A group in people you know is a private label of your own for some of the people you are connected to. This page says what one does and what it deliberately does not do, including the part that surprises almost everybody: the people in a group are never told they are in it.

What a group is

A group is a name and a list of your mutuals. It does two jobs, in opposite directions.

Going out, it is how you address a post. The composer lists your groups, and under them a searchable list of your individual mutuals, and you tick any combination: two groups, a group and one person, one person on their own. A post addressed to family reaches the people who are in family at the moment you post it. Nobody else gets it unless you widen it yourself with add to audience, or you named somebody on the photograph and turned on tagged people may reshare this.

Coming in, it is a tab on your feed, showing the posts you have not seen yet from the people you filed under that name.

That is all a group is. There is no group chat behind it, no shared album, no group profile, nothing to join and nothing to leave. It lives on your account and it is yours.

Making one, naming it, deleting it

Groups are at profile → groups, on your own profile beside the people you know and the albums you are in, rather than in settings.

A new account comes with six: everybody, dinner table, family, close friends, the house and work. The five custom ones start empty, and all five can be renamed or deleted, so their names are a suggestion and nothing more. everybody is not a list you fill: it is whoever you are mutuals with, which on a new account is nobody yet. new group at the bottom of the list makes another.

A name is between one and 60 characters and it is yours: it is never rewritten, so a group you call “Dinner Table” comes back as “Dinner Table”, and two groups may share a name if that is what you want. Spaces at either end are dropped, because a name of nothing but spaces is a row you could not read. create does nothing until you have typed something, and a name longer than 60 characters is refused with “A group name needs at least one character and at most 60.”

You can hold 32 groups at a time. The thirty-third is refused with “You already have 32 groups. Delete one to make another.” The cap counts what you hold rather than what you have ever made, so deleting one always frees a slot.

Deleting a group takes nothing away from anybody, and the confirmation says so: “The people in it stay your mutuals and keep everything you already shared with them. You will just no longer have this group to address a post to.”

A group with nobody in it is not offered in the composer and has no feed tab, because it would address nobody. It stays on the groups screen so that you can put somebody in it.

Adding and removing people

Open a group and tap add people. What appears is a searchable list of your mutuals: only people you are connected to can be in a group, and the screen filters a list rather than taking a name, so there is nothing to type wrong. When everybody you know is in it already, the list says everyone you know is already in this group. remove sits beside each member’s name.

Adding and removing change where your future posts go. Nothing already shared moves, unless you ask for it—and that deserves two sections of its own.

Groups route posts; they do not grant access

Say you post a photograph to family, and a week later you add Ana to family.

Ana does not get that photograph, unless you choose to share it. She gets the ones you address to family from that moment on.

This is not a policy we apply. When you post, your phone wraps that post’s key separately for each person in the audience as it stands at that instant. Every copy of that key we hold is already sealed to somebody’s own device and we can open none of them, so there is no copy we could seal to Ana afterwards—not by decision, by arithmetic. Sharing last week’s photograph with her is something only your phone can do, which is what the next section is about.

It runs the same way in reverse. Taking Ana out of family takes nothing away from her. She keeps every photograph already delivered to her, and she simply stops receiving new ones addressed to that group. What does take a photograph back is removing her as a mutual, blocking her, or deleting the post for everyone, and each of those works by destroying keys rather than by changing a permission. A photograph you contributed to a shared album is the exception: it rests on her membership of that album rather than on the edge between you, so removing her as a mutual takes it only when the album is one you made yourself. Blocking her takes it either way, and so does her leaving the album or being taken out of it.

So there is one rule instead of two: a delivery, once made, is yours until the connection ends. A group is a routing table, not a list of who may see what.

Sharing the past is a separate question, asked once

Because adding somebody to a group shows them nothing, the app offers the other thing you might have meant. When you add Ana to family and there is anything in that group’s past to share, it asks, with her name and the group’s in it: “Let Ana see past family posts?”, under the line “They will find them on your profile, not in their feed.” The answers are share and not now.

Taking the offer does the work on your phone, which is the only place it can be done: it opens each of those posts’ keys and wraps them again for Ana. They appear on your profile as she sees it, dated when you posted them rather than today, and they never land in her feed and never as a notification. Nothing is asked when there is nothing to share.

Settings has a switch for it, share a group’s past posts when adding someone to it, and it starts off. Turned on, the question is skipped and the sharing happens. Left off, you are asked each time. The switch stays on your phone and is never sent to us, because the sharing runs on your phone.

Nobody is ever told they are in a group

Ana cannot find out that she is in your close friends. She cannot find out which of your groups she is in, and she cannot find out that you took her out of one.

There is no notification and no entry on her activity tab. There is no screen in the app that shows it. There is no request she could make to our server that would answer it either: every group route is scoped to the group’s owner in the database query itself, so a member asking about the group she is in gets exactly the not-found a stranger gets. Being the subject of a row is not a claim on reading it.

Because that is a property of what the app lacks rather than something it does, it is held in place by a test written from Ana’s side of it. The test checks that her own groups, her connections, her mutual count and the requests waiting on her read the same before and after you put her in one, and that the group itself, asked for by its identifier, is the not-found a stranger gets.

The same silence runs through a post. Somebody receiving a photograph is not told which group it was addressed through, or that a group was involved at all. And groups are not reciprocal: putting Ana in dinner table does not put you in hers, and neither of you can see the other’s filing.

What we hold is which of your groups each person is in, which of your groups a post was addressed through, and the group’s name. The membership is what an audience is resolved from; the name is a label for you. Those names are not encrypted the way your captions, your album titles and your display name are—there is no reason for your phone to seal something we never show to anybody but you. A group’s name and its membership are shown to you and to nobody else. The privacy policy lists everything we can see.

everybody is the one box that combines with nothing

everybody is a real group rather than a special case, and it is every mutual you have at the moment you post. You cannot add anybody to it or take anybody out of it: you add or remove the mutual, and the group follows. It cannot be renamed or deleted either, and its own screen says why: “Everybody is always everyone you are mutuals with. It cannot be renamed, deleted, or edited.”

In the composer it behaves unlike every other box. Ticking any group or any person clears everybody, and while anything narrower is ticked its box is empty, pale and cannot be tapped. The line under it is the count of everyone you are mutuals with, the same as every other row in the list.

The reason is that everybody already contains family, and it already contains Ana. Ticking either one beside it reaches nobody new. Both boxes ticked delivered exactly what one box ticked delivered, and read—to anybody who has ever used a checkbox—as an audience smaller than the one being sent to. The composer’s whole claim is that you chose who sees this, and a selection that does not say what it does is not a choice anybody made.

The obvious alternative, letting a tap on everybody sweep the other boxes away, was refused as well: that is things disappearing under your thumb, on the one screen where what disappears decides who sees a photograph.

Your groups also sort your feed

The feed has a tab for everybody and one for each group with somebody in it. This is the direction that catches people out: a tab filters by who wrote a post, not by who the post was addressed to. The family tab shows unseen posts by the people you filed under family, whichever of their own groups they used at their end, or none at all.

So one group is two things at once—a list you address posts to, and a lens you read through—and neither is visible to the people in it. The number on a tab is how many posts on it you have not looked at yet: your own count, seen by nobody else, and it goes down as you read. There is more on the feed elsewhere.

A group is not an album

  A group An album
What it is your private label for other people a place several people are in together
Who can see who is in it only you everybody in it
Who can post to it only you any member, while it is open
Where the audience comes from your choice, per post the membership itself

An album is the opposite decision, deliberately. Its members can see one another, because the sentence at the top of an album’s screen—”Only people in this album see these photos.”—is only true if they can be seen, and because you cannot be somewhere without knowing who else is there. A group is not a place. It is a label you keep, about people who never learn of it.

You can hold 32 groups, and 32 open albums of your own making; closing an album frees a slot as deleting a group does, and albums other people made and put you in are not counted at all. How albums work is a page of its own, and the rest of the app is on the how it works page.