The realistic risks are close to home
Discussion of this topic tends toward remote attackers, but the exposures that actually occur are mundane: someone picking up an unlocked phone, a shared account, an automatic cloud upload, a message attachment, a former partner who still has copies, or pressure to unlock a device.
Planning for those produces better protection than planning for a sophisticated adversary who is unlikely to be involved.
Shorten the path at capture
The default camera path creates an original in the camera roll, frequently uploads it automatically, and may generate thumbnails and suggestions before you have decided anything.
Capturing directly into protected storage, where the app supports it, avoids creating the copies you would otherwise have to find and remove.
Audit what already exists
- Review cloud photo libraries and their sharing participants.
- Check message threads in both directions, and any saved attachments.
- Look at photo editors, which retain their own copies.
- Check Trash and Recently Deleted, which are retention windows.
- Consider devices signed in to the same account, including old ones.
Credentials and coercion
Keep the vault credential unrelated to the device passcode, since the situations that matter here usually begin with an unlocked phone.
Destructive duress features exist for coercion scenarios and are irreversible. Understand precisely what they destroy, and test a backup, before enabling anything of that kind.
Two things to be clear about
- Enabling destructive options without understanding or testing the consequences.
- Assuming deleting your copy affects a copy someone else already holds.
If images are shared without your consent
Sharing intimate images without consent is a criminal offence in many jurisdictions, and specialised services exist to help with removal from platforms and with reporting — you do not have to approach platforms alone.
Preserve evidence before deleting: screenshots showing dates, account identifiers, and context. If someone else may control your device or account, platform safety-check tools and a domestic-abuse support service are the right starting points rather than changing settings unilaterally.
A fictional example
Eli starts with a non-sensitive test: “Capture directly into protected storage when available.” Next, Eli follows the second check: “Review cloud libraries, shared devices, messages, editors, and Trash.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Enabling destructive duress without understanding consequences
- Assuming deletion recalls another person's copy
What this workflow does not change
- Enabling destructive duress without understanding consequences
- Assuming deletion recalls another person's copy
Questions people ask
What if someone threatens to share an image?
Preserve evidence safely and contact appropriate platform reporting, trusted support, and current local legal or advocacy resources.