← Blog
Private photos7 min read

Protecting personal memories: the case for zero-knowledge encryption

A photo library is a permanent record of a life. Zero-knowledge encryption is the only model where that record's confidentiality does not depend on a company's future behaviour.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

What a library becomes over ten years A photo library is not a folder of pictures. It is a chronological record of where you lived, who you loved, what you were treated for, which documents you handled and what you looked like at every age. It was assembled one convenient decision at a time, and none of those decisions were made with a decade in mind.

The security question is therefore not "is this company careful today?" but "will this record still be confidential in fifteen years, across acquisitions, policy revisions, jurisdiction changes and staff turnover?"

Why policy is a weak guarantee over long horizons Policies are excellent at governing behaviour now. They are poor at binding the future:

  • companies are acquired and terms are rewritten
  • legal frameworks change
  • product teams add features that require new content processing
  • individual employees make mistakes
  • breaches happen to competent organisations

Every one of these is survivable if the provider cannot decrypt. Every one of them is a live exposure if it can.

The permanence argument Encryption applied today protects photos taken years ago, because it protects the stored objects. A policy adopted today governs behaviour going forward. When the asset is permanent, prefer the guarantee that is also permanent.

What zero-knowledge costs a family Two things, honestly:

Recovery discipline. Someone must keep the recovery kit safe, and ideally a trusted second person must know where it is. For a family library, this is genuinely important: plan inheritance of the kit the way you would plan any other document that matters.

No cloud-side magic. Face grouping and content search happen on-device or not at all.

Both are manageable. Neither is comparable to losing control of a decade of personal images.

A durable arrangement 1. Zero-knowledge cloud vault as the primary home for personal and sensitive media. 2. One offline encrypted copy, kept at a different address. 3. A recovery kit printed and stored in a safe, with a second copy in another secure location. 4. A written note for a trusted person explaining where the kit is and what it opens. 5. An annual check: restore something, confirm the kit works, confirm the offline copy is current.

Availability matters as much as confidentiality Encryption keeps memories private; redundancy keeps them existing. DRIVUNO stores encrypted snapshots across independent EU providers with immutability windows and automatic failover, so a single provider outage or deletion event does not end the library. Those copies are ciphertext as well — we cannot read our own backups of your data.

The plain conclusion For work documents, the risk of provider-readable storage is commercial. For a personal photo library, it is closer to the record of a life. That deserves an architecture where confidentiality does not depend on anyone's continued good behaviour — including ours.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload