← Blog
Photos8 min read

Online private photo storage without AI scanning: what to look for in 2026

Most photo clouds analyse every image they host. Here is how to evaluate private photo storage properly — encryption model, metadata exposure, search, sharing, and ban risk.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

"Private" is a marketing word; the architecture is the fact Almost every consumer photo service describes itself as private. The question that separates claims from facts is simple: **can the provider decrypt your library?** If yes, then face grouping, object search, moderation, model training and legal disclosure are all technically available, whatever the current policy says.

The checklist that actually matters - **Where is the encryption key generated?** On your device, or on their servers? - **Can support reset your password and still show your photos?** If yes, they hold a key. - **What is stored unencrypted?** Many services encrypt pixels but keep filenames, albums, timestamps and locations in the clear. - **Is there content scanning?** Ask whether images are classified for moderation, ads, or model training. - **What happens on a policy dispute?** Can the whole account be suspended based on image contents?

Why AI scanning is the default Serving thumbnails, grouping faces, and offering "search your photos for a dog" all require a server that sees pixels. Providers built those features first and privacy language second. There is no way to have server-side visual search *and* zero-knowledge storage — they are mutually exclusive.

How zero-knowledge photo storage works instead In DRIVUNO, each photo is encrypted in your browser with XChaCha20-Poly1305 before any byte reaches a server. The per-file key is wrapped with your account key (X25519), derived from your password with Argon2id. Thumbnails are generated locally and encrypted too.

Search still works, because your device computes HMAC blind-index tags for names and attributes and the server matches opaque tags without seeing plaintext. Results are decrypted in the browser.

Sharing without leaking the library Sharing is per recipient: a key envelope sealed to their public key, or a public link whose key lives in the URL fragment — the part browsers never send to a server — protected by a passphrase and a short expiry. Remove a recipient and the remaining keys are rotated.

What you should expect to give up - Server-side "who is in this photo" grouping. - Provider-side AI editing that requires uploading a readable image. - Password resets that magically restore access. If you lose your password and your Recovery Kit, the data stays encrypted — that is the guarantee working, not failing.

A reasonable setup for a family library 1. Import originals, not re-compressed copies. 2. Mirror the local photo folder with Live Clone so new imports are protected automatically. 3. Print the Recovery Kit and store it offline. 4. Share albums with named people, not with public links, whenever possible.

Private photo storage is not a promise about behaviour. It is a statement about what the server is able to do. Start free with 1 GB.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload