When someone on r/privacy pointed out that KeepSafe, one of the most downloaded “secure photo apps,” protects your library with nothing more than a PIN code and an email address, the responses were not surprised. They were tired.

“How does this not make them extremely vulnerable to having pin codes brute forced?” the original post asked. The answers varied, but the consensus was clear: the word “secure” on a photo app means almost nothing by itself, and the audience that cares about photo privacy has learned this the hard way.

The problem is not that secure photo storage is impossible. It is that the label is applied to everything from services with genuine privacy protections to apps that are, in effect, a folder behind a four-digit PIN. There is no obvious way to tell them apart from the app store listing or the marketing page.

What does help is asking specific questions about product behaviour rather than evaluating adjectives. A service that answers “what happens to my photos on upload?” with a narrow, checkable statement is more trustworthy than one that answers with “we take your privacy seriously.” The first answer can be verified. The second cannot.

This is a checklist for evaluating any photo storage app or service. Five questions, each targeting a specific behaviour. Then what Yogile’s answers are to each one.

Why “secure” covers so many different things

The r/privacy KeepSafe thread identified one failure: account access could be brute-forced because the only barrier was a short numeric PIN. But that is one narrow axis. A service could have excellent PIN protection and still scan every photo you upload to build an advertising profile. A service could have genuine scanning protections and still give you no clean way to export your library when you want to leave.

What “secure photo storage” actually means for family photos puts this directly: security is not a single property. For personal photo storage, it covers at least four things that operate independently of each other.

Privacy on upload. What happens to photos when they arrive on the service’s servers? Are they scanned, analysed, or processed for advertising or AI training?

Access control. Who can see photos by default? What controls exist, and what do they actually protect?

Durability. Will photos still be there in five years? What happens if the service changes terms, raises prices, or bans your account? Can you get your files out cleanly?

Usability as a security property. A tool your family will not use because it requires app installations and account creation does not protect your photos. People route around friction by sending compressed screenshots instead. If sharing requires downloading a separate app, that is a failure on an axis most checklists miss entirely.

These axes are worth separating because a service can be strong on one and weak on others, and marketing language rarely specifies which.

The checklist: five questions to ask before trusting a photo app

The point of this checklist is to get past adjectives and into concrete product behaviour. For any service under evaluation, find the answers to each question. If a service cannot or will not answer them specifically, that is itself information.

Question 1: What is the default audience for my photos?

This is the single most clarifying question you can ask. In most mainstream photo services, photos are private by default but can be shared. In others, uploading means publishing to a community. In others still, the library is functionally private but the service reserves rights to the content that are not typical of a storage arrangement.

A specific answer looks like this: “photos are private by default; nothing is shared until you choose to share it.” That is narrow and checkable. A vague answer suggests either that the default is public or that the company prefers you not examine this closely.

Question 2: Does the service scan my photos, and what is that analysis used for?

This covers two things: whether the service analyses uploads at all, and what it does with the results. Many services do both on-device processing (face grouping, scene recognition) and server-side processing. On-device processing typically stays on your device. Server-side processing is not under your control, and the question is what happens to its outputs.

The categories to ask about separately: - AI training: are photos used to develop or improve models? - Advertising: is the library used to build a profile that informs targeting? - Feature generation: is analysis used to power search, memories, or recommendations?

The first two are what most people object to. The third is what makes certain services useful. A service that does none of the three is rare, which is why it is worth asking directly.

For secure photo storage to mean what most people want it to mean, the minimum is no use for training and no use for advertising. Check whether the service states this specifically, rather than through a general privacy policy that permits broad use of content.

Question 3: What access controls exist, and what do they actually protect?

A PIN code on a local vault app protects against someone who picks up your unlocked phone. It does not protect against the server that hosts the photos, against an account compromise at the email address used to register, or against a weak PIN being guessed online.

More useful access controls are layered: a strong account login, optional additional protection at the album level, and a clear distinction between what is accessible to whom.

What to look for: whether sharing is private-link (anyone with the link can access the album) or account-gated (only specific people can access). Whether there is an option to add a password on top of a private link. Whether access can be revoked after being granted. Whether the service distinguishes between view access and contribute access.

Question 4: What happens to the original file?

This matters for two reasons: quality and trust.

On quality: many services store compressed versions of photos, not originals. Some do this silently, in a mode labelled “storage saver” or “high quality” rather than “original.” Compressed photos cannot be fully recovered. If the original was not preserved, what you get back in an export is not what you put in.

On trust: a service that modifies your files without a clear explicit opt-in is revealing something about how it treats the relationship. If the answer to this question is vague, assume compression is happening.

The specific answer to look for: “the file you upload is the file that is stored, at original resolution.”

Question 5: How do I get my photos out, and what comes with them?

Portability determines whether you are locked in and what happens to your library if the service changes its terms, raises prices, or closes.

Specific questions to ask: can you export the full library as original-quality files? Does the export include metadata such as dates, locations, and album structure? Is export self-service, or does it require contacting support?

Does Google Photos actually scan your photos is a useful example of going through a specific service’s actual policy language for questions 2 and 5, rather than taking the marketing page at face value.

What Yogile’s answers are

Running Yogile through the checklist, using product behaviour rather than marketing language:

Default audience: Albums are private by default. Nothing is shared until you choose to share it. You determine who can see an album and who can add to it.

Scanning and analysis: No AI scanning of uploads. No advertising profiles built from your photo library. Photos are not analysed for training or ad targeting.

Access controls: Albums use private-link sharing by default. You can add an optional album password on top of the private link to control who can view or contribute. Guests can view or add photos without creating an account or installing an app. Links can be changed or revoked.

Original file: Photos are stored at original resolution. The file you upload is the file that stays. No compression, no resized replacements. Premium includes an additional backup of your original-quality photos.

Getting photos out: Export is available and self-service. The platform is available on web, iPhone, and Android.

These are narrow, checkable claims. What actually keeps your photos private beyond a password covers how these specific behaviours fit together as a set: private by default, optional album password, no analysis, originals preserved.

The area where Yogile’s design differs most from mainstream services is the combination of private-by-default storage with guest access that requires no account and no app. Most services that offer scanning protections require account creation to share anything, which creates a different kind of friction for families and groups.

Applying the checklist to services you already use

Running the same five questions against Google Photos and iCloud surfaces the concrete trade-offs on each axis.

Google Photos answers question 1 well: photos are private by default. On question 2, Google’s terms permit use of uploaded content to develop and improve services, including AI systems. The distinction between on-device and server-side processing is real but not simple. On question 3, access controls are solid, with specific-people sharing and family group options available. On question 4, the answer depends on storage mode: “Original quality” keeps originals; “Storage saver” stores compressed versions permanently. On question 5, export works via Google Takeout, though downloading your full Google Photos library without losing the metadata requires specific steps because Takeout separates date and location information from image files into separate JSON sidecar files.

iCloud Photos answers question 1 clearly: private by default. On question 2, Apple’s position is that most analysis runs on-device. On question 3, shared albums work well within the Apple ecosystem, though iCloud for Android users creates real access gaps when a household mixes device platforms. On question 4, originals are preserved. On question 5, export is available but requires specific steps.

What the checklist makes visible is that mainstream services have genuine strengths on some axes and real gaps on others. The choice is not between “secure” and “insecure.” It is between specific trade-offs on specific axes, named plainly rather than summarized with a badge.

What the checklist does not cover

Two things worth being explicit about.

First, this checklist does not address encryption in detail, though encryption is related to question 3. The five questions above focus on the behaviours that affect the majority of people using personal photo storage: whether photos are scanned, whether they are used for ad targeting, whether the original is kept, and whether access can be controlled. These are the axes most people mean when they say they want a secure photo storage app.

Second, the checklist only tells you what a service says it does. What makes a claim credible is specificity: narrow statements that can be checked against actual product behaviour. The narrower the claim, the more accountable it is. Vague assurances are easy to issue and easy to walk back.

The gap this exposes

The r/privacy KeepSafe discussion eventually landed on a real finding: a PIN code protects against one narrow scenario while leaving others completely open. What the audience was looking for, and what the app had promised, were different things because the word “secure” was doing more work than it could actually carry.

The same gap exists across the category. Most photo storage marketing uses security language that is not specific enough to verify. Most comparison articles do not apply systematic questions. Most people end up choosing based on brand recognition or UI preference and hoping the claims hold up.

Running five concrete questions against any service changes that. It produces an answer on specific axes rather than a summary impression from an adjective.

Start with whatever service you currently use for family photos. Run the five questions. What does it actually do on each one?

For a service that answers all five with specific, checkable product behaviour, Yogile’s secure photo storage page covers what we do and do not do on each one.