What we can and cannot see
A privacy page that only lists strengths is marketing. This one lists the limits too.
What we cannot see
The contents of your photos and files. Files are encrypted on your device before they leave it, and we never hold the keys. The relay stores and moves ciphertext โ encrypted bytes it cannot turn back into your photos.
You can share storage with family without sharing your library. Each person's data is separate, and sharing space with someone does not let them see your photos.
What reaches us
Your password, when you sign in. Signing in is the one moment your password reaches us, verified and discarded. That moment is why we do not make stronger claims than the ones on this page.
Your account details โ the email address you sign up with, the devices on your account, and who you share storage with.
The shape of your activity, not its content โ that files are moving, roughly how many, how large, and when.
Our network provider. Traffic to our servers, including sign-in, passes through Cloudflare, which handles the secure connection on our behalf.
What this does not cover
Losing a disk. Niji keeps one copy of each file, on your disk. Encryption keeps your photos private; it does not keep them safe from a disk failure. Keep your originals until you have a second copy somewhere else.
Someone with your password. Anyone who signs in as you can see what you can see. Use a password you do not use anywhere else.
This page describes how Niji works today. It is a description, not a legal policy.