Apple Photos is a polished mainstream photo library for people already using iPhone, iPad, Mac, and iCloud. It is only worth treating as a privacy-conscious cloud photo option when iCloud Photos is protected with Advanced Data Protection.

Key points:

  • Local Photos libraries benefit from Apple’s device security, passcodes, and hardware-backed protections
  • iCloud Photos uses standard iCloud data protection unless Advanced Data Protection for iCloud is enabled
  • Advanced Data Protection adds end-to-end encryption for Photos and many other iCloud data categories, but you become responsible for account recovery
  • iCloud Shared Photo Library can stay end-to-end encrypted only when all participants have Advanced Data Protection enabled
  • Shared Albums and sharing content with “anyone with the link” are not end-to-end encrypted even when Advanced Data Protection is enabled
  • Some Photos metadata remains under standard iCloud data protection for service operation and compatibility
  • iCloud.com access is disabled by default with Advanced Data Protection; enabling web access gives Apple and the browser temporary access to data-specific keys
  • Advanced Data Protection availability can vary by region; Apple says it is not available to new users in the United Kingdom
  • If you cannot enable Advanced Data Protection, use an end-to-end encrypted photo service such as Ente Photos for cloud backup