Principle

Accountability first

Eyes Only protects images by a simple principle: remove metadata immediately, encrypt directly, and transmit only in encrypted form. Sharing outside the group is blocked by default.

Eyes Only compared

Eyes Only Messenger
(WhatsApp, Telegram …)
Cloud storage
(iCloud, Google Drive, …)
End-to-end encryption depends on app and chat type mostly server-side, optional with additional tools
Metadata (location, biometrics) removed immediately often transmitted as well often stored
No automatic cloud backup partly can be disabled core feature
Forwarding not possible partly restrictable
Screenshots blocked in some cases only warning notices
Automatic expiration date for images only for specific features partly via rules/versioning
Server sees no plaintext (blind server) metadata visible
Recipients do not need an account usually mandatory partly via link sharing
Access only via personal on-site verification
No export outside Europe global infrastructure possible with Nextcloud
Own server possible e.g. Nextcloud

Legend: ✓ = yes, ◐ = partially, ✗ = no

What "blind" means in practice

  • Metadata is removed during capture, before the photo is even shown to the photographer.
  • All photos and group information are stored in encrypted form.
  • Central storage serves only as an encrypted drop-off point.

Accounts and accountability

  • Server accounts exist only for responsible roles such as teachers or supervisors.
  • Regular participants do not need their own server accounts.
  • This reduces attack and abuse surfaces, while accountability remains clearly defined.

More control

Own server through open source

Eyes Only is open source. That is why the server can also be operated entirely in your own infrastructure.

Technically experienced teams gain an additional level of control: their own deployments, their own operating rules, and full transparency about where and how encrypted data is stored.