End-to-end encrypted photos means the provider never holds a usable key. Here is the exact chain — key derivation, per-file keys, thumbnails, sharing — and the questions that expose a weak implementation.
Three private surfaces. Same zero-knowledge architecture.
Encryption "in transit and at rest" is not the same thing: it protects against network attackers and stolen disks, while leaving the provider fully able to read your library.
An honest end-to-end provider answers: ciphertext plus a sealed key; no; server-side visual search and content moderation.
Three private surfaces. Same zero-knowledge architecture.