Skip to content
All posts

Keeping intimate photos private: where they actually go

The private photos you send your partner usually sit on a company's servers, readable. Here's where they go on ordinary apps — and what it takes to keep them truly between two people.

An old key on a wooden table — what it means to hold the only key.

Most couples share things meant for exactly one other person — a photo, a voice note, the kind of moment you'd never post anywhere. It feels private because the conversation feels private. The screen is small and the chat is just the two of you.

Send this

But the screen isn't where the photo lives. The question worth asking, before you send the next one, is simple: where does it actually go, and who can open it there?

On most apps, the answer is "their servers, readable"

When you send a photo through a typical messenger or couple app, it travels encrypted (good) and then lands on the company's servers in a form the company can decrypt (less good). That's normal, and it's how most features work — search, backups, previews, recommendations.

It also means your most private images sit in a database someone else controls. That exposes them to a few things you didn't sign up for:

  • Scanning and profiling. Some platforms analyze media to target ads or train systems. The "private message" you got an eerily relevant ad about wasn't a coincidence.
  • Breaches. Servers full of personal photos are exactly what attackers go looking for. A company's promise not to look doesn't help if someone else gets in.
  • Quiet policy changes. What a company can read, it can decide to use differently later. Your photos are only as private as this quarter's terms.

None of this requires anyone to be a villain. It's just what it means to hand your private things to a third party that holds the keys.

What actually keeps them private: end-to-end encryption

The only real fix is for the company to not be able to read your photos at all — even if it wanted to, even if compelled to. That's what end-to-end encryption (E2EE) means: your photo is locked on your device, and only you and your partner hold the keys to unlock it. The server stores a sealed box it can't open.

This is the standard for the things that matter most. It's why it's worth checking whether a couple app actually does it, or just says "secure."

How Arcov handles it

Arcov's Memory Vault is end-to-end encrypted. Photos, voice notes, and their captions are locked on your device with keys that live only on your and your partner's phones (XChaCha20-Poly1305, if you like specifics). We store the sealed box. We cannot open it. There are no ad SDKs and no data sales — not as a promise, but as an architecture, because we built ourselves out of being able to look.

We'll also be straight about the edges, because vague privacy claims are how trust gets broken: your vault contents, letters, and notes are end-to-end encrypted. A few operational things — your mood value, whether you're online — are protected in transit but readable on our side so the basic features work. We'd rather draw that line clearly than imply encryption covers everything.

Practical advice, regardless of app

  • Check whether the app says end-to-end encrypted, not just "encrypted" or "secure." They're very different.
  • Look for whether the company can recover your content. If they can, so can a breach or a subpoena.
  • Prefer apps with no ads — if the business isn't your data, your data isn't the product.

Sharing intimate moments with the person you love shouldn't mean trusting a company you don't. If that matters to you, it's the whole reason Arcov exists. The beta is open.