What works differently here
people you know borrows most of its shapes from apps you have already used: a feed, a composer, comments, reactions, albums. Some of them behave in ways that will catch you out, because the thing underneath is different. This page collects those, roughly in the order you are likely to meet them, and links to the page that explains each one properly.
A comment is heard by fewer people than can see the photograph
Everywhere else, anybody who can see a post can read all of its comments. Here you hear a comment only if the person who wrote it is somebody you and the poster both know. You always hear yourself, and you always hear whoever’s photograph it is. Anybody else has to be in both circles, where somebody’s circle is themselves plus the people they are connected to.
Ana posts to thirty people. Bruno and Carla are both in that audience and have never met. Bruno sees his own comment and Ana’s; Carla sees hers and Ana’s; Ana sees all three. If Bruno and Carla connect later, each starts hearing the other, under that same old photograph.
The reason is that the audience of a post belongs to whoever made it, so everybody in it is a stranger to somebody else in it. A comment list with no rule over it hands Bruno the handle of a person he could not have searched for and whose profile he cannot open. Nothing warns you before you write, and nobody is told that a comment was hidden from them: the surprise runs in the safe direction, because the people who hear you are always some of the people who can see the photograph and never anybody outside it. Which of them it is gets settled afresh on every read, so it moves both ways: connecting adds somebody, and so does the poster widening the audience afterwards. Comments and reactions.
Removing somebody takes their old comments out from under your photographs
The half of that rule that looks redundant is the half with teeth. Somebody had to be in the audience to comment at all, so “connected to the poster” holds at the moment the words are typed and only starts doing work afterwards. Remove a mutual and their comments go quiet under your photographs for everybody, including readers who still know them perfectly well, and including you.
It is the answer to “I removed him a year ago, why is he still talking under my photographs”. Comments and reactions.
Nobody is ever told who looked
There are no read receipts, no seen-by list and no viewer list, anywhere. The app does record that you saw a post, and when you first did, because that is how your feed empties, and the privacy policy says plainly that we hold that. What does not exist is any way to ask for it: no screen, no route, no field.
Seen-by was built once and taken out again. A per-person read receipt makes looking at a photograph an act that gets reported, so that “you saw it and said nothing” becomes available to everybody in the audience, and that obligation is the thing this app is meant to be a rest from. The feed.
The feed runs oldest first
Open the app and the first thing you see is the oldest photograph you have not looked at, which may be from Tuesday rather than from an hour ago.
Newest-first fills a queue at the end you read from: anything arriving lands on top of what you have not reached, the oldest unseen post sinks under everything later, and the end recedes as fast as you approach it. Oldest first means an arrival sorts behind you and nothing is ever inserted in front of you. The cost is real and is the point. The feed.
The feed ends, and what you have looked at does not come back
When the posts addressed to you run out, the app says all caught up and there is nothing more to scroll. Nothing is suggested, injected, ranked or scored to fill the gap, because there is nothing here to fill it with: every row was addressed to you, by somebody you are connected to or by somebody in an album you are both in.
A post leaves the queue once its first photograph has been fully on screen for a second and a half without interruption, and it does not return. It is in posts you’ve seen, which is reached from under all caught up and from nowhere else. Because a post wrongly marked as seen would be gone for good, the rule is strict: it has to be the decoded photograph rather than the blurred placeholder, and the clock restarts from nothing if the frame leaves the screen. The feed.
Your own posts are not in your own feed
Publishing does not put a row at the top of your own timeline. The feed is what other people sent you; your posts are on your own profile, which is where publishing lands you.
This is not a rule somebody wrote down. A post reaches you by way of a delivery addressed to you, and there is no delivery from you to yourself: your own copy of the key sits on the post. There is simply no row to show. Posting.
There is no number that scores you
No likes count, no view count, no comment count, no reach figure, and no follower or following count. Publishing does not confirm with “sent to 24 people” either: the composer closes and you are on your own profile, looking at the post.
The numbers that do exist count things rather than tally approval. Each feed tab carries a count of what you have not looked at and each album row carries its own; both go down as you read, and nobody else sees either. Your own profile shows your connection count against the limit, 12 of 128, so that the limit is not a surprise you meet mid-add. A group says how many people are in it, and a post of several photographs says which one you are looking at, 3 of 12. A reaction pill says how many people chose that emoji, which names a reason rather than scoring the photograph. Posting.
Reactions never notify anybody, and nothing can turn that on
Most apps make a like the commonest notification they send, controlled by a preference that defaults to on. Here there is no preference, because there is no notification: no push type for a reaction, no column, no route. The settings screen says so under the comment switch, in so many words.
A reaction does write a line in your activity tab, because you can already see who reacted by opening your own post. What is refused is the interruption, not the looking. There is also no digest, no streak and no “you haven’t posted in a while”: the message the server sends has nowhere to put a sentence like that. Comments and reactions.
A notification carries one word, and your phone writes the sentence
When “anna commented on your post” appears on your lock screen, the message that arrived said only what kind of thing happened. No name, no words from the comment, and no identifier for the post either. Your own phone opens the sealed profile it holds a key for and composes the sentence.
The name is withheld because we cannot read it. The identifier is withheld for a separate reason: two phones receiving the same post identifier in the same second are two people in one audience, and repeated often enough at a push provider that is the shape of your graph, handed to somebody else. How the privacy works.
Choosing a group unticks everybody
In the composer, everybody is the one row that combines with nothing. Tick any group or any person and it clears; while anything narrower is ticked its box stays empty, pale and dead, and its line goes on showing the count it shows the rest of the time. Naming somebody in the photograph is the standing exception: their box is ticked and held while the name stands, everybody stays available beside it, and ticking everybody clears their box rather than being blocked by it, because the name keeps them addressed anyway.
everybody means every mutual you have, so family is inside it and Ana is inside it. Ticking either alongside it reaches nobody new, and both boxes ticked delivered exactly what one box ticked delivered while reading as something smaller. A selection that does not say what it does is not a choice anybody made. Having a tap on everybody sweep away boxes you ticked yourself was refused too, on the grounds that things should not vanish under your thumb on the one screen that decides who sees a photograph. Groups and audiences.
A group decides who gets the next photograph, never the last one
Adding Ana to family shows her nothing you have already posted to family, unless you have turned on share a group’s past posts when adding someone to it. She gets posts addressed to it from that moment on. Removing her takes nothing away either: she keeps everything already delivered to her and simply stops receiving new ones.
Both halves follow from the encryption rather than from a policy. At publish your phone wrapped the photograph’s key separately for each person in the audience at that moment, and we hold no key we could hand to Ana afterwards. Nothing on our side could make last month’s photographs visible to her even if we wanted to. If you want her to have them, the app offers to send them, and your phone does the work: they land on your profile rather than in her feed. Groups and audiences.
Nobody can find out which of your groups they are in
Groups are your own labels for other people. They are not shared, not reciprocal and not visible: Ana cannot learn that she is in your close friends, cannot learn that she was taken out of it, and there is no ring, no badge and no shared-with label anywhere to infer it from.
This is a property of what the app does not have rather than a rule it enforces. There is no route that maps a person to the groups they are in, and a member asking for the group they are in gets the same not-found a stranger gets. Groups and audiences.
Your groups sort your feed as well, by who wrote a post
The feed has a tab per group, and the family tab shows unseen posts from the people you filed under family, whatever group the author addressed them to at their end. One group is an outbound routing list and an inbound filter at once, and neither direction is visible to anybody in it. The feed.
An audience can only grow
A post’s audience cannot be narrowed one person at a time: the rows it has already gone to are ticked and cannot be unticked, and there is no control that takes somebody out of a photograph while leaving them a mutual. It grows in three ways. Two are deliberate acts of yours: more → add to audience on the post, and the offer to share your past posts with somebody, which is skipped and done silently if you turned on the matching switch under sharing the past in settings. The third is not yours: a photograph you contributed to somebody else’s album is caught up to anybody the creator adds later, because the membership of that room is its audience.
Widening works because a phone that holds the key unwraps it and wraps it again for the new people. Narrowing cannot work that way, because the key is already on the other phone. The ways back are more → delete for everyone, which takes the post from everybody, and removing or blocking the person, which takes every ordinary post of yours they hold rather than only this one. Posting.
Taking something back destroys a key rather than setting a flag
Removing a mutual, blocking somebody, or deleting a post does not mark a row hidden on a server that could be persuaded to unhide it. It deletes the copies of the keys that opened those photographs, in both directions, in one go. There is no permission left to check because there is no key left to check it against. Removing a mutual reaches your ordinary posts and leaves an album a third person made alone; blocking reaches into that room too, which is one of the differences described further down.
Deleting a post is immediate for everybody. The encrypted files come off storage eight days later, and out of the second copy we keep of them within six weeks. Neither wait is an undo: the keys went at the tap and nothing in the product can restore them. The privacy policy says how long a deleted row can survive in a backup of our database.
The honest limit is the one every way of sending a photograph has. Anything somebody already downloaded stays theirs, exactly as it would if you had emailed it to them. What changes is that nothing new opens. How the privacy works.
There is nothing to look at until you are connected
There is no public profile, no profile link, no QR code and no way to look at yourself as somebody else sees you. There are no follows either: the signup screen puts it as no follows—only mutuals, and the only relationship in the app is one both people agreed to and either can end alone. A profile is not a back catalogue: it is the posts of that person’s that you personally hold, so when you connect it is empty and fills only as they share with you.
Asking for a profile you have no connection to answers exactly as an account that never existed does. Refusals are “not found” rather than “forbidden”, because “forbidden” confirms the thing exists, and it is why somebody who blocked you is indistinguishable from somebody who deleted their account. The one deliberate exception says so plainly instead: trying to add somebody you share no mutual with answers You need a mutual in common to send a request, because you already knew the handle and a fake not-found would hide nothing from you. Connecting with people.
Search is exact, and it is rationed
Type three letters and you get nothing. Search takes a whole handle or a whole email address, and returns at most one person. There are no near matches, no suggestions and no “people you may know”, and the field says so under it: Search finds people by their exact handle or email.
It is also limited to 32 tries an hour, counted whether or not they find anybody, because a surface on which strangers can be discovered is a surface on which they accumulate. Thirty-two is generous for a person adding somebody and useless for working through the handle space. Connecting with people.
Redeeming an invite sends a request to whoever invited you
There is no tap for it, and signup says so on the step where the code is typed: The person who invited you will get a request from you. The account you make is connected to nobody, so nobody shares a mutual with it, so the ordinary gate would refuse in both directions and no first connection could ever be made. A redeemed invite carries a standing permission for your new phone to ask the person who invited you, once.
Once, exactly. If they decline, or you cancel, there is nothing left and you are a stranger to them like anybody else. It is told to you because it happens without a tap, and finding it out afterwards would be the app acting on your behalf and not saying so. Connecting with people.
Two ways a name you do not know can reach you
Nothing here is computed, ranked or suggested, so there is no “people you may know”. Both routes to somebody you have never met run through a photograph you were shown: a name somebody put on it, and, where the photograph is a reshare, the person who originally posted it. Either opens a card: the face, the name, the people you both know, and add. In an album the person doing the naming need not be anybody you know either, because the members are the creator’s mutuals rather than each other’s; they can still only name their own mutuals.
Two consents stand behind a name on a photograph. The person’s own, in settings → let mutuals tag me, which is on until they turn it off; and the poster’s, in the act of naming them. It is the offline mechanism, “who is that in your picture”, and the person in the middle is on the hook for the introduction. Turning that switch off deletes every existing tag of you and every copy of your name and face that went out with one. Behind a reshare stand a different two: the original poster allowed resharing on that post, and named the person who did it. Connecting with people.
Nobody can pass your photograph on unless you allowed it on that post
Repost, forward and share-to-story are available on anything anybody can see in most apps. Here resharing needs tagged people may reshare this, which is off by default, appears in the composer only once you have named somebody, and afterwards is a switch on the post itself. Only a person you named, on a post you ticked it for, can reshare.
A reshare is drawn under your name and your picture, with one line above reading bruno reshared, and the resharer cannot add a caption of their own. It reaches the people they pick from their own groups and mutuals, less anybody who already had the photograph and less you, and nobody else. Taking your name off a photograph, or unticking the permission afterwards, destroys every reshare that rested on it. Nothing is counted: there is no “shared 12 times” anywhere. Posting.
Inside an album, several of these rules turn round
An album is one room, and it behaves like one.
Everybody in it can see who else is in it, which a group never allows. The sentence at the top of the screen is Only people in this album see these photos. That is only true if the people can be seen.
Everybody in it hears every comment, including people you have no connection to, because in an album both halves of the comment rule ask the same question and get the same answer.
And photographs reach you from people you have never connected to, because the members are the creator’s mutuals rather than each other’s. Such a person is named plainly from the album’s own member list, and their name is not a link, because there is no profile behind it for you.
One thing an album refuses that the rest of the app allows: a photograph in an album can never be reshared, because it would leave the room.
Because the room is the creator’s and not yours, removing somebody as a mutual does not take either of you out of an album a third person made, and you go on receiving each other’s contributions there. Blocking is what reaches into that room, which is one of the differences between the two on the moderation policy. Albums.
An album cannot be deleted, only closed
There is no control and no way to delete an album. Whoever made it can close it: nothing more goes in, and everything already in it stays readable for everybody in it. The person who made it cannot leave it either: their control is close, and there is no leave on their screen. If they delete their account entirely, the album closes and the members keep every contribution anybody else made.
The photographs in an album are the members’ as much as the creator’s, so there is no control that takes them away because a third person decided to tidy up. Albums.
A photograph sent to one person is a post, not a message
There is no messaging surface in the app: no inbox, no thread, no typing indicator. Addressing a post to one mutual is an ordinary post whose audience happens to be one, with the same comments and reactions as any other. It is also what makes it possible to share it with somebody else later, without having invented a group for one person. Groups and audiences.
Nothing is cropped, nothing is edited, and there are no drafts
The app has no crop tool, no filters, no rotation and no markup, and nothing is ever cropped in what is stored or sent. A photograph too tall for its box is fitted inside it with margins, and on a post a tap opens it full screen with no bound at all. A post of more than eight photographs is previewed as four square tiles, cropped so that the sheet reads at a glance, with view all beneath them; opening any of them shows the whole picture. The one real crop is your own profile picture, cut to a square on your phone, where you put the square.
Nothing about a post you have not sent is written to your phone either. Leaving the composer asks once and then it is gone. One you have sent is written down until it goes out, so that the app closing mid-upload cannot lose it in silence, and it is deleted the moment it lands. Everything the camera recorded beside the picture is gone too, and not because a filter stripped it: the photograph is decoded and re-encoded, and what comes out has nowhere for a location or a device serial number to be. One thing is kept on purpose—when the photograph was taken—and it travels sealed with the picture, readable by the people you sent it to and not by us. Posting.
Six words, and nobody can give them back
Your account is a key, and the key lives on your phone. A second phone signs in—with a code sent to your email address, or with your password if that is what the account holds—discovers it holds no key, and asks for the six words you were shown at signup. There is no device-linking QR code, because there is one key per person rather than one per device.
A password and the six words are not interchangeable and neither is a way to get the other. The password opens the account; the six words open the photographs. A new phone needs both.
If you lose the six words and every phone that holds the key, the account is gone, including any way to get into it and delete it. Write to us from the address on the account, or with your handle if it has none, and we will delete it for you, but we cannot let you back in and we cannot recover your photographs. There is no copy that is ours to hand back, which is the same sentence as “we cannot read them” said from the other side. How the privacy works.
The six words are the key, and the door is whatever the account holds: an email address or a password. They are two different things to lose, and for a long while only one of them was written down here. A code goes to that address every time you sign in on a phone that is not already signed in, so an address you can no longer read is an account you can no longer open, whatever you wrote down at signup. That is a far more ordinary thing to happen than losing a piece of paper: you leave a job, you change provider, an old free account locks itself.
An account with only a password has the sharpest version of this: there is nowhere for us to send anything, so forgetting it is the account, and nobody can let you back in. That is the trade for our holding no address for you at all, and it is why you can add one later from settings the day you want to.
So the address can be moved, from settings → your email, while you are still signed in. You type the new one, we send a code there, and you type it back—the same pair of steps as signing in, pointed at the address instead of at the app. Nothing but a code delivered to that mailbox will move it, and we send a note to the old address to say it changed, so that a phone somebody else picked up cannot move your account quietly. If the address is already gone and you are still signed in somewhere, do this now rather than later; if it is gone and you are signed out, write to us and we will help you prove who you are.
The app does not stop screenshots
It sets nothing that would prevent one, on any screen, including the one that shows your recovery phrase. Somebody you shared a photograph with can screenshot it, save it, and keep it after you remove them, the same as with any other way of sending somebody a picture. The encryption decides who can open a photograph; it cannot decide what they do next. The terms say the same thing in fewer words.
What is not here
The app is Android only: there is no iPhone app, no web version and no desktop version, so there is nothing to sign into in a browser. It takes photographs, and videos of about a minute. Signing in is by a code sent to an email address, or by a password if the account has one. There are no text messages, so search does not take a number either: an account cannot come to hold one for it to match. Invitations are issued by hand during the closed beta, so there is no invite link to send anybody.
If something here is not what you expected, how it works has the longer version of each of these.