Skip to content

How we compare, including where we lose

Nine comparisons against the services people actually use to share photos and video. Each one has a table, the reasoning behind it, sources for every claim about the other product, and a section on when you should choose them instead of us.

LAST CHECKED 30 AUG 2026

Mainstream cloud photos

ImageTome vs Google Photos

Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.

Read the comparison
Mainstream cloud photos

ImageTome vs iCloud Photos

Apple's end-to-end encryption is opt-in, platform-locked and withdrawn in the UK. Ours is the only mode we have.

Read the comparison
Mainstream cloud storage

ImageTome vs Dropbox

Dropbox encrypts the disk. We encrypt the file, in your browser, with a key Dropbox's architecture has no equivalent of.

Read the comparison
End-to-end encrypted storage

ImageTome vs Proton Drive

Proton is a general encrypted drive with an account you can recover. We are an encrypted media space with an account nobody can recover, including us.

Read the comparison
End-to-end encrypted photos

ImageTome vs Ente Photos

Ente is an encrypted photo library with on-device intelligence. We are an encrypted shared space with no email address and discussion built in.

Read the comparison
End-to-end encrypted storage

ImageTome vs MEGA

Both encrypt in the browser. The question a 2022 research paper asked of MEGA is the question you should ask of us too: what happens if the server turns hostile?

Read the comparison
End-to-end encrypted storage

ImageTome vs Tresorit

Tresorit and ImageTome use the same primitives. Tresorit sells them to a compliance officer; we give them to a person who wants to share holiday photos.

Read the comparison
Public image host

ImageTome vs Imgur

An unlisted link is not privacy. It is an address you hope nobody guesses, on a server that can read everything and delete it whenever policy changes.

Read the comparison
File transfer

ImageTome vs WeTransfer

WeTransfer is a delivery van with a window. We are a locked box that only the recipient has a key for.

Read the comparison

The only question that separates these products

Almost every service on this page will tell you your files are encrypted, and almost every one of them is telling the truth. Encryption in transit and encryption at rest are standard now, and they protect you against a stolen disk or an intercepted connection.

The question that actually divides the list is who holds the key. Where the provider holds it, the encryption protects you from everyone except the provider, anyone who compromises the provider, and anyone who can legally compel the provider. Where you hold it, the provider is in the same position as an attacker: holding ciphertext, with nothing to open it.

That single distinction explains every difference in the tables. Search, previews, moderation, undelete and password reset all require reading your files, so services that keep the key can offer them and services that do not, cannot. There is no clever engineering that avoids this trade. Anyone who tells you otherwise is holding your key.

How to check a claim yourself

Open your browser's developer tools, go to the network tab, and upload a photo to any service that claims end-to-end encryption. Find the request carrying the file and look at the payload. If you can make out a JPEG header, the file went up readable. If it is noise, it did not.

This is the only assurance that does not require trusting a marketing page, including this one. It is worth doing to us as much as to anyone else.

What we do not have

We have no independent security audit, no published source code, and no compliance certifications. Ente has open source clients and servers plus audits. Proton has audited clients. Tresorit has SOC 2 Type II, ISO 27001 and HIPAA. On those specific measures they are ahead of us, and saying so costs us nothing that dishonesty would not cost more.

What we have is a narrower design: no email address, no password, no key on our side, and no administrator who could be asked to open your tome. Whether that is the right trade is your call, and it is easier to make with accurate information than with a table that gives us ticks all the way down.

Choosing between them

A service that encrypts your photos on your own device and never receives the key. That rules out Google Photos, Dropbox, WeTransfer and Imgur, whose encryption keys are held by the provider. It leaves ImageTome, Proton Drive, Ente, Tresorit, MEGA and iCloud Photos with Advanced Data Protection enabled, and among those the differences are about accounts, recovery and what a shared space contains.

It means the service cannot read them by design rather than by policy. It does not mean the software is flawless. The 2022 ETH Zurich research on MEGA showed an end-to-end encrypted service that still did not protect users against its own server, which is why the question to ask any provider is what happens if the server turns hostile.

Proton Drive, Ente, MEGA, Tresorit, iCloud and Google Photos all require an email address, and most require a password. ImageTome requires a username and nothing else, because the keypair generated in your browser is the account.

Server-side search, thumbnails generated for you, content moderation, and usually account recovery. Ente recovers search by running the models on your device. Nobody recovers server-side search, because it requires reading your photos.

They are written by us, so read them accordingly. Every page ends with a section on where the other product is genuinely better than ours, every factual claim about a competitor carries a source, and each page says when it was last checked. If you find something wrong, it will be corrected.

Start with one tome and see how it feels.

Creating an account takes a few seconds and asks you for nothing but a username.

Create an account