Private photo vault

A photo vault your provider cannot open.

Private albums, document scans and personal media, sealed on your device before they ever reach a server — including their names and metadata.

The only people who can open your albums are the people you gave keys to.

For anyone keeping sensitive personal photos, private albums, medical or identity document images, and family memories that should never be readable by a cloud provider.

Built for confidentiality

Sealed before upload

Argon2id derives your key on the device; each item is encrypted with XChaCha20-Poly1305 under a fresh key wrapped with X25519.

Names and EXIF encrypted

Album names, file names, timestamps in metadata and GPS coordinates are treated as content, not as free-to-read labels.

Thumbnails made on your device

Previews are generated locally and stored encrypted, so no server ever decrypts an image to build a gallery.

Blind-index search

HMAC search tags are computed on your machine, so you can find an album without a readable server-side index.

Shares with a fuse

Passphrase-gated links carry key material in the URL fragment only, cap views, and expire within 24 hours at most.

PIN and auto-lock

A separate app-level PIN, lockout after repeated failures, and decrypted material wiped from memory on lock.

Why a separate vault instead of a setting

Mainstream photo clouds are built around readable content: search by object, face grouping, memories and duplicate detection all require decryption. No privacy setting removes that capability, because the product depends on it. A vault with client-side encryption is a different architecture, not a stricter configuration — which is why it can encrypt file names and metadata as aggressively as pixels.

What we can and cannot see

We can see that an account exists, how many encrypted objects it holds, roughly how large they are and when they were written, plus connection and billing metadata. We cannot see images, thumbnails, file names, album names, EXIF or the contents of a search. There is no admin console, support tool or automated classifier able to open an item.

Recovery, stated plainly

Zero-knowledge and provider-side password reset cannot coexist. At signup your device generates a recovery kit that can unwrap your master key. Print it, store it offline, and keep a second copy somewhere safe. If you lose both your passphrase and the kit, the library is unrecoverable — the same property that protects it from everyone else.

Frequently asked questions

Can DRIVUNO see my photos?

+

No. Images are encrypted on your device before upload. Your passphrase is stretched locally with Argon2id, each item is sealed with XChaCha20-Poly1305 under a fresh key, and those keys are wrapped with X25519. Our servers store ciphertext and wrapped keys, with no decryption path.

Are file names and EXIF encrypted too, or only the images?

+

Both. File names, album names and embedded metadata are treated as content and sealed alongside the pixels. Thumbnails are generated on your device and stored encrypted.

What happens if I forget my password?

+

We cannot restore your library — that is the same property that prevents anyone else from opening it. Recovery relies on the recovery kit generated on your device at signup, which you keep offline.

How does sharing a private album work?

+

For people with an account, the album key is wrapped for their public key, and removing them rotates it. For everyone else, links carry key material only in the URL fragment, which browsers never transmit to a server; links are passphrase-gated and expire within 24 hours at most.

Can I search my photos?

+

Yes, using blind indexes. Search tags are computed with HMAC on your device, so the server matches opaque strings and never sees your query or your file names. There is no server-side analysis of image content.

Is this a backup as well as a vault?

+

Your encrypted library is replicated to independent EU storage with immutability windows and automatic failover between providers. Those copies are ciphertext as well. We still recommend keeping one offline encrypted copy of anything irreplaceable.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload