Security

How your photos are protected

Photos and videos are encrypted on your iPhone before they are uploaded. Each file gets its own encryption key; that key is wrapped under your family’s album key, and the album key is only ever granted to your family members’ devices — sealed to keys held on their iPhones and in the web browsers they use to open the album. Our servers store ciphertext and wrapped keys. We cannot decrypt your photos or videos, and neither can anyone who compromises our storage, with the two exceptions below: email preview copies, and invitations sent by email.

A few things sit outside that encryption so the product can work, and we say so plainly:

The full design, including key rotation and what happens when someone is removed from an album, is documented and available to security researchers on request.

The encryption uses standard, well-studied primitives: Apple’s CryptoKit on the iPhone, and the browser’s built-in Web Crypto on the web. We do not invent our own ciphers. Independent review of the design is part of our roadmap; findings from good-faith research are welcome below.

Reporting a vulnerability

If you believe you have found a security issue in Kin Album, email security@kinalbum.com. Include enough detail to reproduce the issue. We will acknowledge your report within 3 business days, keep you informed as we investigate, and credit you when a fix ships if you would like credit.

We will not pursue or support legal action against good-faith security research that respects our users: do not access other families’ data beyond what is needed to demonstrate the issue, do not degrade the service, and give us reasonable time to fix before public disclosure. Machine-readable details live at /.well-known/security.txt.