We Can't Read Your Photos or Videos — Not Archivios, Not an Attacker, Not a Subpoena, Not a Breach
Published 2026-09-06
That's not a slogan — it's a direct consequence of how encryption is built into Archivios. When end-to-end encryption is on, your photos and videos are locked on your device before they're ever backed up, using a key that never leaves it. Everything that reaches our servers is ciphertext. Here's what that actually rules out.
Not Archivios
We built the backup pipeline, and we still can't open your files. The key that decrypts your photos is generated and stored on your device — we never receive it, never derive it, and never have a copy anywhere in our systems. What we store is an encrypted key blob that only your recovery code, another unlocked device, or your recovery contacts can unwrap — and we don't hold any of those either.
Not a data breach
If an attacker somehow got a full copy of our storage and database, they'd get exactly what we have: ciphertext and encrypted key blobs. Without the key that lives on your device, there's nothing to decrypt it with. A breach exposing plaintext photos isn't a "we tried our best" situation here — the architecture itself doesn't hold a copy of your photos in a readable form anywhere.
Not a subpoena
A legal order can compel us to hand over data we have — it can't compel us to hand over data we don't have. If we're asked, we can only turn over the same ciphertext an attacker would get. There's no master key on our side to produce, because one was never created.
Not an attacker
Same answer as the breach scenario: your device's key is what unlocks your photos, and it's protected there behind your device's own security (Face ID/passcode). Someone would need your device unlocked and your key, not just access to our servers.
The one honest exception
This isn't a pitch for a system with no trade-offs, so here's the part that matters: this same design means we can't recover your photos for you either, if every recovery path is gone. If you lose your recovery code, lose access to every device that already has the key, and never set up recovery contacts, those photos are unrecoverable — by anyone, including us. That's not a loophole in the encryption; it's the direct cost of it actually working the way it's described here. It's exactly why there are three separate ways to recover access on a new device, not one, and why recovery contacts exist as a safety net that doesn't depend on remembering a code.
Read more on how the recovery paths actually work: How end-to-end encryption works · Encryption, explained without the jargon.
Download on the App StoreTags: encryption, privacy, security, data breach, account recovery