Leaving Google Photos for Proton, Ente or Immich?

Leaving Google Photos, two encrypted clouds (Proton, Ente) and two options to host yourself (Ente, Immich). Compare before you choose.

3D render of a translucent blue glass camera, a golden padlock and encrypted spheres in orbit, on a white background

Introduction

Open Google Photos on your iPhone. Scroll. Ten years of your life sit there, your kids’ faces scanned one by one, the places you’ve been sorted onto a map, your receipts, your screenshots, all indexed, all recognized, all read. Free. Well, free the way Gmail was.

You want out. Good call. Except “leaving Google Photos” isn’t swapping one app for another, it’s answering two questions before you even pick a piece of software.

First question: do you want a maker to host your photos for you, turnkey, or do you want to run them on your own machine? Second question: end-to-end encryption, the kind that makes your photos unreadable even to the service storing them, is that a dealbreaker or negotiable? Your answers trace two very different roads.

So we’ll go in order, honestly, including where it hurts. First the two encrypted clouds, the ones that host for you without ever being able to read your memories: Proton and Ente. Then, for those interested, the two solutions you run at home: Ente again, and Immich. Yes, Ente shows up twice. It’s the only one of the lot to play both courts, encrypted cloud like Proton, self-hostable like Immich.

A word for the impatient: the second block, the self-hosting one, is for those who want to run their own server. If setting up a machine at home isn’t your thing, skip it with no regrets, the cloud part is more than enough to get you out of Google.


The criteria that matter

Comparing three photo libraries by the number of gigabytes misses the point. What matters when you hand ten years of family photos to a service is something else. Here’s the grid.

Real encryption. Can the service, technically, look at your photos? The real test is zero-access: keys are generated on your device, the server stores only ciphertext, and even under a court order it can only hand back gibberish.

Open code, and the audit. Open source on the app side, that’s good. Open source on the server side too, that’s rare. An independent firm that has read that code and published its verdict, rarer still. These three boxes are not ticked by the same players.

Jurisdiction. Where the servers live, and under what law. Switzerland sits outside the CLOUD Act. The European Union enforces the GDPR. The United States has a statute that forces an American company to hand over data even when it’s stored abroad. Remember that detail, it splits two of the candidates.

The photo app day to day. Automatic background backup, import from Apple Photos, albums, search, presence on Mac AND iPhone. This is where Google Photos shines, and where most sovereign alternatives stall.

Price and model. Free funded by ads, an honest subscription, or free because it’s your own hard drive. Three different economics.

Longevity. The day the company folds, do your photos become unreachable? A big solid outfit and a small self-hostable project don’t answer that question the same way.

Six criteria. None of the three wins them all, which is exactly the point of the comparison: to let you choose what matters most to you. And two of them, jurisdiction and longevity, don’t read the same way depending on whether you hand your photos to a maker or keep them on your machine. The rest of the piece shows it, block by block.


Hosting with the maker: Proton vs Ente

Two clouds, two real end-to-end encryption promises. At Proton as at Ente, the keys are born on your device and the server only ever sees gibberish. Which means encryption won’t be what separates them, both hold up on that front. What sets them apart is three things: open code, the independent audit, and the jurisdiction your photos live under.

Proton Photos

Philosophy: offer an end-to-end encrypted photo library, built into a full suite, without you having to understand how it works. The bet of turnkey sovereignty.

Proton, you might already know. It’s the Geneva company behind Proton Mail, Proton VPN, Proton Pass. Photos isn’t a separate product: it’s a feature of Proton Drive, which inherits all of its encryption. You turn on backup in the iOS app, and from there every photo is encrypted on your iPhone before it leaves for the servers. OpenPGP on the Curve25519 curve, AES-256 for the content. Proton doesn’t hold the keys. Even the metadata is encrypted.

The strengths:

  • Real zero-access encryption, inherited from Drive. Proton can’t see your photos, the non-negotiable starting point of the whole edifice.
  • Swiss jurisdiction. Outside the European Union, outside the United States, so outside the CLOUD Act. The federal data protection act, now revised, lines up with the GDPR. Servers in Switzerland and Germany.
  • Automatic background backup on iOS since June 2024, with deduplication, encrypted albums, burst handling. It runs on its own, like Google Photos, without you thinking about it.
  • Zero extra cost. If you’re already on Proton for mail or VPN, Photos is included. Your privacy suite handles your memories too.
  • The most solid outfit of the three. Founded in 2014, more than 500 people, and since June 2024 controlled by the Proton Foundation, a non-profit whose mission is locked in and which makes the group unacquirable. That’s a longevity guarantee neither Ente nor Immich can show.

The weaknesses:

  • The server code is closed. The client apps (iOS, Android, web) have been open source since September 2024, and that’s great. But the server itself stays a black box. On this exact point, open code, Proton is the most closed of the three candidates. Ironic for the seemingly most “sovereign” choice.
  • The public audit doesn’t cover Photos specifically. The firm Securitum audited the web app in 2021, iOS and Android in 2022, results published in 2023. Solid. But an audit dedicated to the Photos brick isn’t confirmed to date.
  • On Mac, it’s less polished. The Photos experience is designed for iOS first. On your Mac, you go through the Drive app or the web, and the comfort isn’t at the iPhone’s level.

For whom: the user who wants encrypted, Swiss, and above all nothing to install or maintain. If Proton Mail is already your inbox, the question is almost settled.

Price: free up to 5 GB. Drive Plus 200 GB around $3.99/month. Proton Unlimited 500 GB around $9.99/month, which also bundles Mail, VPN, Pass and Calendar.

Ente

Philosophy: do one thing, the encrypted photo library, and do it better than anyone, with code anyone can read, and encryption anyone can prove.

Where Proton does everything, Ente does only this. And it shows. Vishnu Mohandas, the founder, is a Google alumnus: he built the photo app he wished he’d found on his way out.

The result is the experience closest to Google Photos on comfort, automatic background backup, direct import from Apple Photos, search, shared albums, all while staying end-to-end encrypted. libsodium, Argon2id to derive your key, XChaCha20-Poly1305 for the content. Ente can’t decrypt your memories.

The strengths:

  • The only one of the three that’s 100% open source, client AND server. The server code was opened in March 2024, under the AGPL-3.0 license. That’s exactly the box Proton leaves empty. You can read what runs on their machines.
  • Zero-knowledge is proven, not promised. A Cure53 and Symbolic Software audit in March 2023, then a second Cure53 audit on the server side in October 2025, funded by CERN. Yes, CERN: the lab is a heavy Ente user, and it paid for this audit to harden a tool it relies on itself, not to slap its own label on it. Ente is the only one whose encryption is both verified by a firm AND verifiable in the code. It’s the top of the stack for demonstrable trust.
  • Data 100% inside the European Union. Three encrypted, replicated copies: Amsterdam, Frankfurt, Paris. Your photos never leave European soil.
  • The best dedicated photo app of the three, on iOS and on macOS, with an iPhone app and a real desktop app on Mac, not a browser tab. On this day-to-day criterion, Ente edges out Proton.
  • And you’re not locked into their cloud. Since the server is open, you can, the day the urge or the need hits, pull your whole library out of their cloud and bring it back onto your machine. It’s possible, more on that below: that’s exactly what puts Ente in the self-hosting race.

The weaknesses:

  • The entity is American. Ente Technologies is incorporated in Delaware, the team works out of Bangalore, in India. On paper, the CLOUD Act applies to the company. In practice, it hits a wall: zero-knowledge means a court order only yields unreadable ciphertext, and the servers are in Europe. The entity’s jurisdiction is neutralized by the architecture, but it exists, and honesty demands saying so.
  • A small team. A lean team, fully self-funded, without a cent of venture capital. It’s a mark of independence, but also a light structure next to Proton’s 500-plus staff. The safety net here isn’t the size of the company, it’s the possibility of self-hosting.

For whom: the one who wants the best photo experience without conceding anything on openness, or on proof of encryption. The reader for whom “open source audited” isn’t a marketing line but a prerequisite.

Price: free forever up to 10 GB, with no expiry date. 50 GB at $2.49/month, 200 GB at $4.99/month, 1 TB at $9.99/month, 2 TB at $19.99/month. Family plan up to five people.

Ente on iPhone: home screen with memory cards, and advanced search combining people and concepts

The cloud verdict. On open code and proof by audit, Ente wins hands down: the only open source server of the pair, the only published server audit. On raw jurisdiction and structural solidity, Proton keeps the edge: Switzerland outside the CLOUD Act, more than 500 people behind the product, and a foundation that makes the group unacquirable. Two honest clouds, two strengths that don’t overlap.


Hosting it yourself: Ente vs Immich

Change of scenery: here the server runs on your machine. Your Mac mini, your NAS, your VPS. Jurisdiction drops out of the equation, your data is at your place, under your law, nobody else to trust.

The real fault line becomes encryption. Ente stays end-to-end encrypted even when you host it yourself. Immich, no, and that’s not a detail.

Ente, you can host it yourself too

We covered Ente in full in the cloud block, no need to redo it all. Here we look at one thing only: what it’s worth once installed on your own machine.

The strengths:

  • The only self-host that’s end-to-end encrypted. Its server is open source under AGPL-3.0, you deploy it at home, and it keeps its E2EE even self-hosted. It’s the only solution in the comparison to give you both “at my place” AND “unreadable to anyone”, including you who runs the machine.
  • A real desktop app on Mac. Even self-hosted, you keep an app installed on Mac, where Immich sends you to the browser. The iPhone app, both have one, it’s the Mac desk that decides. Day-to-day comfort doesn’t drop when you switch to self-hosting.
  • Your survival net. The day the company folds, you pull your whole library back onto your server without losing a thing. Your memories don’t depend on the company’s health.

The weaknesses:

  • Self-hosting isn’t the showcase. Ente is a cloud first. Self-hosting is documented, but the team pushes it far less than Immich, and the install is less packaged, less spoon-fed.
  • A smaller self-host community. Fewer tutorials, fewer help threads, fewer field reports than the Immich ecosystem the day you get stuck on a deployment.
  • Search stays a notch below Immich. It exists and it’s good, semantic search and facial recognition included, but Immich pushes the cursor further. If the intelligence of the library is your first criterion, you might feel it.

Immich

Philosophy: hand you Google Photos exactly, facial recognition, search, the map, memories, but running 100% on your machine, under your law, with no company in the loop.

Immich is the most radical project of the bunch, and the most impressive technically. Created in February 2022 by Alex Tran, it reproduces the Google Photos experience down to the smallest detail, except it runs at your place.

You install the server on your Mac mini, your NAS or your VPS, the iOS app pushes your photos onto it in the background, and there you go: a smart photo library you alone own.

Since May 2024, the core team has been funded full time by FUTO, a Texan pro-open-source company, which lifted the project out of hobby status. Version 2.0 stable in October 2025, version 3.0 in July 2026. More than 100,000 stars on GitHub. The project is alive.

The strengths:

  • Maximum sovereignty, total control. Your photos are physically at your place, on hardware you own. No third-party server, no company that can close your account, change its terms or get bought out. You decide where your data lives, literally.
  • Fully open source, client and server, under AGPL-3.0, with one of the most active communities in the entire self-hosted ecosystem.
  • Free, actually. No paid tier, no gated feature. A support license exists ($99.99 lifetime per server, or $24.99 lifetime per user), but it’s purely cosmetic, you lose nothing by skipping it. Still, I always recommend supporting open source projects, so if you like the product, dig into your pocket!
  • The Google Photos experience, better on principle. Facial recognition, content search, transcoding, map: it’s all there, and it all runs without sending a single byte to Mountain View.

The weaknesses:

  • No end-to-end encryption. That’s the central trade-off of the solution. The data isn’t encrypted on the server. The protection is your machine’s disk encryption and your connection’s TLS, both on you to set up. The team owns this choice, it deems E2EE (End-to-End Encryption) incompatible with server-side processing, since facial recognition and search need to read the images in the clear. In other words, you’re not trading encryption for nothing: you’re trading it for the intelligence of the library and total control of the infrastructure. But you’re trading it.
  • No public audit identified. The code is open, so readable, but no independent firm has published a verdict to date.
  • No first-party macOS app. The iOS app exists and handles automatic backup. On Mac, you go through the browser. For a 100% Apple reader, that’s real friction.
  • You’re the administrator. The hurdle isn’t day-to-day maintenance, once it’s set up it just runs. It’s the installation, the backups, the updates. The day your disk dies without a backup, there’s no support line to call. You’re the support line.

For whom: the one who already self-hosts at home, who has a Mac mini or a NAS on hand, and for whom “my data on my machine” outweighs “encrypted with a third party.” He takes the deal with eyes open.

Price: free, it’s self-hosting. Your only cost is the hardware and your time.

Immich web interface: photo timeline, geolocation map and a photo's detail view with its EXIF metadata

Immich on iPhone: timeline, search by people and places, albums, a photo's detail view and the automatic backup screen

The self-host verdict. For most people, the winner is Ente. It’s the only one that gives you self-hosting without giving up end-to-end encryption, with a real Mac app and on-device smart search, a notch below Immich but plenty good enough. The price to pay is the install, and let’s be honest about it. Just to test at home, Ente’s official script spins up its database and its storage on its own, barely longer than Immich. But for a durable install, the one that keeps your ten years of photos safe, Ente asks you to understand object storage, an S3 bucket to configure, access keys to manage, where Immich makes do with a folder on your disk. It’s not insurmountable, but it’s not “a hair”, it’s a real step up. So Immich stays the pick for whoever wants search pushed to its maximum and the simplest install of the lot, and who accepts protecting their photos with disk encryption alone. The real split between the two isn’t “encryption or search”, both can search: it’s E2EE, yes or no.


The synthesis

Three solutions, three positions on two axes only: where your photos live, and whether they’re end-to-end encrypted. The rest follows. The dry summary, service by service.

  • Proton, cloud with the maker, end-to-end encrypted, but no self-hosting possible.
  • Ente, both at once, encrypted cloud like Proton and self-hostable like Immich, with E2EE in both cases.
  • Immich, self-host only, no server-side encryption.

The whole comparison reads right there, or almost. Ente is the only one to tick both hosting modes, encrypted cloud AND machine at home. Proton locks the cloud with no self-host. Immich does the reverse, self-host with no server encryption. What’s left is to settle what this summary doesn’t say.

Encryption. Proton and Ente make your photos unreadable to them, court order included. Immich doesn’t encrypt server-side, its protection is your disk encryption. Watch the easy shortcut: Immich doesn’t trade encryption for smart search. Ente also does semantic search and facial recognition, on-device. Immich is simply a notch above on that front. The real divide stays E2EE.

Jurisdiction. Proton in front, Switzerland outside the CLOUD Act. Ente just behind: American entity, but data in the European Union and a court order neutralized by zero-knowledge. Immich in its own category, your data is wherever you put it.

Price. Immich is free if you already have the hardware. Ente and Proton play in the same per-gigabyte range, with an edge to Proton if you already take its whole suite.

Longevity. Proton is the rock, more than 500 people and a foundation that blocks any takeover. Ente is smaller but self-hostable, so survivable, you get everything back if the company folds. Immich depends on a community project, but since it runs at your place, its disappearance doesn’t lock you out.


Mack’s recommendation

Sovereignty doesn’t come down to a Swiss flag slapped on an icon. It’s a stack of trade-offs, and the most “obvious” of the three, Proton, hides the most closed server code of the lot. Once you’ve digested that, the choice gets clear, because it no longer hangs on the marketing but on what you, yourself, refuse to give up.

Let’s start with the two that host for you.

Cloud, zero effort, you just want out of Google: Proton. You turn on backup on iPhone, it’s encrypted, it’s Swiss, and you stop thinking about it. And if you already use Proton Mail, you have strictly nothing more to do. It’s the shortest path out of Google’s house.

Cloud, but you want proof of encryption and open code, not the promise: Ente. The best dedicated photo app, the only fully open code audited on both sides, data in Europe. For a demanding reader who wants the concrete under the hood, it’s the most complete cloud. It’s also mine when I recommend a photo library to someone who isn’t already in the Proton world.

Then, for those who want the machine at home.

Self-host without giving up encryption, my default pick: Ente. You host at home, you keep E2EE and a real Mac app. Just count on a more demanding install than Immich the day you want it durable, the time it takes to tame object storage. For whoever puts encryption above the rest, it’s worth it.

Self-host, maximum search and the simplest install win: Immich, on one condition, that you hear the trade-off, no E2EE, you protect your photos with your disk encryption and nothing else. In exchange, absolute control, the smartest photo library of the lot, and the most direct deployment.

One word to avoid confusion: this comparison is about the photo library, about replacing Google Photos with automatic backup. If your question is about general file storage, invoices, contracts, documents, that’s a different match, and it plays out elsewhere.


In short

Two encrypted clouds, two servers to run at home, and a pivot that plays both camps. The through line isn’t “which one is best”, it’s a single question: what do you place above everything? Turnkey peace of mind, proof of open code, or physical ownership of your files.

Concretely, by profile:

  1. Cloud with no effort, already on Proton or drawn to the Swiss all-in-one: go to Proton Photos, turn on iOS backup, done.
  2. Cloud, but you want the best app and proven encryption, not sworn: install Ente, import from Apple Photos, let automatic backup do the rest.
  3. Self-host, you want to keep encryption: Ente self-hosted, accepting a more demanding install for the durable setup. If maximum search and simplicity win, Immich, knowing you’re trading E2EE for mastery.

Start by exporting your photos out of Google before you close anything. You can migrate over a weekend. Reclaiming ten years of memories locked somewhere else, no.


Sources

The publishers themselves

  • Proton Drive and Proton Photos (proton.me), the Geneva company brought under Proton Foundation control in June 2024, for encryption, jurisdiction and pricing.
  • Ente (ente.io), the maker of the open source encrypted photo library, for the zero-knowledge architecture and the plans.
  • Immich (immich.app), the self-hosted project funded by FUTO, for features and the stance on encryption.

The code and the audits

  • Ente’s server on GitHub, opened under AGPL-3.0 since March 2024, with the Cure53 audit reports (2023 and October 2025, the latter sponsored by CERN).
  • Immich’s code on GitHub, client and server under AGPL-3.0, to check the nature of the project and its activity.
  • Securitum reports on Proton’s apps (web 2021, iOS and Android 2022, published in March 2023).

The legal framework

  • The US CLOUD Act and the revised Swiss federal data protection act, to place the respective jurisdictions.