About

About Miuchio

A private shared album, built by one person who wanted one.

What Miuchio is

Miuchio is a shared photo album for small groups: a family, a group of friends, the people from one trip. It is meant to be a quiet place to keep photos together, not a feed. Everyone in an album can add photos, and nobody outside it, including the server that stores them, is given the keys to open them.

Why I built it

I am a private person, and I have a lot of respect for software that respects the people using it. Photos are some of the most personal things we share: the people we love, our homes, moments we would never show a stranger. Yet most places we keep them can see inside, and what happens to them there is decided by the company, not by us.

I wanted sharing an album to feel simple, without giving the service access to the photos inside it. That is why photos are encrypted on the phone before they are uploaded, and why the database is designed to record as little about you as I could manage.

Miuchio has no ads and no data to sell. Even if nobody else ever uses it, I will gladly use it with my family and friends.

Who makes it

Miuchio is designed and built by one person, Freytastic: the protocol, the app, the server and these pages. When a page here says "I", that is who it means. More of my work is at freytastic.dev.

What that covers:

  • A custom end-to-end encryption design for shared albums: epochs, signed key changes, removal that holds up under races, and a database designed to reduce identifying metadata, with the links it still reveals documented. The parts that are mine are listed in the Protocol overview.
  • A Flutter app, with native code for the key store on Android and iPhone, and for image processing on Android.
  • A Go server with Postgres, Redis and S3 storage, which enforces the album rules without ever holding an album key.
  • Shared test vectors that make the Dart app and the Go server produce byte for byte identical handshakes, signatures and hashes.

The code is open

Miuchio's code is public on GitHub and will stay public. You do not have to take these pages on trust: every claim about the protocol can be checked against the code that implements it.

I would rather describe a limit plainly than let a page suggest Miuchio does something it does not. Every technical claim on this site is checked against the code, the limits have a page of their own, and the blog covers the mistakes along with the fixes.

I also plan to make Miuchio self hostable, so you can run the server yourself. That is not ready yet.

Where it stands

  • The app works and is being tested. It is not in the app stores yet.
  • There is no backup and no second device yet.
  • Self hosting is planned, not built.
  • The protocol has not had an independent security review.
  • Known gaps are listed on What Miuchio does not protect.

Get in touch

If you think something should work differently, open an issue or a pull request on GitHub. For anything else, reach me directly. I am most active on Signal, then Discord, then X. For a security problem, please message me privately rather than posting it; Report a security issue explains how.