Albums
An album is a place several people are in, that any of them can put photographs into. It is the part of people you know where what you share reaches people you have not connected to, and it behaves differently from a group in nearly every way that matters. This page says how, including the parts that surprise people.
What an album is
One person makes an album and adds people to it. Any member can put photographs in; every member sees every photograph in it, and nobody else does. The sentence at the top of an album’s own screen is the whole of the promise: “Only people in this album see these photos.”
Your albums are a row on your own profile, under who you know: profile → albums. new album asks for a name and makes one, which at that moment is an album with one person in it. The name is sealed on your phone under a key we never see, so we cannot read it, and it cannot be changed afterwards.
You can hold 32 open albums at a time. Closing one makes room, and the refusal says so: “You already have 32 open albums. Close one to make another.”
There is no cover image, no photograph count and no member count. An album’s row in the list is its name—or an album, if the name will not open on this phone—and under it either closed on 7 september or a number like 3 new, or nothing at all.
Who can do what
- Make an album: anybody.
- Add somebody: the creator only, and only somebody they are mutuals with. add people, then search your mutuals.
- Add photographs: any member, while the album is open.
- Leave: anybody except the creator.
- Take somebody out: the creator, with remove beside that person’s name.
- Close it: the creator only, and nothing reopens one.
Two of those are worth saying plainly. Nobody who is not already a mutual of the creator can be put in an album, so there is no way to invite a stranger into one. And a member who asks to remove another member gets the same nothing a stranger gets: being in an album is not a claim on who else is.
The creator cannot leave their own album, and the album screen offers them no leave. A creator who could walk out would leave an album nobody can add to and nobody can close.
Everybody in an album can see who else is in it
This is the first thing that catches people out, because a group works the opposite way. A group is your own private label for other people, and nobody is ever told they are in one. An album lists its members, under people in this album, to every member.
Both are right, because they are different things. A group is one person’s filing; an album is a place people are in together, and you cannot be somewhere without knowing who else is there. The sentence at the top of the screen is only true if the people can be seen.
It also has to work this way. When you add a photograph to an album, your phone locks it separately for each member, which means your phone has to be handed each member’s key—and any member can add photographs. There is no arrangement where the members are hidden from the people who contribute and the photographs still arrive.
What being a member is
Every album has a key of its own, made on the creator’s phone. It opens the album’s name and nothing else. Your copy of that key, wrapped so that only your phone can open it, is what being a member is: adding somebody is one wrap, and removing them takes that row and every post key they held here away together.
The photographs are not sealed under that key. Each one is an ordinary post with a key of its own, locked separately for every member at the moment it is added. That is more work than sealing everything under one album key, and it is the whole reason removal means anything. Somebody who has been in an album for a year has already opened the album key many times. If the photographs were sealed under it, nothing added after they left would be closed to them by arithmetic, only by us agreeing not to hand over the files. That is a permission check wearing a key’s clothes, and it is what this app is trying not to be.
Putting photographs in
Say Ana has made an album called Maine and put you and Bruno in it. add photos opens the composer with the album as its audience and no picker, because the audience is not a choice: where the composer usually asks who should get a photograph, this one says everyone in Maine and leaves it there. A contribution cannot also be addressed to a group or a person, and its audience cannot be widened afterwards. The refusal names the remedy: “An album’s audience is the people in it. Add them to the album instead.”
Apart from that, a contribution is an ordinary post. It has its own caption, its own comments and its own reactions, and the person who put it there can delete it for everyone. It arrives in each member’s feed as an ordinary row, with a line under the author and the date reading in Maine, which opens the album. It does not arrive in your own feed, because nothing you post is delivered to you. It cannot name anybody, though: the tag link sits on a row of the audience picker, and a contribution has no picker.
A contribution cannot travel, either. A photograph in an album can never be reshared: the control is not drawn on it at all, and neither is the switch that would allow one, because the permission a reshare rests on cannot be set on a post in an album. A request that went round the app for it is refused with “You can reshare a post only if you were tagged on it and the poster allowed it.” An album is one room, and a photograph leaving it through somebody’s mutuals would break the only promise an album makes.
Joining an album hands you its past
An album usually holds photographs from before you were added. They are not served to you by us: we hold no key that could open them. Instead the phone of the person who added you re-wraps each photograph’s key for you and sends the copies back, in batches. That is the creator’s phone, because it is the creator who adds people to an album, and it holds a copy of every key it was given.
Those older photographs appear on the album’s screen, dated by the day they were put in the album rather than the day you joined, and they never enter your feed and never notify anybody. Forty photographs arriving in a queue because somebody joined an album is the flood the feed exists to avoid.
You will see people you are not connected to
The members of an album are the creator’s mutuals, not each other’s. You and Bruno are both mutuals of Ana, and may never have connected to one another: in Maine you are in a room together anyway, and his photographs arrive in your feed.
The app does not pretend otherwise, in either direction. His name is shown, taken from the album’s own member list, and it is not a link, because there is no profile behind it and there would be nothing to open. There is no face beside it either, because a profile picture travels only to people you are connected to, so where a face would be there is a plain coloured circle instead.
Being in an album is the choice that does this. There is no setting that hides you from the other members or them from you, because the members are the audience, so the remedy is the album itself: leave it, or do not put the photograph in there.
You can report a contribution the way you would report any post, under more → report. The member list itself has no report control, and a comment has none either, so a co-member you have no connection to is reported for what they contributed, and for what they said only through the post it sits under. The moderation policy says what happens next.
In an album, everybody hears every comment
Everywhere else in the app, a comment under a photograph is heard only by the people you and the poster both know. You always hear yourself and you always hear whoever’s photograph it is; anybody else has to be a mutual of you both. Two people in the same audience who have never met never see each other’s words.
In an album the rule inverts, and everybody hears everybody. What counts there is being in the album rather than who knows whom, because an album is one room and its members can already read each other’s names off its own screen. Asking about mutuals instead would hide most of a shared album’s conversation from most of the people sharing it.
The membership is read afresh on every look, so leaving an album, or being taken out of one, takes your words out from under other people’s photographs there. What you said under your own contributions stays, because you are always heard under your own photograph.
Nothing is counted
There is no “12 photos”, no “8 members” and nothing that grows. The one number anywhere near an album is 3 new on its row, which is how many of its photographs are still in your own queue: your own, private, and going down as you look.
The activity entry when somebody adds you reads Ana added you to Maine. It does not say how many photographs are in there, because a count of what other people have done is exactly the sort of number this app does not show anybody.
Being told about an album
Being added to an album never buzzes your phone. It writes a row on your activity tab and nothing more, and there is no switch to turn that into a notification, because there is no notification to turn on.
New photographs in an album notify nobody either, until you turn on that album’s own switch, which reads tell me when somebody adds to Maine. It is yours alone, it is off to begin with, and each album has one. A closed album does not show it at all, because nothing more can be added.
Even then, the message we send your phone carries only the kind of thing that happened. There is no name in it, no album title and no identifier. The sentence you read was written by your own phone out of what it already holds, and if your phone cannot work out who contributed, it shows nothing rather than something vague.
Leaving, and being taken out
leave says what it will do: “You will stop seeing these photos, and anything added later. What you added stays.” Being removed by the creator says the same thing about you.
In both cases the membership row and every key that person held for the album’s photographs go together, in one statement. Anything contributed afterwards is locked for the people who are in the album at that moment, so no copy of that key exists that their key could open. What was already downloaded to their phone stays theirs, as with any photograph anybody has ever sent anybody; nothing new opens.
What they contributed stays. Those are their posts, and every other member was given a copy of their own.
Removing a mutual, and blocking
Removing somebody you are mutuals with takes them out of every album you made, and takes you out of every album they made, with the keys on both sides. A membership that outlived the connection would leave the creator’s own contributions open to somebody they had just removed.
An album a third person made is not yours, and this is the part people do not expect. Two people who stop being mutuals go on receiving each other’s photographs in somebody else’s album, because a delivery there rests on being in the album rather than on the connection between them. A block is what reaches into that room: every delivery between the two of you goes, album photographs included, and neither is ever locked to again. Neither of you is taken off the member list, because the room belongs to somebody else.
An album is closed, never deleted
There is no way to delete an album. No control does it, the app has no way to ask for it, and the database refuses to let an album with photographs in it be deleted from under the people who put them there. What the creator can do is close it: “Nothing more can be added to it. Everyone in it keeps what is already there.” The row then reads closed on 7 september, a date rather than a countdown. A closed album offers no add photos, no add people and no close, and still offers leave, because leaving only ever narrows.
The reason is that the photographs in an album belong to the people who put them there as much as to the person who made it. Deleting it would take somebody else’s photographs away because a third person decided to tidy up, and it would happen without a word to them. Closing has a second job as well: closed albums do not count against the 32, so closing is what makes room.
The same holds if the creator deletes their account. Every album they made is closed in the same breath as the deletion; everybody in it keeps every contribution everybody else made, and only the departing creator’s own photographs go, the way all of their posts go. Nobody can add to it or add anybody to it afterwards, and it stays readable for the people in it. Deleting your account says what else that destroys.
What we can see
We cannot see an album’s name, its photographs, its captions or its comments. All of those are sealed on the phones that made them.
We do hold what is needed to deliver a photograph to the right people: who is in each album you are in, who made it, when each person was added, whether it is closed, who contributed what and when, how large the encrypted files are, and whether each recipient has seen a contribution and when they first did. Nobody is ever told that last one. The privacy policy says the same for the rest of the app.
Two smaller consequences. A report is about a post or a person, and never about an album, because we can act on a post or an account and not on a room. And if you export your data, your own contributions are in it, because they are posts you made; other members’ contributions are not, even though your phone holds a key for every one of them.
There is more about the rest of the app in the guide.