Media Den logo

Media Den

← Blog

Photo Handling & Storage Matters

When you take a photo, it feels private by default: it's on your phone, in your pocket. That feeling doesn't carry over once the photo leaves your device. Most apps upload what you shoot to a server somewhere, and from that point on, whether it stays private depends entirely on how that server is set up. This year gave a few clear examples of what happens when our tools don't protect us.

A "private and secure" face-search tool exposed 9 million images

In August 2026, security researcher Jeremiah Fowler found that ClarityCheck, a people-search service whose reverse image search tells users it's "private and secure," had left more than 9 million image files sitting in an unsecured Amazon S3 bucket: roughly 450 GB of profile photos, screenshots, and other images of adults, teenagers, and children, in folders literally named "faces" and "profiles." The bucket's address was reachable by anyone, and it was sitting right in the company's own public website code.[1] A second misconfiguration let anyone type a name into a ClarityCheck URL and get back email addresses, phone numbers, and physical addresses for people with that name, no account needed. ClarityCheck's product works by taking a photo of someone and identifying who they are; the exposed database meant the same could happen to anyone whose face had ever passed through the service, regardless of whether they knew about it.

Now in this case, this is an example of someone else likely uploading someone else's photo. In that sense, you can't control what someone else does with a file you've already given them. But, you absolutely can ensure the files you do give them have had their metadata stripped, so at least they don't carry along the photo's location, device information, etc.

An AI photo app left everything open, no login required

In February 2026, researchers found that Video AI Art Generator & Maker, an Android app with over 500,000 downloads, was storing user uploads in a Google Cloud Storage bucket with no authentication at all. Anyone who found the address could browse it. The bucket held more than 1.5 million photos and 385,000 videos, going back to the app's launch in 2023.[2] Nothing was hacked in the traditional sense. The files were simply never locked in the first place. Again, don't trust these apps with your storage ownership! Also again, metadata removal!

Photo apps with a million downloads exposed location data with every image

The same month, three photo identification apps on the Play Store, including a dog breed identifier with half a million downloads, turned out to be leaking user emails, profile photos, and GPS coordinates for roughly 152,000 people.[3] The cause was a misconfigured Firebase backend, the same kind of mistake behind a long list of similar leaks. A photo taken to identify a spider ended up tied to the exact coordinates of where it was taken. Same takeaways as the other examples.

A stalkerware operator's own database was left unprotected

In April 2026, a security researcher found a public database holding 86,859 screenshots pulled secretly from one person's phone: private chats, photos, and messages spanning about a year.[4] The data had been collected by stalkerware and uploaded to a cloud dashboard for whoever installed it to view. That dashboard had no password. Anyone who found it could see everything the spyware had already stolen. Strong client side encryption would have prevented this likely.

The pattern

These leaks weren't remarkable. Users were just sharing files with intact metadata, via SaaS vendors whose quality is difficult to validate.

The fix for that failure mode isn't "configure the server more carefully," because mistakes have already been made here. First, sharing your photos and videos with intact metadata is giving away information that people can use to learn new things about you. Second, when you don't know where your files are going, you've lost control. Third, if the tool you're using doesn't support strong client-side encryption, those files are still just a breach away from being shared freely. Media Den solves all three of these issues.

How Media Den handles this

First, Media Den has zero server footprint, other than the blog you're visiting now.

The app simply has zero path for your files to go anywhere other than your own storage system, be that Amazon S3, iCloud Drive, Google Drive, or Microsoft OneDrive (Want another source? Hit me up on the support page). Because you own the storage system, you own the access, billing, governance, backups, logging, etc. The app has zero external logging, zero telemetry, and zero tracking.

Second, Media Den encrypts the data on your device, before uploading it to your storage system. This means that not even Amazon, Apple, Microsoft, or Google see the contents of your files - they just see jibberish. We also take great strides so that when the data is brought to your phone for local viewing, we store it again in an encrypted manner, only decrypting when necessary for viewing.

Third, Media Den makes a best effort attempt at removing as much metadata as it can (up to what you have configured it to do so) when you import items into the app. There are some edge-cases we surely haven't caught, with more exotic image and container formats, but we're continuing to find and cover these.

Learn more about Media Den →

Download on the App Store Download on the App Store

References

  1. Lily Hay Newman and Matt Burgess, Wired, "Reverse-Lookup Service Exposed Millions of Photos of People's Faces," August 19, 2026. wired.com
  2. Cybernews, "Android AI video generator app leaks 8M photos and videos," February 2026. cybernews.com
  3. TechRadar, "Top photo ID apps leak user data — over 150,000 thought to have been affected," February 2026. techradar.com
  4. Cybernews, "Tens of thousands of screenshots linked to European celebrity exposed in spyware breach," April 2026. cybernews.com