Encryption is one of those words that gets used to mean "safe", which is not specific enough to be useful. Here is exactly what Keepr does, in the two places it matters, and what each one is actually protecting you from.
Everything you send travels over HTTPS#
Every request between your phone or browser and Keepr is encrypted in transit, including the photo and video uploads themselves. Nobody sharing a cafe's wifi with you is reading your pictures off the network.
Photos and videos are encrypted at rest with AES-256#
Your files live in cloud storage that Keepr rents and controls, run by a company called Wasabi. Every object written there is encrypted before it touches a disk, using AES-256, with a separate key generated for each individual file.
This is not something you switch on, and it is not something Keepr had to remember to ask for. It is how that storage works, which means it has applied to every file you have ever uploaded, including the first one.
Messages get a second layer, applied by Keepr itself#
Circle chat is the one place Keepr adds its own encryption on top. Message text is encrypted with AES-256-GCM before it is written to the database, so it is not sitting there in readable form.
Are my messages private covers that in full, including who can read a circle's conversation.
None of it is end-to-end, and here is the honest difference#
End-to-end encryption means the key never leaves your device, which makes the provider unable to read anything at all. Keepr is not built that way. The keys belong to Keepr and to its storage provider.
What that changes is narrower than it sounds, and it's worth setting out exactly. Your content is decrypted automatically, at the moment something has to be shown to somebody who already has access: a thumbnail so a grid loads quickly, a video ready to play, an album packed into a download, a picture indexed so your own search can find it, a message delivered to the circle it belongs to. That list is the whole of it. Nobody browses your library, none of it goes to another company, and none of it is used for advertising or to train a model.
So the difference is where the guarantee comes from. With end-to-end encryption it is mathematics. With Keepr it is how the product is built and run. That is the weaker of the two, which is exactly why you will not find the phrase "end-to-end" anywhere on a Keepr page, and why this one exists to say so plainly instead.
What encryption is not the answer to#
A few things people reasonably expect encryption to cover, which it doesn't:
- Who can see a photo. That is decided by album access, not by cryptography. There are exactly five ways somebody reaches an album, and they're listed in Who can see your photos.
- Someone you already shared with. Once a photo is in a circle, the people in that circle can see it. Encryption has no opinion about that.
- Your unlocked phone. Photos you've viewed are cached on your device so they load quickly, and anyone holding your unlocked phone can open the app.
- A signed-in device you've forgotten about. Worth a look at Where you're signed in rather than at anything to do with ciphers.
Nothing is handed to another company to be analysed#
Keepr's search index and its duplicate detection run on Keepr's own servers. No photo is sent to an outside AI service, sold to anyone, or used to train a model. See How search understands your photos.