Albums are references, not containers

A Photos album is a view onto items in the library rather than a folder holding copies. Current Photos does not offer a per-album password; that is a product capability limitation, not a claim that an access-controlled logical view is technically impossible.

It also means deleting an album does not delete the photos in it, which surprises people in both directions.

What is actually available

For casual concealment, the locked Hidden collection is the built-in answer. It requires authentication on current iOS versions and its entry point can be removed from the albums list.

For a genuinely separate credential and encrypted storage, that requires an application designed for it. The distinction is between hiding within Photos and storing outside it.

Naming does nothing

An album called Private is exactly as accessible as one called Holidays. The name is a label on a view, and anyone browsing the albums list sees both.

This sounds obvious written down, and it is a common arrangement in practice.

The realistic setup

  • Confirm Hidden requires Face ID, Touch ID, or the device passcode.
  • Turn off Show Hidden Album if casual discovery is the concern.
  • Audit iCloud Photos and every other device signed in to the same Apple Account.
  • For a separate credential, evaluate an encrypted vault and test its recovery path.

Two errors

  • Naming an ordinary album “Private” and treating it as locked.
  • Deleting originals before a protected copy and its recovery path are verified.

A fictional example

Amara starts with a non-sensitive test: “Confirm Hidden requires Face ID, Touch ID, or the device passcode.” Next, Amara follows the second check: “Turn off Show Hidden Album if casual discovery is the concern.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Naming an ordinary album 'Private' and assuming it is locked
  • Deleting originals before a protected copy and recovery path are verified

What this workflow does not change

  • Naming an ordinary album 'Private' and assuming it is locked
  • Deleting originals before a protected copy and recovery path are verified

Questions people ask

Can one iPhone album use a different password?

Photos does not provide a separate password per album.

Sources and further reading