How to Store Family Photos So No Company Can Read Them
Nobody sits down and decides where their family photos will live. You buy a phone, it asks once whether to back up your camera roll, you tap yes because losing the photos would be worse, and eleven years later there are forty thousand images of your kids on a server belonging to a company you have never spoken to.
That is the actual situation for most people. It is worth knowing what it means, because the answer is not "your photos are encrypted, so you're fine."
Your Photos Are Encrypted. That Is Not the Same as Private.
Google, Apple, and Microsoft all encrypt your photos. They are telling the truth. The part that gets less attention is who holds the key.
At Google Photos, at OneDrive, and at iCloud in its default configuration, the provider holds it. Your photos are encrypted the way a hotel safe is locked: genuinely locked, and the hotel has a master key. That protects you from a stolen hard drive and from other customers. It does not protect you from the company.
You can tell this is true from the features. Google Photos can find every picture of your daughter, every photo of a receipt, every shot of a beach. That search is not magic. It works because the system can look at your photographs.
What Goes Wrong in Practice
The usual objection here is that nobody at Google is sitting around browsing your holiday pictures, which is fair. The realistic risk is not a nosy employee. It is automated review.
Because these services can read your files, they scan them for policy violations. When a scanner flags something, accounts get suspended, sometimes with no working appeal, and people have lost their entire photo history along with the email address attached to it. Some of those flags are wrong. A photo of a toddler in a bath, or a picture taken to send a doctor, does not look different to a classifier than something genuinely alarming.
You do not have to be doing anything wrong to be exposed to this. You only have to be storing your life on a system that reads it.
What Actually Fixes It
There is exactly one property that matters: the photo has to be encrypted on your phone or laptop, before it is uploaded, with a key the company never receives.
This is usually called end-to-end encryption or zero knowledge. When it is in place, the provider's servers hold something they cannot open. No scanning, because there is nothing to scan. No handing anything over, because there is nothing readable to hand. If they get breached, what leaks is noise.
The trade is real and you should know it going in. Nobody can reset your password back into your files, because nobody else has the key. Lose your passphrase and your recovery options, and the photos are gone in a way that customer support genuinely cannot fix.
The Options, Honestly
Turn on Advanced Data Protection in iCloud. If your whole family is on Apple devices, this is the cheapest real answer, and it costs nothing beyond the storage you already pay for. It is properly end-to-end encrypted. Two caveats: it is off by default, so almost nobody has it, and it is a setting rather than an architecture. Apple withdrew the feature for users in the United Kingdom after government pressure, which tells you the guarantee lives at the company's discretion.
Use a hosted service that is encrypted by default. Proton Drive, Filen, and Sync.com encrypt on the client and do not hold your keys. If you want to stop thinking about this today and you are comfortable with one company running everything, any of them is a defensible choice.
Run a server yourself. Nextcloud, Seafile, and our own Hoodik are free to self-host. You get complete control, and in exchange you own a machine that needs patching, backups, and a certificate that expires at inconvenient times. Plenty of people enjoy this. Plenty of people try it for six months and quietly go back.
Pay someone to run one for you. Hoodik Cloud is our version of this: a dedicated instance rather than a folder inside a shared system, encrypted in the browser before anything leaves, and exportable to your own Docker host whenever you want. It starts at €9 a month for 100 GB, and adding your partner or the grandparents does not change the price.
What to Check Before You Trust Any of Them
The marketing on all of these pages looks similar, so here are the questions that separate them.
Is it on by default, or is it a setting? A feature you have to find and enable protects the small fraction of people who go looking.
Can you read the code? Client-side encryption is a claim about software you are running. If the client is closed, you are trusting a description of it rather than the thing itself.
What happens to the file names and the thumbnails? Plenty of services encrypt the photo and then upload a readable filename and a preview image. That leaks more than people expect.
Can you get everything out? Try the export before you need it. If the only way out is downloading forty thousand files one at a time, you are locked in whatever the marketing says.
Who can switch it off? If the protection can be withdrawn by a government order, a policy change, or an acquisition, then it is a promise rather than a property of the system.
If you are not sure where your current provider sits on the first question, we keep a short answer for each of the common ones on the privacy check page.
Moving Without Losing Anything
The order matters here, because the failure mode is deleting the original before the copy is verified.
Start by pulling your archive. Google Takeout will export Google Photos, and it can take days to arrive if the library is large, so start it before you do anything else. Apple has a similar export at privacy.apple.com. Do not skip this because you plan to keep using the account for now.
Once the archive lands, check it. Open a few files from different years, confirm the dates survived, and make sure videos actually play. Exports go wrong quietly.
Then upload to wherever you have chosen and let it finish, which for a decade of photos is an overnight job on most connections. Verify a sample again on the other side, ideally from a different device, because that also proves the decryption works for you and not just on the machine that did the upload.
Now turn off camera backup on every phone in the house. This is the step people forget, and it is the one that decides whether the problem comes back. On Android it is in the Google Photos app settings; on iPhone it is iCloud Photos in the system settings.
Leave the old account alone for a month. If nothing is missing after that, delete the photos from it.
One Honest Note About the Cost
Encrypted storage costs more per gigabyte than Google or Apple, and anyone who tells you otherwise is selling something. The big providers run at a scale nobody else has, and they can deduplicate identical files across millions of accounts, which is impossible when every account's files are encrypted with different keys.
So the question is not which is cheaper. It is whether it is worth a few euros a month for your family photos to sit somewhere that cannot open them, cannot scan them, and cannot lock you out over a classifier's mistake. For a lot of people the answer is no, and that is a reasonable answer.
If it is yes, the practical advice is the same regardless of which service you pick: choose one where the encryption is on by default, the client is inspectable, and the exit is a single download you have tested.
Try Hoodik
Self-hosted, end-to-end encrypted. One Docker container, 10 minutes to deploy.
