Your photos. Nobody else's business.

ImageTome encrypts every image, video and word in your browser, before any of it reaches us. We hold the pieces on the right. Only you and the people you invite hold the key that puts them back together.

NO EMAIL · NO PASSWORD · NO TRACKING

What you see
What we store

Four steps, and we never hold a key

01

Your browser makes a key

No email, no password. Creating an account generates a keypair on your device. The public half goes to us so other people can share with you. The private half never leaves.

02

You make a tome

A tome is a private space with its own key. Its name and description are encrypted too, so even the label on the box is unreadable to us.

03

You add things to it

Images, video, posts and comments are encrypted in the browser before upload. What arrives at our servers is noise, and stays that way.

04

You invite people in

Inviting someone wraps the tome's key with their public key. Only their device can unwrap it. The key itself never reaches us in a readable form.

The honest part

Encryption this strict costs you things that other services give away freely. You should know what they are before you sign up, not after.

There is no password reset

Lose your key with no backup and the account is gone. We cannot email you a link, because we have nothing to send. Export a backup on day one and keep it in a password manager.

You cannot search inside your media

We can only index what we can read, and we cannot read any of it. You can browse a tome and sort by date. You cannot search for a face, a place or a word inside a photo.

Deleting really deletes

There is no trash to recover from and no thirty-day grace period. When you delete an image, a tome or an account, it is removed, and nobody can bring it back.

What you get

Images

JPEG, PNG, GIF and WebP, encrypted before upload. Thumbnails are encrypted too.

Video

MP4 and WebM, up to 200MB each, decrypted and played in the browser.

Posts

Write alongside your media. Titles and bodies are encrypted like everything else.

Comments

Talk about a photo underneath it. Every comment is encrypted with the tome key.

Invites

Bring people in by username. Their device unwraps the tome key; ours never sees it.

Messages

One-to-one conversations, encrypted the same way as everything else.

Questions

Then the account is gone, and so is everything in it. We never hold your key, so there is nothing for us to reset or restore. Export a backup as soon as you sign up and keep it in a password manager.

No. Encryption and decryption happen in your browser. What reaches our servers is a blob we have no key for. Someone who took a copy of our entire database would have a very large collection of noise.

A password can be phished, reused or leaked, and an email address ties your identity to your content. Here, the keypair in your browser is the account. There is no password database to breach because there are no passwords.

Each tome has its own key. When you invite someone, that key is wrapped with their public key, so only their device can unwrap it. The tome key never reaches us in a readable form.

Images in JPEG, PNG, GIF and WebP. Video in MP4 and WebM, up to 200MB per file. Video thumbnails are generated in your browser and encrypted before they are uploaded, like everything else.

Yes, and you should. Open your browser's network tab while you upload a photo and look at what actually gets sent. That is the only assurance worth having.

Your key is yours and your backup keeps working. We are building export so you can take your encrypted content with you and decrypt it yourself, independent of whether we are still here.

Start with one tome and see how it feels.

Creating an account takes a few seconds and asks you for nothing but a username.

Create an account