Kin Album
Can family photo apps see your photos?
Most can. Not because anyone is being sinister — because the features people like need to read the picture. Here is how to tell which kind of app you are holding.
Updated September 12, 2026
The short answer
Most family photo apps can open your photos on their servers, and most of them describe doing exactly that in their own privacy policies. It is not usually a secret and it is not usually malice. Searching your album by what is in a picture, grouping every photo of one child together, making the little year-in-review movie — none of those features are possible unless a computer at the company can look at the image. The question worth asking about any app is not whether the company would look. It is whether the company can.
“Private” means three different things
Almost every app in this category says it is private, and almost all of them are telling the truth about something. They are just not all telling the truth about the same thing. There are three separate promises hiding under the word, and only the third one is about the company itself.
- Private from the internet. No public link, no explore page, no suggested-followers, nothing a stranger can search their way into. This is the easiest of the three to deliver and nearly everyone delivers it.
- Private from other people you know. Only the relatives you invited can open the album, and you can remove someone. Also common, and worth checking the details — whether an invited person can download, forward, or re-share what they see.
- Private from the company. The staff, the servers and the software cannot open the picture. This one is rare, it is the only one that survives a change of owner or a change of policy, and it is the one the word “private” on a marketing page almost never means.
What an app can see when it can read your photos
If a company’s servers can open the file, everything derived from that file is available to them — and the useful features are built out of exactly those derivations. The clearest way to see what that means in practice is to read what the companies publish about it themselves.
FamilyAlbum’s privacy policy, last updated 18 August 2026, lists among the data it collects “perceptual hashes of photographs and video clips, feature vectors of users’ faces, the estimated gender and age of each user’s face, results of classifications of facial images of each user”1. The same policy files that under biometric information and sensitive personal information. Their developer, MIXI, explains the mechanism on its own innovation page: the app can “automatically identify faces by getting the feature vectors for each face from photos and videos”2, “facial/person recognition is performed on photos and videos using deep learning”3, and for search, “our AI calculates the semantic similarity between search queries and the content of photos and videos”4. A sticker feature is described as detecting faces and determining “pose and age”5.
Tinybeans’ privacy policy says the company “may use automated processes and machine learning to analyze User Content, User Submissions, Feedback and Responses”6.
Read those sentences as engineering, not as accusation. A face-grouping feature cannot exist without a numeric description of a face; a search box that finds “birthday” cannot exist without something having looked at the cake. The disclosures are what a company has to write down when it builds those features honestly. What they tell you as a parent is simply this: those photographs are readable, and the readable version is what the product is built on.
“Encrypted” is two different claims
Nearly every app uses the word. The two claims underneath it are not close to the same.
Encrypted in transit and at rest means the photo is scrambled on the wire between your phone and the company, and scrambled again on the disk it lands on. This is real and it is worth having: it stops someone on the café wi-fi, and it stops a stolen hard drive being readable. It does not stop the company, because the company holds the keys and has to — that is how the search box and the face grouping work at all. FamilyAlbum’s privacy page says “data transferred between your device and our servers is encrypted using the latest encryption technology”7. Keepr Circle describes its photos as “encrypted in transit and securely stored” and says it never sells them, trains AI on them, or scans them for advertising8.
End-to-end encrypted means the photo is scrambled on your own device, before it is uploaded, with a key the company never receives. The company stores something it cannot open. As one parent put it in r/NewParents in January 2026, “with end-to-end encryption it is verifyable that the platform provider can’t access any of the photos even if they wanted to”9. That is the distinction in one line: the first is a promise, the second is an arrangement. The cost of the second is real and shows up later on this page.
If a page says “encrypted” without saying which, assume the first. Companies that have the second one say so, because it is expensive and they want credit for it.
The AI question, specifically
This is where most of the 2026 arguments happen, and two different questions keep getting fused into one.
The first is whether your family photos are used to train somebody’s general-purpose AI model. The second is whether the app runs recognition over your photos to power its own features. They have different answers, and a company can truthfully say no to the first while the second is a documented part of the product.
FamilyAlbum is the case study, because parents had this argument in public. Its privacy policy lists Anthropic among recipients “to provide customer support and to improve search functionality”10. When people wrote to ask, the company replied that “no media, including photos or videos uploaded to the app, will be entered into the models for any purpose”11 — and several people in the thread reported getting the same answer. Meanwhile the face-clustering and recognition described above had been in the product, and on the developer’s own site, the whole time. One commenter made the distinction cleanly: “there is a big difference between training a custom model to sort your album vs putting it in a huge AI model”12.
Both things are true at once, which is why the argument went in circles. If what worries you is a general model learning from your child, the company’s answer addresses it. If what worries you is any software anywhere computing a description of your child’s face, the published documentation is the answer, and it is yes. Those are different fears and you are allowed to have either one.
How to check any app yourself, in ten minutes
You do not have to take a comparison page’s word for this — including ours. Every answer below is in documents the company publishes.
- Search the privacy policy for “biometric”, “facial”, “feature vector” and “machine learning”. The California disclosure section is usually the most specific part of any US policy, because the law makes it be.
- Search for “end-to-end”. If it is not there, the answer is no. Nobody who has it forgets to mention it.
- Look at the feature list and ask what each feature needs. Search by what is in the photo, automatic albums per child, auto-generated movies, smart stickers, people tagging — each one requires the server to read the image.
- Find the list of companies data is disclosed to. It is usually a short named list in the policy, and it is more informative than any marketing page.
- Check how you would leave. Whether there is an export, whether it costs extra, and whether it gives you originals. This is the question people wish they had asked, every time.
What Kin Album can and cannot see
Our answer to the question in the headline is no, and it would be worth very little if we did not also say where that stops.
Photos and videos are end-to-end encrypted. They are scrambled on your iPhone before they upload, and Kin Album holds no key. We cannot open them — not “will not”. There is no face recognition in this product, no content search, and no model that could run on your pictures even if someone wanted one, because what we store is not an image.
Three things sit outside that. Captions, comments and the names you type are stored readably, because the album has to work in an email and in a browser. The small preview image prepared when someone receives photos by email is prepared outside the encryption — off by default for a member, on by default for a relative who only has email, since a photoless email is an empty envelope to someone with no app. And ordinary metadata — when something was posted, who posted it — is visible to us the way it is for any service.
The cost is real. Encryption nobody can bypass includes us, so if you lose both your iPhone’s iCloud Keychain backup and your written recovery phrase, your photos genuinely cannot be recovered. There is no support ticket that fixes that. That is the trade: the same property that stops us looking stops us helping. We think it is the right trade for a child’s photographs, and you should know it exists before you make it.
One parent wrote in r/beyondthebump in June 2026, about an app they had trusted for years, “I really thought family album was safe, that’s literally why we use it”13. The point of this page is that you should not have to find out afterwards. Read the policy, ask what the features need, and pick whichever app’s honest answer you can live with.
Kin Album is a private family photo album where the company cannot open the photos. It launches on the iPhone App Store soon — join the waitlist and we will email you the day it does.
Join the waitlistSources
Every claim on this page about another company is quoted from something that company published, or from a dated post by a real person. The date beside each one is the day we last opened it and saw that text. Companies change their products and their policies — check before relying on any of it.
- Their own words FamilyAlbum — Privacy Policy, section 4 (How We Collect Your Personal Data); repeated in section 13.a under Biometric information and Sensitive personal information. Last updated 08/18/2026.
Perceptual hashes of photographs and video clips, feature vectors of users' faces, the estimated gender and age of each user's face, results of classifications of facial images of each user
Source Checked 2026-09-12. - Their own words MIXI, FamilyAlbum's developer — Innovation page for FamilyAlbum, under Personal Pages.
automatically identify faces by getting the feature vectors for each face from photos and videos
Source Checked 2026-09-12. - Their own words MIXI, FamilyAlbum's developer — Innovation page for FamilyAlbum, under 1s Movies.
Facial/person recognition is performed on photos and videos using deep learning
Source Checked 2026-09-12. - Their own words MIXI, FamilyAlbum's developer — Innovation page for FamilyAlbum, under Natural Language Search.
Our AI calculates the semantic similarity between search queries and the content of photos and videos
Source Checked 2026-09-12. - Their own words MIXI, FamilyAlbum's developer — Innovation page for FamilyAlbum, under facial recognition for stickers.
Detect faces in photos, determine pose and age, and filter out a child's face when it is profile
Source Checked 2026-09-12. - Their own words Tinybeans — Privacy Policy, section 2 (Information Usage).
Notwithstanding anything to the contrary herein, Tinybeans may use automated processes and machine learning to analyze User Content, User Submissions, Feedback and Responses (as defined below), which helps us to aggregate response data and activity, identify trends, build product features that optimize responses, make product recommendations and provide guidance on which content, products and services work best in different scenarios.
Source Checked 2026-09-12. - Their own words FamilyAlbum — Privacy summary page.
Data transferred between your device and our servers is encrypted using the latest encryption technology.
Source Checked 2026-09-12. - Their own words Keepr Circle — Their photo-privacy guide, under Choosing a private photo sharing tool.
Keepr Circle keeps your photos encrypted in transit and securely stored and, unlike ad-funded platforms, never sells them, trains AI on them, or scans them for advertising, so only the family you invite ever sees them.
Source Checked 2026-09-12. - A person, quoted the category — A commenter in r/NewParents, answering a parent asking whether FamilyAlbum was safe, January 2026.
With end-to-end encryption it is verifyable that the platform provider can't access any of the photos even if they wanted to.
Source Checked 2026-07-07. - Their own words FamilyAlbum — Privacy Policy, section 6 (Disclosure of Personal Data to Recipients). Last updated 08/18/2026.
Anthropic (to provide customer support and to improve search functionality)
Source Checked 2026-09-12. - A person, quoted FamilyAlbum — FamilyAlbum support's emailed reply, posted in full by a user in r/beyondthebump. Two people in the thread reported receiving the same text the same day, June 2026.
No media, including photos or videos uploaded to the app, will be entered into the models for any purpose.
Source Checked 2026-07-07. - A person, quoted the category — A commenter in r/beyondthebump arguing the opposite way in the same thread — that organising photos and training a foundation model are different things, June 2026.
There is a big difference between training a custom model to sort your album vs putting it in a huge AI model.
Source Checked 2026-07-07. - A person, quoted FamilyAlbum — A parent in r/beyondthebump, in the same thread, June 2026.
I really thought family album was safe, that's literally why we use it
Source Checked 2026-07-07.