Send one photo.
Then take it back.
Set how long it lives. Set how many times they can open it. Kill it after you’ve sent it — even after it’s been delivered. It never lands in their camera roll.
This is the real thing. Try it.
The problem
Every photo you send is a permanent gift.
The second it arrives it’s theirs. It goes to their storage, their gallery and their cloud backup — and every one of those is their setting, not yours.
You send it
One tap. That is the last decision you get to make about it.
It lands in their camera roll
Whether it gets saved there is their setting, never yours.
It syncs to their cloud backup
Where end-to-end encryption is opt-in, if it is offered at all.
It copies to every device they own
Laptop, tablet, the old phone in a drawer.
And it stays there
No expiry. No view limit. No way to take it back.
Versus what you already have
You have view-once. Here’s what it can’t do.
The controls you want exist as one fixed preset, buried in an app built for something else.
| Capability | Peek | Snapchat | Signal | ||
|---|---|---|---|---|---|
| Custom duration | Yes | Limited | Limited | Limited | Limited |
| View count | Yes | Limited | Limited | Limited | Limited |
| Revoke after sending | Yes | Limited | Limited | Limited | Limited |
| No camera roll | Yes | Limited | Limited | Limited | Limited |
| Screenshot alert | Yes | No | Limited | Yes | No |
| Recipient watermark | Yes | No | No | No | No |
| No account for them | Yes | No | No | No | No |
| Server can't read it | Yes | Yes | No | No | Yes |
Swipe the table sideways to see every app →
- Full control
- Limited
- None
Checked against each company’s own documentation in August 2026. “Limited” means the feature exists in some form, but not as a per-photo control you set — and anything the recipient already saved stays saved. These products change often. If something here is out of date, tell us and we’ll correct it.
Per photo, not per app
You write the terms.
Three chips, one tap each. Set a default once and sending is a single tap after that.
How long
How many times
Watermark
They can open it three times in the next 24 hours. After that it stops opening, for good.
Every view carries a faint watermark tied to their device. You can kill it before then, from your phone.
How it works
We enforce a policy on a file we can’t read.
Client-side-only expiry is an honour system. Ours isn’t — the server stops serving the file when your policy says so, without ever learning what it is.
- 01
Encrypted before it leaves
Your phone encrypts the photo with AES-256-GCM. What travels is ciphertext.
- 02
We hold a file we can't open
The blob sits on our servers under your policy — expiry, view count, revoked or not. We enforce all of it without ever seeing the picture.
- 03
The key rides in the link
It lives in the URL fragment, which browsers and link handlers never send to a server. It goes from your phone to theirs, past us.
No asterisks
What we can and can’t see.
Most privacy pages stop at the flattering half. Here’s all three parts, including the one that isn’t.
What we can’t see
The photo. It’s encrypted on your device before it’s uploaded, and the key travels in the link — never to our servers. We hold an encrypted file we have no way to open.
What we can see
That you sent something, when it was opened, and how big the file was. We keep as little of it as we can and delete it on expiry.
What nobody can prevent
Someone photographing their screen with a second phone. No app stops that, and any app that says otherwise is lying to you. What we do is make it obvious and traceable — screenshot alerts, and a watermark tied to the recipient.
The app isn’t out yet.
Be first through the door.
One email when it ships. Nothing else, and never to anyone else. What we do with it.