Local-first product · Family archive

The archive travels.
The data stays private.

A portable Windows photo library runs from an external drive, turns decades of folders into a searchable catalog, and preserves the originals as the source of truth.

Public screenshots are privacy-safe derivatives of the deployed interface. No family photos, folder names, paths, or source code are published.

Privacy-safe Family Photos browser showing generic nature demo images
PORTABLE APPBrowse · search · filter · favorite
25,932catalog entries
22,942distinct assets
3 / 3readable sources
6user-data backups

01 · Product decision

The daily experience is a photo browser—not an AI console.

The product is designed for non-technical family use: no account, no subscription, no cloud dependency, and no command line. Search, date navigation, folders, favorites, rotation, and import stay visible; administration remains separate.

01

Portable runtime

The application, catalog, thumbnails, review state, backups, and imports share a marker-defined drive layout.

02

Catalog, not relocation

Original media stays in place. The catalog adds dates, media metadata, tags, deduplication, and fast browsing.

03

User data separated

Favorites, manual decisions, suggestions, and rotation state live outside the formal catalog and are backed up independently.

04

AI is optional

Local visual analysis prepares suggestions in staging. The family browser remains usable without loading or exposing an AI workflow.

02 · Verified deployment

Evidence came from the portable production drive, opened read-only.

The deployed executable was launched from the external drive. SQLite integrity checks and aggregate queries used read-only connections; database timestamps remained unchanged after inspection.

25,649images
283videos
2,024duplicate groups
2,990extra file locations
25,301metadata successes
22,659locally analyzed assets
Privacy-safe folder location review with 317 decisions
Privacy-safe derivative of the deployed folder-location review. All 317 folder decisions were already covered; identifying names and paths were replaced.

03 · Privacy architecture

Private source, local data, public proof.

The complete application source is stored in a private GitHub repository. The public case publishes only an explanatory page, aggregate JSON, and privacy-safe interface derivatives.

Private

Source code, original photos, folder names, paths, catalog files, user decisions, raw screenshots, and portable-drive identifiers.

Public

Product decisions, system boundaries, verified aggregate counts, limitations, and screenshots with sensitive content replaced.

Controlled

Production publication follows a Preview-first gate and requires explicit human approval after responsive and privacy QA.

04 · Honest quality boundary

Database integrity passed. Filesystem alignment still has work.

All inspected SQLite databases returned integrity “ok”, but a full catalog-to-filesystem validation found 93 missing paths among 25,932 catalog entries. The case keeps that drift visible; no automatic sync or repair was performed during publishing.

Read-only evidence

Inspection did not import, synchronize, restore, rotate, or rewrite any family data.

Suggestions are not facts

Local AI results remain suggestions with explicit Accepted, Rejected, and Suggested states.

Screenshot boundary

Published images are labeled privacy-safe derivatives and must not be used as proof of the original photo content.

Delivery result

A family archive can be useful without becoming a cloud product.

The private repository preserves the full implementation. This case shares the product thinking, verified scale, privacy model, and current quality boundary.

Back to top ↑