Security & privacy at PhotoLog

How PhotoLog protects your photos and videos — where encryption happens, where your data is stored, and how bring-your-own-storage fits in.

Photos and videos are encrypted in your browser before they are uploaded, so PhotoLog’s servers only ever hold ciphertext.

Photos and videos are encrypted on your device before they are uploaded, and the upload goes directly to object storage rather than through PhotoLog's own application servers.How encryption works is the full explanation — how the keys are organized, what PhotoLog can still see, and where the honest limits are.

How PhotoLog encrypts a file before uploadA photo or video exists unencrypted only on the device that holds it. That device encrypts it before anything is sent anywhere, then writes the encrypted bytes directly to object storage using a short-lived upload link — not routed through PhotoLog's own application servers. Storage receives and keeps only the encrypted result.Your devicePhoto(plaintext)Encryptedhere, beforeuploadDirect to storageEncrypted file(opaque)Not routedthrough PhotoLog'sapp serversObject storageEncryptedfile only
Your photo or video is unencrypted only on the device that holds it. That device encrypts it before it is uploaded anywhere, then writes the encrypted bytes directly to object storage using a short-lived, single-use link — the upload does not pass through PhotoLog's own application servers on its way there, and storage receives and keeps only that encrypted file, never the original.

Where your data lives

Encrypted media is stored in cloud object storage. Data residency names the specific storage posture; this page states only the encryption claim, not where the encrypted bytes physically sit.

Bring your own storage

Some PhotoLog plans let a studio connect its own storage bucket instead of using PhotoLog's. Where you store the encrypted bytes is a choice the customer controls — see bring your own storage — and it is a separate question from what PhotoLog can read, which this page and the encryption page answer.

What this page does not cover

  • Per-QR and per-event moderation. PhotoLog does not moderate what a contributor uploads to an event gallery today; any future moderation feature will carry its own label when it ships, and it is not part of the encryption architecture this page describes.
  • The specific storage region or certification your data sits under — see data residency for that claim, stated precisely rather than as a bare adjective.

More on security and privacy