A photo library is a permanent record of a life. Zero-knowledge encryption is the only model where that record's confidentiality does not depend on a company's future behaviour.
Three private surfaces. Same zero-knowledge architecture.
The security question is therefore not "is this company careful today?" but "will this record still be confidential in fifteen years, across acquisitions, policy revisions, jurisdiction changes and staff turnover?"
Every one of these is survivable if the provider cannot decrypt. Every one of them is a live exposure if it can.
Recovery discipline. Someone must keep the recovery kit safe, and ideally a trusted second person must know where it is. For a family library, this is genuinely important: plan inheritance of the kit the way you would plan any other document that matters.
No cloud-side magic. Face grouping and content search happen on-device or not at all.
Both are manageable. Neither is comparable to losing control of a decade of personal images.
Three private surfaces. Same zero-knowledge architecture.