Choose what leaves your device. Strip GPS, camera, timestamps or software info before upload, field by field, and lock sensitive photos in a hidden vault.
Strip GPS, camera, timestamps or software info before upload, field by field
A hidden vault behind your fingerprint, face, or PIN
On-device face grouping and text recognition, never sent to a server
Offline place names and a map, with no network lookups
App-wide lock, and no analytics or trackers of the app's own
An independent, third-party Android client for Proton Drive Photos. Built against the publicly documented Drive API, no private endpoints, no proprietary code, no obfuscation. All gallery code is written from scratch in eu.akoos.photos; the official protoncore_android libraries (pinned to v36.6.0) are consumed unmodified for authentication, crypto, and Drive sync. GPL-3.0, source on GitHub, build it yourself from the tagged source.
FAQ
Anything else? Open an issue or discussion on GitHub.
Is this an official Proton app?
No. Photos for Proton is an independent, third-party app built by Akoos (gitakoos on GitHub). It uses Proton's official open-source libraries (protoncore_android) to talk to Proton Drive, but it is not built, endorsed, or supported by Proton AG.
What is it built on?
Kotlin + Jetpack Compose + Material 3 for the UI. Hilt for dependency injection, Room for the local catalogue, Coil for image loading, Media3 / ExoPlayer for video playback and the video editor, AndroidX scheduling for background sync, Glance for the home-screen widget. Proton's protoncore_android library is pinned to v36.6.0 and consumed unmodified for authentication, key management, and Drive sync. No proprietary SDKs.
Does it fit into the Proton ecosystem?
Yes. Because the app uses protoncore_android, the same library Proton's own apps are built on, your sign-in, account, encryption keys, and Drive storage all behave identically to the official clients. Your photos land in your Proton Drive Photos folder.
Does the app send any telemetry?
The app adds no analytics or crash-reporting SDKs and sends no telemetry of its own. It talks to Proton's API to authenticate and sync your photos, to GitHub when it checks for a new release, to OpenStreetMap for the map's background tiles when you open the map, and uses encrypted DNS (Quad9 or Cloudflare) for connectivity. ProtonCore is bundled unmodified and follows your Proton account's telemetry setting.
Do I need a Proton account?
No. Choose "Continue without account" on the sign-in screen and the app opens straight to the photos already on your device, with no Proton session at all. Sign in with any Proton account, including free, at any time to add end-to-end encrypted cloud backup and sync, with no data loss; cloud usage counts against your existing Proton Drive quota.
Where can I get it?
Signed APKs are published on the GitHub releases page. There is no Google Play release planned, the app deliberately avoids Play Services. See the Download section.
Does the app strip EXIF / metadata from my photos?
Yes. In Settings → Privacy & metadata there is a master "strip on upload" switch plus individual toggles for GPS & location, camera make & model, timestamps, and software info. Stripping happens on-device before upload. The original local file is not modified.
How do albums work?
Albums are references, not folders, both on Proton Drive and on device. Adding a photo to an album never moves it. Your files keep their original capture dates and stay in their original location.
Every album you create now lives on Proton Drive, so it picks a cover automatically, survives a re-install, and is ready to share by email with viewer or editor access. Alongside your albums you'll see device folders like Camera and Screenshots (read-only inside the app, system folders), and you can mirror any device folder to a matching Drive album so it stays in sync as you back up.
What happens to my albums if I uninstall the app?
Anything you've backed up, including its album membership, is safe on Proton Drive and reappears the moment you sign back in. Local-only photos (never uploaded) keep their files but lose the in-app album organization, because that lived in the app's data folder which Android wipes on uninstall. Device folders like Camera survive unchanged.
Can I share an album with someone?
Yes. Open any album, invite people by email, and choose whether each person can view or edit, you can change that later, even on invites that are still pending. You can see who has access, remove someone, or stop sharing at any time. Recipients open the album end-to-end encrypted on Android and on Proton Drive web, and albums shared with you show up in the Shared tab, where you can browse full quality and save a whole album into your own library. They open straight from your cache, so large ones load fast.
How do updates work without Google Play?
The app checks the GitHub Releases page for a newer signed APK and offers to download and install it for you in one tap. You can also grab any release manually from GitHub Releases at any time. Updates are opt-in, and the app talks to Proton's API, to GitHub for the release check, and to encrypted DNS resolvers for connectivity.
Download
Signed APK on the GitHub Releases page. GPL-3.0-licensed source, clone the v2.5.0 tag and build it yourself if you prefer.