Protect one photo or several photos

Apple Photos does not give each image or ordinary album a custom password. The Hidden collection uses device authentication. For separate access, NullVault uses a vault pattern rather than a per-photo password; multiple imported photos can share that vault.

Use the iPhone hiding guide for the built-in steps, or pattern-locked vaults for independent storage. Choose a pattern unrelated to the phone code, import the intended items, reopen them after locking, and confirm recovery before deciding whether to remove the source copies. The phone lock versus vault lock guide explains who each credential permits to enter.

There is no per-photo password

iPhone does not assign an individual credential to a single item in the Photos library. Protection operates at the level of a collection, an app, or the device — not one image.

So the question becomes which of those levels to use, and what happens to the original once you do.

Each option protects a different copy

Adding an item to the locked Hidden collection changes its presentation and membership within the Photos library under device authentication. Attaching a copy to a locked note protects the copy while leaving the original in Photos. Importing into a vault protects the imported copy under a separate credential.

The note and vault workflows create protected copies. Hidden remains within the Photos library, so the cleanup and copy audit determine what exposure remains.

A common copy-management failure

Protecting a duplicate while leaving the original visible in the library is a possible failure when the protective step feels like completion.

Verify the protected copy opens at full resolution, then deal with the original, the edits, and Recently Deleted.

Working through it

  • Decide whether device authentication is sufficient or an independent secret is required.
  • Create or move the protected copy.
  • Open the protected item at full resolution to confirm it is intact.
  • Audit the original, any edited versions, exports, and Recently Deleted.

Two errors

  • Protecting a duplicate while the original remains visible.
  • Relying on a device passcode that the people you are protecting against already know.

A fictional example

Eli starts with a non-sensitive test: “Choose whether device authentication or an independent secret is required.” Next, Eli follows the second check: “Verify the protected full-resolution item opens.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Protecting a duplicate while leaving the original visible
  • Using a recipient-known device passcode as the only boundary

What this workflow does not change

  • A locked note or vault protects its copy; the Photos original may remain.
  • The Hidden collection uses device authentication rather than a custom password for each photo.
  • Protecting a collection does not remove the need for recovery material and a usable backup.

Questions people ask

Can a locked note hold one image?

Yes, but verify whether a source copy remains elsewhere and whether the note title reveals context.

Sources and further reading