under a passphrase of its own, if you would rather the file were safe to leave lying around. Do neither and the account is gone, along with everything in it - there is no reset link, because we hold nothing to reset. Pick one on your first day; both take seconds.
No. Encryption and decryption happen in your browser. What reaches our servers is a blob we have no key for. Someone who took a copy of our entire database would have a very large collection of noise.
A password can be phished, reused or leaked, and an email address ties your identity to your content. Here, the keypair in your browser is the account, and there is no password database to breach because no password ever signs you in. A passphrase turns up only where you ask for one - unsealing a recovery copy, or opening a backup you chose to seal - and in both cases it does its work inside your browser. It is never sent to us and it never authenticates anything.
Each tome has its own key. When you invite someone, that key is wrapped with their public key, so only their device can unwrap it. The tome key never reaches us in a readable form.
Images in JPEG, PNG, GIF and WebP, up to 50MB each. Video in MP4 and WebM, up to 200MB per file. Video thumbnails are generated in your browser and encrypted before they are uploaded, like everything else.
Google Photos holds the keys to your library and scans it to power search. Proton Drive is genuinely zero-knowledge and, unlike us, offers general file storage and a much broader product. We now have optional recovery of our own, so that particular gap has closed. We publish a comparison for each of the nine services people most often ask about, including where they beat us.
Less than on a service that can read your uploads, and we would rather say that than pretend otherwise. We cannot scan for anything, because we cannot read anything, so we act on what is reported to us and close accounts when we are told. What we do have is a shape that makes the problem smaller: nothing here is public, nothing is indexed, there is no link to pass around, and every tome is invite-only. There is no audience to reach.
Yes, and you should. Open your browser's network tab while you upload a photo and look at what actually gets sent. That is the only assurance worth having.
Your key is yours and your backup keeps working. Recovery would not, since it depends on our servers handing the sealed copy back - which is a good reason to export a backup even with recovery switched on. We are building export so you can take your encrypted content with you and decrypt it yourself, independent of whether we are still here.
Start with one tome and see how it feels.
Creating an account takes a few seconds and asks you for nothing but a username.
Create an account