My son was just born, and while a few photos will go on the likes of Facebook and Instagram, overall my partner and I are wanting to keep our shared photos private from the EULA abuses that we all know and hate.

Does anyone here have any good suggestions? I would create my own front end, but I can’t swing hosting or a static IP to do it from my local box. Are there any companies out there who aren’t total shit bags who claim immediate irrevocable license to all of my photos to do with whatever the fuck they please?

        • shastaxc@lemm.ee
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          9 months ago

          Nice. I’ve heard good things about it previously and it seems like it’ll check all my boxes. I’ve just been trying to figure out what to do for monthly backups to the cloud. I don’t wanna risk losing all my extended family’s photos in a hurricane or house fire.

    • daq@lemmy.sdf.org
      link
      fedilink
      arrow-up
      3
      ·
      9 months ago

      Seems too expensive. Most people that owned a phone with a camera for the last few years would easily be in the $200/yr plan. I know I am.

      That’s the cost of Amazon and Walmart subscriptions combined just to get one benefit of Amazon subscription.

      I realize people here tend to shit on Amazon, but they never leaked anyone’s photos so unless you share them yourself, they are perfectly safe in AWS cloud with unlimited storage.

  • Imprint9816@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    20
    ·
    9 months ago

    Proton offers a cloud photo storage similar to Googles but its all E2EE. A bit clunky compared to google but much more privacy friendly.

    • Sips'@slrpnk.net
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      Been a customer for half a year here now and it is such a good service! Easily worth the cost. Highly recommend checking out there website to go through their feature set, their level of transparency is beyond good 🙌

  • Dessalines@lemmy.ml
    link
    fedilink
    arrow-up
    10
    ·
    edit-2
    9 months ago

    I self-host Photoprism, and use it to share albums privately with people.

    The flow goes:

    • I take pictures with my phone
    • Those get synced via Syncthing to my photos folder.
    • Photoprism is set up via docker, with my photos folder added.
    • neutron@thelemmy.club
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      It can become really messy if one family member deletes a picture by accident and everyone complains. I’d use Syncthing for machines I personally manage.

  • CaptainSpaceman@lemmy.world
    link
    fedilink
    arrow-up
    6
    ·
    9 months ago

    Best guess would be a privacy focused chat app like Signal or Matrix.

    Otherwise you may want to look at crypto bases file storage ala Filecoin or potentially even Pixelfed

    • Adalast@lemmy.worldOP
      link
      fedilink
      arrow-up
      5
      ·
      9 months ago

      This could be a good option. I will have to look into it. I know some of our family is not the most savvy (lucky to be able to use FB) so I may have to look into building a front end on top of it for them, but this is a solid start.

  • hitmyspot@aussie.zone
    link
    fedilink
    arrow-up
    4
    ·
    9 months ago

    While self hosted will obviously be better, you have to balance that with simplicity for non tech users.

    We use the paid app tinybeans. Doing it now, I’d consider hosting a stability photos folder.

  • brian@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    9 months ago

    I know you said you can’t do your local box, but there’s no necessity for a static IP to do that. Dynamic DNS is relatively easy to set up, I suppose provided you have a domain name you own (which you can find for very reasonable prices).

    • BearOfaTime@lemm.ee
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      Or setup Tailscale and enable the Funnel feature for whatever service you want to expose.

      This way it’s a bit more secure, since the exposed endpoint is hosted by Tailscale and routed to your device via your Tailscale (encrypted) network.

      Using Funnel, no one needs to have the Tailscale client.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      9 months ago

      Dynamic DNS only works if your IP is publicly routable. My ISP (not sure about OP) puts us behind NAT, so the only way to expose services on my network is through a tunnel, like a VPN.

      But many ISPs do provide a routable IP. My last ISP did, so it’s not uncommon.

      And you don’t necessarily need to own an IP, services like FreeDNS let you use a subdomain from someone else, but a domain can be as little as $1/year (for TLDs like .site and .store), so it’s probably better to just get one. I have like 10 domains, and they only cost $10/year each or so. But if you just want to try out hosting something, using someone else’s isn’t a bad way to go.

  • DeuxChevaux@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    9 months ago

    I use DokuWiki for this type of thing. With a few add-ons it is nicely configurable (galleries, discussions etc), could be run from any webspace, and doesn’t need a database. You can have ACLs that make sure that only registered users get access. But it is a bit of a DIY solution, and takes a bit of work to set up.

    • Adalast@lemmy.worldOP
      link
      fedilink
      arrow-up
      3
      ·
      9 months ago

      I’m not above getting my hands dirty and this sounds like it could have promise. Thank you.

  • Olivia@lemmy.today
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    9 months ago

    If you and your partner both have iphones then iCloud should be sufficient for keeping the photos to yourselves if you turn on Advanced Data Protection. I think it requires you and your partner to have two yubikeys at a minimum though.

    https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f

    Photos encrypted at rest, only you and your partner will have access to the keys. If you want the convenience of icloud backup then the government would be able to subpoena your decryption keys from your phone backups, but it’s not going to be available for casual employee access. Automated tagging/face matching is done by your iPhone when it’s plugged in so there’s some organization. Nothing close to Google’s AI organization.

    I know Apple is a shit company. But they’ve learned a thing or two after the Fappening.

    Advanced Data Protection should be the minimum setting for you to consider Apple as your photo storage. Your photos will auto upload from your phones, apple has partner sharing so photo libraries will automatically be shared between you and your partner, and they recently implemented a system similar to “signal key verification”, but again limited to ADP turned on.

    Otherwise you’re looking at Proton or Tresorit.

    • Adalast@lemmy.worldOP
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      I will happily look at the alternatives. We avoid Apple like it carries the plague, mostly on my objections to their licensing policies alone. Also, I love that you linked to something about The Fappening, have a 💯 and my heartiest appreciation for you as a scholar and a gentleman.

  • anamethatisnt@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    9 months ago

    Synology has QuickConnect which makes external access easy without dyndns/static ip. I haven’t used it myself.
    https://kb.synology.com/en-global/DSM/tutorial/share_File_Station_files_without_DSM_account

    Another option is to create a Microsoft 365 Business tenant, with a single Business Basic license you get 1TB OneDrive storage and 1TB Sharepoint storage - their ToS says not to use customer data in AI training.
    Unless you already know how to manage it this is probably as cumbersome as selfhosting though.
    I have no idea about their ToS against non business licenses, so this assumes spending for a business basic license.

    If you aren’t behind CGNAT you can use dyndns to get around not having a static ip if you want to get into selfhosting with proper external access. I doubt you’ll have the time with a newborn though. :)

    • Adalast@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      ·
      9 months ago

      I will look at QuickConnect as that sounds potentially ideal.

      I honestly don’t trust MS as far as I could throw them. The amount of ads they are forcing into the OS level is evidence enough for me to believe that they are willing to abuse customers. And if DropBox is any indication of how ToS and EULAs can change in the blink of an eye to include all files, past and present, to be used for AI training with no recourse to opt-out, then MS’s current ToS doesn’t really give any fuzzy feelings.

      I will definitely have to look at dyndns as I need to find a way to provide a static endpoint to gain access to ethically sourced AI training materials for my own works and that sounds like it might work.

      And yes, I do work in AI, which is why I am so focused on not allowing the megacorps to ignore even the most basic regimes of ethics or customer respect.

      • anamethatisnt@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        9 months ago

        I would pair a Synology NAS with at least one, preferably two, usb disks to make local backups to with the built in Hyper Backup - losing the whole family picture archive hurts and usb disks are cheap. It doesn’t seem possible to make a read only QuickConnect connection so beware of that if there’s to be non techie users connecting.

        Personally I use dyndns and openvpn (if I rebuilt today I would look at Wireguard instead of openvpn as a vpn solution) as I prefer not relaying my traffic through services outside my self hosting. That would require you to aid your non techie family members with the initial configuration on their end though.