What "blind" means in practice
- Metadata is removed during capture, before the photo is even shown to the photographer.
- All photos and group information are stored in encrypted form.
- Central storage serves only as an encrypted drop-off point.
Principle
Eyes Only protects images by a simple principle: remove metadata immediately, encrypt directly, and transmit only in encrypted form. Sharing outside the group is blocked by default.
| Eyes Only |
Messenger (WhatsApp, Telegram …) |
Cloud storage (iCloud, Google Drive, …) |
|
|---|---|---|---|
| End-to-end encryption | ✓ | ✓ depends on app and chat type | ◐ mostly server-side, optional with additional tools |
| Metadata (location, biometrics) removed immediately | ✓ | ✗ often transmitted as well | ✗ often stored |
| No automatic cloud backup | ✓ | ◐ partly can be disabled | ✗ core feature |
| Forwarding not possible | ✓ | ◐ partly restrictable | ✗ |
| Screenshots blocked | ✓ | ◐ in some cases only warning notices | ✗ |
| Automatic expiration date for images | ✓ | ◐ only for specific features | ✓ partly via rules/versioning |
| Server sees no plaintext (blind server) | ✓ | ✗ metadata visible | ✗ |
| Recipients do not need an account | ✓ | ✗ usually mandatory | ◐ partly via link sharing |
| Access only via personal on-site verification | ✓ | ✗ | ✗ |
| No export outside Europe | ✓ | ✗ global infrastructure | ◐ possible with Nextcloud |
| Own server possible | ✓ | ✗ | ◐ e.g. Nextcloud |
Legend: ✓ = yes, ◐ = partially, ✗ = no
More control
Eyes Only is open source. That is why the server can also be operated entirely in your own infrastructure.
Technically experienced teams gain an additional level of control: their own deployments, their own operating rules, and full transparency about where and how encrypted data is stored.