Common questions
Who can see your photographs, what leaves this archive and who receives it, how the faces get their names, and how safe it all is.
Frequently Asked
The six that come up most, answered plainly, and where the long answer sits.
Who can see my photographs?
The members of this archive, and nobody else.
More detail
Membership is not the same as having an account: signing up puts you in a queue, and the keeper of the archive has to let you in before a single photograph is drawn for you. Until then you see the waiting screen, and if they turn you down you see a closed door.
That check is asked again on every request rather than once at the sign-in page. Every page in the app resolves which archive you are in before it queries anything, and the route that serves the actual image files asks the same question before it hands over a single byte — a photograph's URL is not a key to it. Downloads go further and are keyed by id, so an id belonging to another archive is a “not found” rather than a file.
How does it know who people are in photos?
It doesn't. It groups faces that look alike, and a name only ever arrives because a person typed one.
More detail
Two models run over every photograph as it arrives, both on this archive's own computer: the first finds the faces in it, the second turns each face into 512 numbers — an embedding — which land close together for two pictures of the same person and far apart for two different people. What that produces is a group of faces that resemble each other, with nothing written on it.
The full account, and a diagram of a face becoming numbers becoming a name somebody typed, is in Faces below.
Does this app use AI?
Yes — ten jobs across three companies, four of which send the photograph itself. The face scan is not one of them: it runs on this archive's own computer.
More detail
Two of the ten run without anybody asking, both as a photograph arrives: one describes it, and one makes that description searchable. The other eight wait for a press or a typed search — a caption suggested, a scan enhanced, an occasion named, a search understood.
Every job, the company it goes to, what it keeps and how to switch it off is in What the AI does below.
What information of mine is sent elsewhere?
The photographs themselves, to be described, and words the archive has already written about them — never a name, and never anything that says who a face belongs to.
More detail
Five companies, in one breath: Anthropic reads the photographs and most of the words, OpenAI turns those words into numbers so a search can match by meaning, Topaz Labs enhances a scan when somebody presses the button, Google matches a place name to a real address, and Mux is what plays a video at all.
The AI work runs under zero data retention — the picture or the words go, the answer comes back, and neither is kept. Enhancement, video and maps sit outside that: a photograph sent to be enhanced is held for seven days, a video's playing copy is kept for as long as the video is here, and the map companies keep what their own terms say. Which job sends what is in What the AI does below.
Where does the information on this website come from?
Four places: what people type in, what the camera or scanner wrote into the file, what the face scan groups, and what the AI adds.
More detail
People. Any member can say something under a photograph and answer the questions on a person's page — several relatives can answer the same question, and you can edit or delete your own answer afterwards. Captions, dates, places, who is pictured, events, albums and pets are an archivist's to set.
The file itself. The camera or the scanner writes the date and time the picture was taken, the coordinates it was standing on, the make and model of the camera, and how many pixels across it is. A scan carries one thing more: the day the scanner's clock read, which is the evening somebody sat at the desk and not a claim about the photograph.
The face scan. Groups faces that resemble each other, and stops there. The names come from somebody working through Review → Faces.
The AI. A description and a handful of searchable words on every upload, and — only when asked for — suggested captions, a name for an occasion, and a paragraph about a public place.
Google. Turns an informal place name into a real address, and says what ground a photograph's coordinates were standing on. The nearest town to those coordinates is worked out here instead, from a list of the world's towns that ships with the app.
How do I add my own information?
Upload files, comment on any photograph, and answer the questions on a person's page. Captions, dates, people and places are an archivist's to set.
More detail
Each of those has one place it happens. Uploading is the Add photos button, and every delivery you have sent up is listed under Your uploads. Comments sit in the Info pane of an open photograph, under the picture. The questions — and the memories written under them — are on the Overview tab of a person's page.
That is narrower than it sounds, and here is what makes it enough: if you know something about a photograph you cannot change yourself — the year, the porch it was taken on, which cousin is on the left — say it in a comment or tell whoever keeps the archive. That is how it gets in, and it is how most of what is written here arrived. What each room is for is in The guide.
Who can see this
The gate, what it covers, and what other members can tell about you.
Is any of this public? Could a search engine find it?
No. There is no public URL to index, no “anyone with the link” mode, and no share token.
More detail
The files sit in private storage that nothing is served from directly — every image on every page has come through the app's own route, behind the membership check.
Share is honest about this rather than quietly making a hole in the gate: sharing a photograph either hands the file itself to your phone's share sheet — bytes you could already download — or copies a link, and the app tells you as it copies that the link opens for members of the archive. Public links are a feature somebody may eventually want, and they are deliberately not built.
Can other members see everything I upload?
Yes — there is one archive and one collection, and no per-photograph, per-album or per-person visibility anywhere in it.
More detail
A private corner would be a second class of access, and the whole design of the gate is that there is exactly one. So the rule is the blunt one: if something should not be seen by everyone the keeper of the archive has let in, it should not be put here.
Can other members see what I have been doing?
What you do to the contents is recorded and has your name on it; what is only about you is not.
More detail
Some of it, on purpose, and it is worth knowing which half. The activity feed under Admin records what people do to the contents — what was uploaded, edited, tagged, filed and deleted, and who did it. A shared archive needs an answer to “who moved that” which isn't asking around at Christmas.
What is kept out of it is everything that is only about you: your favorites, the marks you leave on photographs that need work, which people and places you have lately visited, and what you have said to the Curator. Comments are the obvious exception in the other direction — they are written to be read, and they sit under the photograph with your name on them.
The Curator is worth saying out loud, because a conversation feels like it evaporates and this one does not. Every message you send it, and every reply it gives, is written down and kept, so the panel can pick the thread back up on your next visit. They are filed against your name and nobody else's — there is no screen, for a member or an archivist or an owner or an admin, that shows somebody else's chat — and “Start over” hands you a clean sheet rather than burning what came before.
What can an owner or an admin do that I can't?
An owner keeps the roster and decides who gets in; an admin gets the back room — the job log, the activity feed and the AI ledger — and neither is a wider view of the photographs themselves.
More detail
An owner keeps the roster: they see everyone who has asked to join along with their email addresses, and they are the ones who let somebody in or turn them down.
An admin gets the back room — the log of what the background jobs have done, the archive-wide activity feed, the buttons that run a job by hand, and the ledger of every AI run and what it cost. An admin is also the only one who can say how a photograph was made — a scan, an enhancement, something a model drew — because that is a claim about the photograph rather than a note filed beside it. Neither role is a wider view of the photographs themselves: every member already sees all of those, the answer to how one was made included.
Faces
What the face scan is, what it is not, and how to correct it.
How does the face recognition work?
Two models run over every photograph as it arrives: the first finds the faces in it, the second turns each face into 512 numbers — an embedding — which land close together for two pictures of the same person and far apart for two different people.
More detail
How faces, embeddings, and names connect
The computer compares faces. You add the names.
A face in a photo
Each face is looked at separately.
A description in numbers
Similar numbers suggest similar faces.
A name you add
You confirm the person and add a name.
An embedding is not a name. It helps find possible matches. Matches can be wrong, so your corrections matter.
Both are files that ship with the app and run on its own server. No embedding, no crop of a face, and no name is sent to an outside service at any point: the comparison is arithmetic done next to the database. The photograph itself does go out, faces and all, and the AI section below says exactly when. This is also the cheapest job in the whole app, which is why it runs on every photograph and never asks.
Photographs, and only photographs. Video used to be read the same way — a dozen stills pulled from each one and put through the same detector — and that was taken out, because a digitised tape gave back more half-resolved strangers than Review could be worth: the people in front of the camera, and a row of unresolvable ones behind them, every one of which arrived as another group to name or dismiss. A video is not scanned at all now, and voice recordings never were.
So it knows who people are?
No — it only knows which faces resemble each other, so what it produces is a group of faces with no name on it.
More detail
That distinction is the whole design. A name only ever comes from a person typing one on Review → Faces.
Once a group has been named, faces that arrive later and land in that group are tagged with that name automatically — that is what makes naming one group worth doing. But the archive has never learned a name on its own, and there is nothing in it that could tell you who a stranger is.
It has grouped two different people together, or split one person in two.
Both are expected, and both are correctable from Review.
More detail
A group that is wrong takes not them? and the name comes off it; a group that is a statue, a reflection or somebody's shadow takes not a person and stops being offered. Naming two groups with the same name is how you tell it that a face fifteen years apart is one person, and the profile gathers them under the one name.
One person reliably owns several groups, and that is the tuning rather than a fault: the threshold is set one notch tighter than the last setting measured clean, because putting two groups together is a click and pulling a contaminated group apart is not.
Can I stop it scanning me?
Not with a switch — there isn't one today, and saying otherwise would be the comfortable answer rather than the true one.
More detail
Detection runs on every photograph as it is uploaded — not on video, per the answer above — and it is what makes anybody findable in an archive of thousands.
What you can do: untag yourself from a photograph, dismiss a group so it is never offered for naming again, and delete a photograph — which takes its faces and their embeddings with it in the same transaction, along with the file. If a per-person opt-out matters to you, it is a reasonable thing to ask the keeper of the archive for; it is recorded here as absent rather than as impossible.
Could my face be used to identify me somewhere else?
No — an embedding is a list of numbers that means nothing except against other embeddings made by the same model, and it is never sent anywhere.
More detail
It is stored beside the photograph it came from, it is never compared against anything outside this archive, and there is no service on the other end of it. The model itself is a public one — the numbers it produced about your family are not.
What the AI does
Every job, the company it goes to, what it keeps, and how to turn it off.
What is the AI doing to my photographs?
Ten jobs, three companies. Four send the photograph itself; the other six send only words the archive has already written about it.
More detail
Photographs do leave this archive, faces and all, to be described by an outside company. Nothing that says who is in them ever does: no name, no fingerprint of a face, no link to any other photograph.
Nearly every one of those trips is made under a setting that keeps neither the picture nor the answer. The ones that are not are named below, and one of them keeps a copy for seven days.
Two jobs run on their own when a photograph arrives — one describes it, the other makes that description searchable. Everything else happens only when somebody presses a button or types a search. The face scan is separate from all of it: it runs on the archive's own server, on every upload, and sends nothing anywhere. Nothing any of these jobs writes ever replaces what a person typed.
Are my children's faces sent anywhere?
The photographs are, faces and all. Nothing that says who a face belongs to ever is — no name, no fingerprint of a face, no crop.
More detail
The part that actually recognises a face. When a photograph arrives, this archive's own computer finds the faces in it and turns each one into a string of numbers — a kind of fingerprint, whose only useful property is that two of them taken from the same person land close together. Those numbers are what let the archive say “this is the same child as in these other forty photographs”.
That work runs here, on this archive's own machine, using files that ship with the app. No fingerprint of a face, no crop cut out around one, and no name is sent to any company, at any point, for any reason. The whole photograph is, and the next part says when. There is nothing held anywhere else that could be used to pick your child out of somebody else's photographs.
It also never decides who anybody is. It groups faces that resemble each other and stops; a name only ever arrives because a person typed one.
The photographs themselves — and a photograph of your children has your children's faces in it. There is no way around that sentence, so here is exactly when it happens.
Every photograph is sent once, as it is uploaded, to Anthropic, to be described so that it can be found by searching later. That one runs on its own, without anybody asking. What goes is the picture and nothing else: no names, no ages, no relationships, nothing the archive knows about who is in it.
Three more send a picture only when somebody deliberately does something. A search that asks about something only the picture can settle sends the few dozen it has already narrowed down. Pressing Enhance sends that one photograph to Topaz Labs. And pressing “Suggest a few” for a caption sends that one photograph to Anthropic — this is still the job that sends the most alongside a picture, and it is worth being plain about what that means: it sends who is tagged, how they are related, and whereabouts in the frame each tagged person is and how large their face is. But it never sends a real name — everybody tagged is swapped for a numbered stand-in first, so a caption suggestion is the one moment where a company is told “the child on the left is Person 2's daughter”, and the real name is filled back in here, before a suggestion is ever shown. Nothing else here sends that much alongside a picture, and nothing does it unless somebody presses the button.
Two things follow that are worth saying rather than leaving to be discovered. Nothing here treats a photograph of a child differently from any other. There is no separate rule, no age check, no exclusion — a family archive is mostly photographs of children, and the archive does not pretend to sort them.
And there is no way to exclude one person, or one photograph, from any of this. The switches are archive-wide and belong to whoever runs it. A per-person opt-out is a reasonable thing to want and a reasonable thing to ask the keeper of the archive for; it is recorded here as absent rather than as impossible.
Which jobs send the photograph itself?
Four — describing a photograph as it arrives, a second look during a search, suggesting captions, and enhancing a scan.
More detail
Writes a short description and a handful of searchable words, so a search can find a picture nobody ever captioned.
This is the only job here that runs on its own, without anybody asking for it. The photograph is sent once, read, and described, and the description is what lets a search for “birthday cake” turn up a picture that has never been labelled. It also writes down roughly how good a picture it is, which is what lets the archive lead with the ones worth looking at.
The company is sent the picture and nothing else about it. It is not told who is in it: names come from the face scan, and the face scan never leaves this machine.
A smaller copy goes rather than the full-size original — enough to read, not enough to print. The same protection applies when older photographs are described later.
When a search asks about something only the picture can settle — a colour, the words printed on a shirt — the few dozen photographs already narrowed down get looked at again.
Almost no search does this. It happens only when what you typed cannot be answered from words alone, and then only against photographs the rest of the search had already narrowed down to — at most forty, never the whole archive. The results page tells you how many were looked at, so a capped run cannot pass its handful off as everything.
It is the most expensive thing one press of Enter can do here, which is the other reason it is kept this narrow.
Five ways of captioning one photograph, for you to pick from, edit, or ignore.
The one to read twice, because it still sends more than any other job here: the picture, whereabouts in the frame each tagged person sits and how large their face is, and how those people are related to each other. But their names never go with it. Before the request is built, everybody tagged in the photograph is swapped for a numbered stand-in — “Person 1”, “Person 2” — everywhere their name would otherwise appear: in the list of who is tagged, in that placement and face size, in how people are related, in the caption already on the photograph, and in the sample captions and past suggestions shown alongside it. The company writes about “Person 1 and her sister on the porch”, and this archive puts the real names back before you ever see a suggestion.
That swap only covers people tagged in this photograph. The event and place names, and the sample captions themselves, can still carry a name — somebody not tagged here, or a family word like “Mom”. Nothing sends it unless you press the button, nothing is saved unless you pick one of the five, and picking none leaves the photograph exactly as it was.
Sharpens, cleans up or enlarges an old print or a soft scan.
The result arrives as a second copy that sits beside the original as its own tab, so you can flip between them. The original is untouched, and it is still what a download hands over unless you pick the enhanced copy by name. Topaz Labs keeps the photograph it was sent for seven days, and offers no setting that shortens that. This is the only job here that costs money by the press rather than by the word.
Which jobs send only words about a photograph?
Six. The picture stays here.
More detail
Turns a photograph's description and caption into numbers, so that “messy toddler” can find one described as “a child covered in cake”.
The only job here that goes to this company, and it never sees a photograph — only the words the archive has already written about one, plus a caption if somebody typed one. The words you type into a search go the same way, and only when searching for them literally has turned up nothing.
Turns “videos of grandma at the lake in the nineties” into the filters the archive already has.
What is sent is the words you typed, along with the archive's list of people, places and events by name — that list is how it can tell which June you meant. No photograph goes, and the search itself is not written down anywhere afterwards.
The helper in the sidebar, which listens to what you tell it about the family and proposes people, places and dates for you to accept or throw away.
It is sent what you write, and the archive's lists of names, pets and places so that it can tell one June from another. It is never sent a photograph.
A conversation with it feels like it evaporates, and it does not. Every message you send and every reply it gives is written down and kept, so the panel can pick the thread up on your next visit. Those are filed against your name and nobody else's — there is no screen anywhere in the archive, for any kind of member, that shows somebody else's conversation. “Start over” hands you a clean sheet rather than burning what came before.
Everything it proposes is a proposal. Nothing it suggests is written into the archive until you say so.
Answers a question about one photograph's faces — why somebody is not tagged, why a face was missed.
This one sends no photograph at all, only what the archive has already written down about that one: whether it has been scanned for faces, how many were found, who is tagged, and its stored description. It answers from that and nothing else — so it will tell you why a face is unnamed, and it will not guess who the person is or when the picture was taken.
Proposes a name and a description for a run of photographs the archive thinks belong to one occasion.
Sent only when somebody accepts a suggestion — never in the background, and never for a suggestion nobody has touched. What goes is what has already been read off the photographs: their captions, their dates, the place, and who is tagged. The answer lands in the blank fields of the form, where you can edit it before anything is saved.
Looks up a short factual paragraph about a church, a school or a cemetery — when it was built, what it is known for.
The one job here that goes looking outside for an answer rather than answering from what it already knows. The name of the place is searched on the open web, because a small-town church is exactly the subject a model will otherwise invent confidently and wrongly. So treat this as a public search: the place's name and address leave, the way they would if you typed them into a search engine yourself.
Never a family home. The button does not appear on one, on purpose.
Is anything sent to a company that isn't an AI?
Two: Google, which turns a place name into a spot on the map and says what a photograph's own coordinates are standing on, and Mux, which is what plays a video at all.
More detail
The words you type in the address box, or the one place you name to the Curator, go out to be matched to a real address.
This is the only way to learn that “the farm on Route 9” is somewhere real, rather than have a model invent a plausible-looking coordinate for it. The address box sends as you type; the Curator sends the one finished phrase. No photograph goes, ever.
One thing worth saying plainly, because it is the only place in the archive where this is true: the little map pictures on a place's page are fetched by your own browser, directly from the same company, rather than by the archive on your behalf. So for those pictures — and only those — the company sees the coordinates and your browser, without the archive standing in between.
A photograph that already knows where it was taken gets asked what is at that spot, so it can say “Epcot” rather than a pair of numbers.
Only the coordinates go, and only for a photograph whose camera wrote them into the file in the first place. The picture itself never does. A photograph with no location recorded is never the subject of one of these.
This one runs on its own rather than when you press something, which is what makes it worth naming separately from the address box above. It asks a tight circle — roughly 150 metres — and where that circle answers nothing, the archive falls back to the nearest town worked out here, from a list that ships with the app, with nothing sent anywhere.
A copy of every video, so that it can be played at a size a phone can actually stream.
The copy is kept for as long as the video is in the archive. The original file never leaves storage the archive controls, and it is still what a download gives you. Videos are also the one thing never scanned for faces — voice recordings never were either.
What do those companies keep afterwards?
AI analysis runs under zero data retention — the picture is passed along, the answer comes back, and neither is kept. Enhancement, video hosting and maps sit outside that.
More detail
AI analysis goes through the Vercel AI Gateway with zero data retention required on every model request. This applies to descriptions, captions, searches, conversations, and the numerical representations of text used for search, including analysis of older photographs. Requests go only to providers covered by the Gateway's zero-retention agreements, which also prohibit using those requests to train their models.
This limits what the provider keeps after processing; the photograph or words still have to be sent for the job to work. The archive keeps the resulting descriptions and other answers so you can use them here.
Pressing Enhance sends the photograph directly to Topaz Labs, which keeps it for seven days, outside that guarantee. Video hosting and maps are separate services: Mux keeps a copy of each video so it can play, and Google receives place names and map requests. Their retention is governed by their own terms. Zero retention for AI analysis does not mean that everything outside this archive keeps nothing.
What this archive does control is how little goes out in the first place, which is why the jobs are drawn as narrowly as they are: nothing is sent that could have been worked out here, enhancement never runs unasked, and the job that runs on its own sends the picture without a single name attached.
What stays on this archive's own computer?
The face scan, the thumbnails, the format conversion, the duplicate check and the date guess — all of it, sending nothing anywhere.
More detail
These are the reason a photograph uploaded with every job above switched off still arrives with its faces found and its thumbnails made.
finds the faces in a photograph and groups the ones that look alike. It runs on this archive's own computer, and nothing it works out — no fingerprint of a face, no grouping, no name — is ever sent anywhere. The photograph itself is another matter, and the answers above that send a picture say when it goes, faces included. Caption suggestions are the one job that sends anything derived from the scan — see “Are my children's faces sent anywhere?” above.
the smaller copies that let a page of photographs load quickly.
so that a picture taken on an iPhone shows up in any browser.
by comparing the pictures themselves rather than their file names.
for an undated photograph, worked out from the ones it arrived with and the people in it. Offered to you, never written down until somebody agrees to it.
What can the AI never do?
Decide who is in a photograph, delete anything, overwrite what a person typed, or set a date.
More detail
Four things nothing here is able to do, and the reason each one holds.
The face scan groups faces that resemble each other and stops there. A name only ever comes from a person typing one.
No job removes a photograph, a tag, a caption or a comment. Nothing here can take something away.
Everything it writes is an addition, kept beside the photograph and editable. What you typed is never contradicted afterwards.
A date comes from the camera, from an occasion, or from a person who knows. A wrong date spreads through everything sorted by time, so no model is allowed near one.
Can it be turned off? What stops working?
Yes — archive-wide, by whoever runs it. Video is the one real loss: it stops playing.
More detail
Whoever runs the archive can switch these off, and they go off for everybody rather than photograph by photograph. There is also a separate switch for the one job that runs on its own, so that new photographs stop being described while everything else carries on.
A job that is off fails quietly and on purpose. With describing off, a photograph still uploads, still gets its faces, still gets its thumbnails, and still appears everywhere it should — it simply arrives without a description, and a search then finds only the words people typed themselves. With enhancing off, the button is gone. With the address lookup off, a place is filed under the name you gave it and nothing more.
Video is the one real loss, and it is worth being plain about. The company that plays video is not adding something to a video — it is what plays it at all. With it off, a video still uploads, still keeps its original file safe, and can still be downloaded, but it never plays inside the archive: it sits at “Processing…” instead.
A switch for one person rather than for the whole archive does not exist today. If that matters to you it is a reasonable thing to ask the keeper of the archive for; it is recorded here as absent rather than as impossible.
What does it cost, and who can see?
Every request is counted and recorded; enhancement is the one whose runs are listed inside the archive, on a page under Admin.
More detail
What is recorded is which job it was for, which company answered, and how much of it there was. The enhancement page under Admin says which photograph, who pressed the button, and what it cost. The rest is recorded where whoever runs the archive can read it, though not on a page in here.
Describing older photographs uses the same protected service and standard prices as describing a new upload. The archive gives up the cheaper batch option because it requires photographs to be kept. Guessing a date costs nothing at all, because that work happens here.
What happens when it gets something wrong?
You edit it. Everything it writes is an addition, and what you typed is never contradicted afterwards.
More detail
It will, sometimes — a description that misses the joke, a searchable word that is nearly right, a caption that reads like a stranger wrote it. Because everything it writes is an addition rather than a replacement, the fix is simply to edit it.
Dates are where this is taken most seriously, because a wrong one is contagious — everything sorted by time inherits it. Nothing any of these jobs writes ever touches a date.
Dates
Photographs dated by a phrase, and where they land in the timeline.
I only know roughly when a photograph was taken. What do I enter?
Type it the way the family says it: “Summer 1975”, “December 1962”, “Christmas 1985”, or just “1962”.
More detail
Everywhere a date can be entered — the upload desk, the photograph's details panel, the bar that appears when you select several photographs — there is a second field beside the exact one for exactly this, and the two are exclusive: a photograph carries a real date or a phrase, never both. The phrase is kept as the words you gave it, and those words are what every screen shows — the archive never rounds “Summer 1975” into a date and prints that back at you.
Vaguer is fine too. “The seventies” is a real answer and better than nothing — a photograph with any phrase on it counts as dated, not undated, because somebody wrote something down.
How can “Summer 1975” sort in between real dates?
Behind the words, the archive files each phrase on a stand-in day and sorts by that.
More detail
A month and a year land on the first of that month; a year alone on January 1st; the seasons on a fixed day apiece — Spring on March 19th, Summer on June 20th, Fall or Autumn on September 21st, Winter on December 20th; and the named holidays on their own days — Christmas December 25th, Valentine's Day February 14th, and Easter, which really moves from year to year, pinned to April 5th. The stand-in day is a shelf position rather than a claim: the photograph still reads “Summer 1975” everywhere it appears, and the one place the day itself is shown is the “Sorted as” line under More details, where it is named as the stand-in it is.
The date filters read the same placement, so “Christmas 1985” turns up under a December filter and a 25th filter, and “Spring 1972” under March. The honest edge of that: a photograph dated just “1975” sits on January 1st, so it answers a January filter too. And a phrase with no year in it at all — “the seventies” — gets no shelf position: it sorts by when it arrived, and is reachable with the date filter off.
Your files
What is kept, what is a copy, and what happens when something is deleted.
What happens to the original file I uploaded?
It is kept, untouched, and it is the thing the archive is actually for — and that goes for all four things you can put here: a photograph, a video, a voice recording, a document.
More detail
Everything else — the thumbnails on the grid, the JPEG made so a browser can render a HEIC, the M4A made so a browser can play an old voicemail, the enhanced copy — is a copy for showing, and none of them is ever offered in the original's place. A download hands over the bytes you uploaded, under the name you gave them.
If I delete a photograph, is it really gone?
Not right away — deleting moves it to Recently deleted, where it sits for 60 days, restorable the whole time. What leaves the archive at the end of that has still not left the off-site backup.
More detail
Its people tags, comments, favorites, and place in every album come back with it exactly as they were, because none of that was touched.
After 60 days, or sooner if it's deleted forever from that screen, it goes for real: the record and everything hanging off it in one motion — its faces and their embeddings, the description and keywords, the transcript, the comments, the favorites, its place in every album. Then the files — original, preview, enhanced copy, and every stored thumbnail.
Two things stay. One is a line in the activity feed saying it was deleted, and by whom. A record of what is no longer there is the part of a shared archive that cannot be reconstructed later, and it holds the name rather than the photograph.
The other is the weekly off-site copy at Backblaze B2 — the second copy described under How safe this is. That copy is written once and never written over, which is what lets it survive a mistake made here; the same property means a deletion made here does not reach it. Nothing takes a photograph back out of it on a schedule either, so a photograph that has to come out of the backup as well comes out by hand, done by whoever runs the archive. The exception is a photograph uploaded and deleted inside the same week, which the backup may never have copied in the first place.
Where do the files actually live?
In one private object store, controlled by the family's deployment, with the archive's database beside it.
More detail
The credentials for it belong to the deployment and not to any person, nothing is served out of it directly, and the app is the only door.
Can I get everything back out?
One at a time, yes, and what comes out is the original — but there is no way to take many at once.
More detail
Nothing is re-encoded or shrunk on the way, and it carries the filename the family gave it. Open a photograph and the Download button is under it. Where a second version exists the button asks which you want: the JPEG copy of a HEIC that opens anywhere, the enhanced copy if somebody made one, the 1080p MP4 of a video that attaches to an email. The original is what you get unless you pick one of those by name.
On a phone there is a second door beside Download, because the first one leads to Files and a photograph belongs in Photos. Save to Photos hands the file to the phone's own share sheet, which offers “Save Image” next to AirDrop and Messages, and the picture lands in the camera roll where everything else on the phone can find it. Same bytes either way. A very large video is offered Download only — the share sheet needs the whole file in memory at once, and a phone would rather kill the tab than let that happen.
A selection from Photos & video and a whole album from its page were both meant to come down as a zip, and neither is built — selecting photographs works, but what the bar that appears when you select several photographs does with them is edit and file, not download. Getting a large archive out in one motion is the obvious thing to want and it is honestly missing; it is recorded here as absent rather than as impossible.
How safe this is
How many copies there are, what would have to go wrong to lose one, and who is paying for it.
Is there a backup? What would it take to lose all of this?
Yes — every original, and the database rows that say what it is, is copied to Backblaze B2, a storage company with no other role in this archive, on a weekly schedule.
More detail
That schedule also reads a sample back and hashes it to prove the copy is still byte-for-byte right. It is on top of the redundancy already inside each service the archive depends on, which only stands between a photograph and a single failed disk. It does not stand between a photograph and an account closed by mistake, a company that stops operating, or a change nobody catches in time — which is what the second copy is for.
The restore has been rehearsed, not just assumed: rebuilding the database from a dump and reading the files back from B2 has actually been done, once, end to end, against a database made for exactly that and thrown away after. What is still missing is a written succession plan — who else could reach the accounts this depends on, and what they would do — a different, unbuilt half of the same problem.
How many copies of my photograph are there, and where?
Two: the file you uploaded, in private storage the family's deployment controls, and a second copy written to Backblaze B2 within a week of upload.
More detail
The file you uploaded is the copy of record, whether it is a photograph, a video, a voice recording or a document, and the B2 copy is checked against it on a schedule after that. The thumbnails, the browser-friendly copy of a HEIC, the version that streams when you press play: none of those are backed up separately — they are made from the original and can be remade from it, so losing one costs time, not the photograph itself.
The two do not go away together, which is the point of having a second one. Deleting a photograph forever removes the first copy and leaves the second sitting in the backup; taking it out of there as well is somebody's job rather than a schedule's. The deletion answer under Your files says what that means in practice.
If something is deleted or changed by mistake, can it be undone?
A deleted photograph, yes — 60 days in Recently deleted. A changed one has no button: the database can be wound back for up to seven days, and past that there is only the activity feed.
More detail
Two different answers, because “undone” means different things here. A deleted photograph is the easy case: 60 days in Recently deleted, restorable the whole time, with its people, comments and place in every album coming back exactly as they were.
A changed one is the harder case, and there is no button for it. Overwrite a caption, untag somebody, reorder an album — the database behind it can be wound back for up to seven days. Past that, the only record of what happened is a line in the activity feed naming who changed what and when, which is enough to put right by hand but is not the same as an undo.
What happens if whoever pays for this stops paying?
The site is the first thing to go, and there is no arrangement written down today for who would take the bill over.
More detail
Four companies are paid, monthly, from one person's card, to keep this running: hosting, the database, the storage that holds every photograph and video, and the service that plays video back. Together it runs somewhere around fifty dollars a month, and it is not free to anyone who runs it.
If that stops, a host does not keep serving an archive nobody is paying for. The database and the storage accounts behind it run on their own billing cycles and last longer on their own, but the same thing eventually happens there too: no provider keeps a family archive for free once payment lapses. What that makes worth doing now, while it still works, is exactly the question above about getting everything back out.