Shutterhold

Your photo library, in your own AWS account.

Shutterhold is a complete photo library, for a household or an organisation, that installs into an AWS account you control. Your photos, your account, your bill. Nothing of yours passes through anyone else.

  • Serverless: nothing to patch, nothing running when nobody is looking
  • Web app on every device, plus an iPhone app that backs up by itself
  • Imports from Google Photos and Apple Photos
  • No public access, by design
The Shutterhold timeline: a grid of photos grouped by month, with a scrubber of years down the right-hand side
The timeline. The pictures here are from the Library of Congress and the National Archives, in the public domain.

Yours, entirely

Private by construction, not by promise.

Shutterhold is not a service you subscribe to. It is a system you own: every bucket, table and function is in your account, and the only people who can see a photo are the ones you let in.

  • No public access anywhere

    The only pages a stranger can reach are the sign-in ones. There are no public share links, on purpose. Photos are served from a private bucket through short-lived signed URLs, and the site asks search engines to stay out.

  • Originals are never touched

    Edits change the record, never the file. Thumbnails and previews are made beside the original, which stays byte for byte what you uploaded.

  • Encrypted, and backed up

    Storage is encrypted at rest and reached over TLS 1.2 or better. The database keeps 35 days of point-in-time recovery; a deleted or overwritten original is kept as a version for 90 days in production. A copy of the originals in a second region can be switched on.

  • Accounts by invitation

    There is no sign-up form. An administrator invites people by email, two-step sign-in is available to everyone and required of administrators, and anyone can see their signed-in devices and log out everywhere.

  • The administrator sees counts, not pictures

    A superadmin manages people and storage. They get no access to anyone's photos or albums, and the audit trail records what they did.

  • A phone can only add

    The iPhone app holds a credential that can upload photos and nothing else. A lost phone's token can be revoked from the website in one tap.

Getting photos in

Bring the whole collection, from wherever it is.

Upload from a browser, back up from a phone, or move an existing library across in one go. Whatever the route, the same picture is only ever stored once.

  • Upload that resumes

    Each file is checked before it is sent, so only new photos travel. Big files go in parts, pick up again when the connection returns, and the web app can be installed on a phone or a desktop like any other app.

  • An iPhone app that backs up by itself

    Camera originals, HEIC and video included, are backed up in the background, with an only-while-charging option. The rest of the app is the website itself.

  • Zip files become albums

    Drop a zip of up to 100 GiB, fifty of them to an import, and each folder becomes an album. Importing the same zip twice adds nothing.

  • Google Takeout, read properly

    Dates, places, descriptions, people's names and favourites are taken from Takeout's sidecar files, across archives, with a report of what went where.

  • Apple Photos and iCloud exports

    An export from Photos on a Mac or a download from iCloud comes in with its albums, and the two halves of a Live Photo are kept together.

  • Duplicates recognised by content

    A photo is known by what it is, not what it is called. A JPEG is still recognised after a re-export changed its metadata.

The Imports page: the drop zone for zip files and, below it, a finished import of a 809 MB zip listing the albums made from its folders and the 307 photos added
Imports: drop a zip, a Google Takeout export or an Apple export, and see which albums its folders became and what happened to every file.
  • What it accepts

    JPEG, HEIC, PNG, WebP, GIF, TIFF, RAW (CR2, CR3, NEF, ARW, DNG, RAF, ORF, RW2), MP4, MOV and 3GP (3GP, 3G2)

    A file's type is read from its contents, not its name. Up to 5 GiB per file.

Finding things

A timeline, albums, search, and help from a model that never sees an original.

Photos are read for their capture time, camera and location when they arrive. Place names come from a dataset inside the system, so coordinates never leave your account.

  • Timeline and albums

    Photos by month with a scrubber of years. A photo can be in as many albums as you like without being copied, and an album can carry a cover and a description.

  • Search with filters

    Keywords, places, dates, cameras, album names and descriptions, filtered by date range, place, type, favourites, album and people, with suggestions as you type.

  • AI captions and keywords

    Amazon Bedrock describes each photo from a small preview, never the original, and never to identify anyone. It runs in your account's region, costs fractions of a cent a photo, stops at a monthly cap you set, and each person can switch it off for their own photos.

  • Favourites, trash and a map

    Favourites in a tap. Trash keeps a photo for 30 days, or until you empty it. Where a photo has a location, the viewer shows it on a map.

  • People, if you want it

    Face grouping is off until a person switches it on for their own library. It runs inside your account on open-source models, no outside service is handed a picture, and "delete my face data" does what it says.

The Albums page: a grid of album covers with their names and photo counts
Albums made by an import, one per folder.
A photo open in the viewer with its details panel: when and where it was taken, the camera, and its albums
The viewer, with a photo's details beside it.
Search for the word canyon: the filters for AI tag, dates, place, type and album above the 39 matching photos
Search, with its filters.

Sharing and export

Share with people you know. Take everything with you whenever you like.

  • Albums shared with accounts, not the world

    Share an album with another person on your installation as a viewer or a contributor. Contributors add their own photos and keep ownership of them. Revoking takes effect at once.

  • A copyright notice where it belongs

    Each person can set a notice. It is written into previews and into the copies other people download, never into the original.

  • Export, and import it back

    Download an album, a selection or the whole library as a zip. The whole-library zip is laid out like a Google Takeout export, so Shutterhold itself reads it back with albums, dates, places and keywords intact. No lock-in, including to Shutterhold.

An album open: its name, the actions Download, Upload to album, Upload zip, Share, Rename or describe, and the photos in it
An album, with download, upload and sharing a click away.

Running it

One command installs it. A few dollars a month runs it.

Shutterhold is built for AWS with the AWS CDK. The installer makes everything in an account you own, including a DNS zone for your name, and hands you an administrator sign-in.

A few dollars a month, plus about US$2.50 per 100 GB of photos. An estimate from AWS's public pricing, not a measurement. Lambda, DynamoDB and CloudFront sit inside or near their free allowances for a household; storage is the bill.
  • Twenty to forty minutes

    One command, most of it CloudFormation. The site works on a temporary address straight away; your own name follows once DNS points at it.

  • Your name, or one under shutterhold.com

    Run it at a name you already own, such as photos.example.com, or take a name under shutterhold.com.

  • Nothing central

    There is no shared service and no central database. Updating is pulling the latest code and deploying it; nobody can push anything into your installation.

  • Looked after

    CloudWatch alarms watch the queues and functions, a monthly budget alert emails you before a surprise, and every alarm has a runbook saying what to do.

  • Restores that have been rehearsed

    Point-in-time restore of the database into a table of its own, and recovery of a deleted original from its versions, each with a drill you can run.

  • Built to be read

    The design, the data model and the rules every change must respect are written down beside the code, and the tests hold the infrastructure to least privilege.