Mainstream cloud photos
ImageTome vs iCloud Photos
Apple is the only mainstream photo service that offers genuine end-to-end encryption for your library, and it deserves credit for it. The catches are that it is off by default, it is Apple-only, and in the United Kingdom it is no longer available at all.
Apple's end-to-end encryption is opt-in, platform-locked and withdrawn in the UK. Ours is the only mode we have.
Side by side
| Criterion | ImageTome | iCloud Photos |
|---|---|---|
| Encryption model | ImageTome End-to-end. AES-256-GCM in the browser, before upload. | iCloud Photos End-to-end for Photos only with Advanced Data Protection enabled. Standard Data Protection otherwise, where Apple holds the keys. |
| Who holds the keys | ImageTome You. An RSA-4096 private key generated on your device and never sent to us. | iCloud Photos You, with ADP on. Apple, with it off, which is the default. |
| What an account needs | ImageTome A username. No email address, no password, no phone number. | iCloud Photos An Apple Account with an email address, usually a phone number and two-factor authentication. |
| If you lose access | ImageTome Nothing we can do. Your exported key backup is the only route back in. | iCloud Photos Recovery contact or recovery key with ADP on. Full Apple-assisted recovery with it off. |
| Filenames and titles | ImageTome Encrypted. Tome names, descriptions, filenames, titles and post bodies. | iCloud Photos Some metadata stays readable by Apple even under ADP. |
| Content scanning | ImageTome None, and none is possible. Nothing here is detected proactively, because nothing can be read. | iCloud Photos On-device analysis for the Photos app. Apple abandoned its server-side CSAM scanning plan in 2022. |
| Video | ImageTome MP4 and WebM up to 200MB, with thumbnails generated and encrypted in the browser. | iCloud Photos Excellent, deeply integrated with iPhone capture. |
| Sharing | ImageTome Invite by username. The tome key is wrapped with their public key. | iCloud Photos Shared albums and iCloud links. Shared Albums are not covered by end-to-end encryption. |
| Discussion | ImageTome Encrypted comments on posts, images and videos. | iCloud Photos Comments and likes on shared albums. |
| Verifying the claim | ImageTome Open your network tab during an upload and read what is actually sent. | iCloud Photos Apple publishes its security model in detail, but the clients are closed source. |
Advanced Data Protection is real, and it is opt-in
With Advanced Data Protection switched on, iCloud Photos is end-to-end encrypted and Apple cannot read your library. That is a genuine, well-engineered privacy feature and it puts Apple far ahead of Google on this specific point.
It is not the default. A user who never opens Settings and turns it on is running Standard Data Protection, where Apple holds the keys to their photos and can produce them in response to a legal request. Most people never turn it on. The encryption you have to find and enable is the encryption most people do not have.
On ImageTome there is no setting, because there is no other mode. The keypair is generated before you have an account to configure. You cannot accidentally run in a weaker configuration, because a weaker configuration does not exist.
What happened in the United Kingdom
In January 2025 the UK Home Office served Apple with a technical capability notice under the Investigatory Powers Act, reportedly seeking access to encrypted iCloud data. Apple refused to build a backdoor and instead withdrew Advanced Data Protection from the United Kingdom in February 2025. New UK users cannot enable it, and existing users were required to turn it off.
Apple filed a further legal challenge at the Investigatory Powers Tribunal in August 2026, and the position may change again. The structural point is what matters for a comparison: because Apple operates the encryption as a feature it grants, a government could ask it to withdraw that feature, and it did. We have no equivalent lever to pull. There is no switch on our side that turns a user's encryption off, because the key was never on our side.
Sharing is where end-to-end encryption usually breaks
iCloud Shared Albums are not covered by end-to-end encryption, even with Advanced Data Protection enabled. The moment you share a set of photos with other people, that set leaves the protected envelope. This is not unusual. Sharing is the hard part of end-to-end encryption, and most services solve it by giving up on it.
ImageTome is built the other way round: sharing is the primary case, not the exception. A tome has one AES-256 key, and inviting somebody wraps that key with their RSA-4096 public key so only their device can unwrap it. A shared tome is exactly as encrypted as a private one.
When iCloud Photos is the better choice
- If you live on Apple hardware, iCloud Photos with Advanced Data Protection enabled is a strong, private default that requires no effort from you. Turn it on today if you have not.
- Apple gives you account recovery that survives losing a device, through recovery contacts and recovery keys. We do not. If you would rather have a safety net than an absolute guarantee, Apple built the better product for you.
- iCloud handles a lifetime photo library, automatic capture backup and hardware integration we make no attempt to match.
ImageTome and iCloud Photos, asked and answered
Only if you enable Advanced Data Protection, and not at all for users in the United Kingdom, where Apple withdrew the feature in February 2025 after a UK government order. Under Standard Data Protection, Apple holds the keys to your photo library.
No. Shared Albums fall outside the end-to-end encrypted categories even when Advanced Data Protection is enabled. On ImageTome, sharing a tome does not weaken its encryption.
Yes. ImageTome runs in the browser and uses the Web Crypto API, which Safari supports. There is no app to install and no App Store review sitting between you and your own encryption.
An order can compel a company to hand over what it holds. What we hold is ciphertext and public keys. We could be compelled to hand over every byte on our servers and it would not decrypt anything, because the private keys are on your devices and have never been anywhere else.
Sources
- Apple can no longer offer Advanced Data Protection in the United Kingdom to new users, Apple Support
- Apple kills its iCloud end-to-end encryption feature in the UK, TechRadar
- Protecting your iCloud data after Apple's Advanced Data Protection removal in the UK, Help Net Security
Claims about iCloud Photos were checked against the sources above on 30 August 2026. Products change. If something here is out of date or wrong, we would rather fix it than keep it.
Other comparisons
vs Google Photos
Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.
Mainstream cloud storagevs Dropbox
Dropbox encrypts the disk. We encrypt the file, in your browser, with a key Dropbox's architecture has no equivalent of.
End-to-end encrypted storagevs Proton Drive
Proton is a general encrypted drive with an account you can recover. We are an encrypted media space with an account nobody can recover, including us.
Try the version where nobody holds your key.
One username, one tome, and a look at your own network tab to check we mean it.
Create an account