Balise

Your photos are personal

Useful to you.
Private by design.

Sealed on your iPhone. Opened only by automated processing, with a key no one at Balise, or anywhere else, can use.

Balise makes your photos useful without keeping a second photo library. Your originals stay in Apple Photos.

Watch · 0:48

How Balise protects your photos.

Sealed on your iPhone

Each processing copy gets its own new key and is sealed before it leaves your phone. Storage only ever holds the sealed copy.

Our team can’t open your photos

Not as a policy, by design. The key that opens a copy lives in a hardware vault in separate custody, and only automated processing may use it. An independent custodian holds that rule, not us.

You decide what your AI sees

Claude and ChatGPT can use your searchable information. To receive photos, they need your approval for the exact selection. Access through Balise lasts one hour.

In a small coffee shop, a photo on an iPhone folds itself into a washi envelope locked with its own small key.

What happens to a photo

Sealed all the way to the one place it’s opened.

  1. Your iPhone

    Seals each copy with its own new key. The original stays in Apple Photos.

  2. Private storage

    Only ever holds the sealed copy.

  3. The processing service

    The one place a copy is opened, so Balise and its AI providers can analyse it. Providers get a readable copy for a limited time.

  4. What Balise keeps

    What it learned. The copy is deleted.

Some processing uses a temporary copy in private cloud storage. The details below explain the limits and exceptions.

Balise’s team works behind a glass wall while a small robot carries one sealed envelope to the iron door of a storehouse, kept by an independent custodian drawn as a friendly knight with a golden key on his surcoat.

Who holds the key

No one at Balise, or anywhere else, can use the key.

It can’t leave the vault
The private key was created inside a hardware security module and cannot be exported, by Balise or by anyone else. A copy can only be opened by asking the vault to unlock its key.
One door, and it’s automated
Only the processing service may ask the vault to unlock a photo key, one photo at a time. Our team’s accounts, our servers and our deployment tools are refused by the access rule, and no person can sign in as the processing service.
Held by someone who isn’t us
An independent custodian outside Balise holds the access rule, and the signing key that vouches for any new vault key. We can’t widen who may use the key on our own, and every use of it is recorded for the custodian.
On a veranda, someone approves photos on an iPhone with a glowing seal, while a robot at the garden gate checks the seal and stops an unsigned paper from a server.

When you connect Claude or ChatGPT

A connection isn’t permission to see every photo.

Your assistant can search the information Balise has learned. When it needs photos, Balise shows you the exact selection to approve in the app.

Approval covers only those photos and that requesting connection, for one hour from your decision. Looking again doesn’t extend the hour. A new selection needs a new approval.

Your approval is signed on your iPhone. The service that decrypts a photo checks that signature before it opens anything, so an approval Balise’s own servers produced opens nothing.

The hour limits access through Balise. It cannot erase a photo the assistant has already received or remove it from your conversation. Your assistant’s own settings and policies apply there.

In a tatami room, a small robot drops one sealed envelope into a small iron brazier and slides another, tied with a sprig of herbs, into a lacquered box.

Photos that need more care

Some photos get extra care.

Explicit photos are dropped
Balise drops them early, before looking any closer, deletes them, and learns nothing from them.
Health photos stay private
What Balise learns from a prescription, a test result or a photo of an injury stays your own record, so you can ask about it in Balise or with the assistant you connect. Those photos never appear in a Story, a highlight, a cover or on your map.

What stays, and for how long

Your photos and what Balise learns are different.

In a tatami room, a small robot writes notes while the photo it looked at dissolves into petals.
Ordinary processing copies
Deleted after processing finishes, including any enabled People comparison. A one-day storage cleanup rule backs up interrupted deletion.
Photos you approve for an assistant
Only the selected copies, with access ending one hour after approval. Deletion follows expiry; fetching a photo again never extends access.
Photos waiting for a new category
Nothing is kept. If Balise needs a category it has not built yet, it keeps what it noticed about the photo, not the photograph.
Searchable information
Descriptions, dates, locations, notes and other details remain in your private Balise account so you can find and use them. Deleting a processing copy does not delete this information. You can delete it in Balise.
Things you publish
Cards, Stories and other published content follow your sharing choices. They stay available under their publishing rules until you take them down. Someone may already have saved a copy.

If you’d like the details

A closer look at the protection.

How does the encryption work?

Your iPhone gives each processing copy its own new AES-256-GCM key and seals the copy with it. It then seals that key with a 3072-bit RSA-OAEP (SHA-256) public key, so only the matching private key can open it. Copies stay sealed in storage.

The private key was created inside a hardware security module (Google Cloud HSM) and cannot be exported. Only the processing service may use it, to unlock one photo key at a time. The API coordinates requests but never holds the key. Any image processing derives from a photo is sealed again with a new key. Your searchable information is not sealed that way — it is stored separately, as the next answer explains.

Your iPhone also recognises the key it seals to. Handed a key it doesn’t recognise, and that the custodian has not vouched for, it stops instead of uploading.

Is everything end-to-end encrypted?

Balise encrypts image copies before upload, but automated processing needs to decrypt them. It is not a system where only your devices can ever analyse the images. Your searchable information is stored separately on Balise’s servers and is not covered by the same per-image encryption.

What do AI providers receive?

Balise’s processing providers receive the readable images or text needed for the task. Photo access uses short-lived links or a temporary private cloud input. Vertex inputs currently have a ten-minute access window; access expires independently of physical deletion, which is retried after expiry with a one-day storage cleanup backstop. These temporary inputs use cloud storage encryption, rather than the phone’s per-image encryption.

Balise does not authorize training on your content. That is different from promising that a provider retains nothing. See the Privacy Policy for providers and the data involved. Connecting your own Claude or ChatGPT account is a separate choice governed by that service’s settings and policies.

What does “our team can’t open your photos” mean?

No one at Balise can open a private photo copy, and that isn’t a staff policy. Our accounts are refused by the rule that guards the key. That rule is held by an independent custodian outside Balise, who also receives a record of every use of the key.

The copy is encrypted on your iPhone, so without the master key it can’t be opened.

If you deliberately publish a photo or send one to support, the people you share it with can see it.

Your memories. Your say.

Choose what Balise can import. Approve photo requests. Delete what Balise has learned whenever you want.

Get an inviteRead the Privacy Policy

Last updated 11 September 2026. Questions? Talk to us.