That’s my next project to get things from Google/Apple.
The options I’ve seen so far
- Immich: great if you can self-host, but I prefer not to, so that’s out for me
- Nextcloud on a VPS (Hetzner or others): you need E2EE to prevent the providers from seeing your photos, but then all the apps like Memories etc don’t work ( https://help.nextcloud.com/t/end-to-end-encryption-nextcloud/237705/3 )
- Ente: has E2EE embedded, the face recognition happens on the clients. Can be self-hostable, so that gives more trust that other providers can launch their own European instances in the future.
- https://zeitkapsl.eu/en/ : has E2EE, but no self hostable option, so you kind of have to trust them that they implement their design (which is actually kind of nice: https://zeitkapsl.eu/en/e2ee-architecture/ . They have a security audit on their roadmap (announced 8 days ago: https://zeitkapsl.featurebase.app/en/p/formal-security-audit )
Any option I am missing?


I mean… Depends on your threat model. Hetzner is a very reputable German hoster. The only way someone is going to try and read and puzzle together memory dumps is if you’re under investigation for something seriously heinous.
Shutting the VPS down also solves this.
But really, this is a general problem with every “someone else’s computer” solution.
E2EE still nice though, wish Immich had it.
I see. Thanks. E2EE would indeed be nice, but the Immich devs have made it clear for a long time that it woudn’t work due to the way Immich has been developed.