explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

contactsupportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR — should you self-host?
  • Immich 3.0 — what shipped (July 1–2, 2026)
  • The HN argument — E2EE, trust, and "whose computer?"
  • Real cost math — self-host vs Google One
  • Privacy beyond storage — blur before you publish
  • Operational patterns that work (from HN + docs)
  • Immich 3.0 vs Ente — pick your tradeoff
  • What people still complain about (honest)
  • Checklist before you switch
  • Related Reading
← Back to blog

explainx / blog

Can You Self-Host Your Photos? Immich 3.0, Privacy, Costs, and When to Blur Faces

Immich 3.0 (July 2026) is the top HN self-hosted Google Photos alternative. Real cost math vs iCloud, E2EE debate (Ente vs Immich), Tailscale access, and bgblur.com for face privacy before you share.

Jul 3, 2026·8 min read·Yash Thakker
ImmichSelf-hostedPrivacyPhotosEnteBGBlur
go deep
Can You Self-Host Your Photos? Immich 3.0, Privacy, Costs, and When to Blur Faces

Can you self-host your photos? Yes — and July 2026 is the loudest moment yet for the idea. Immich 3.0 hit Hacker News the same week (286 points, 141 comments) while v3.0.1 patched mobile album display. The thread was not really about slideshow UX — it was about trust: Who can see your library? What does self-hosting cost in money and time? And do you need end-to-end encryption or just disk you control?

This post answers those questions — Immich 3.0 in context, Ente as the E2EE alternative, real cost math, and bgblur.com when you share faces outside your trusted circle.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.


TL;DR — should you self-host?

QuestionShort answer
Can I replace Google Photos?Yes — Immich 3.0 is the closest open-source match for backup + search + sharing
Is it free?Software is free (AGPL); hardware, power, backups, and your time are not
Is it private?More control, not automatic secrecy — you secure the server, network, and shares
E2EE?Immich: no · Ente: yes — pick based on threat model
Immich 3.0 worth upgrading?Yes if you run v2 — mobile editing, integrity checks, backup fixes
Blur faces before public share?Yes when consent is unclear — bgblur.com for quick anonymization

Immich 3.0 — what shipped (July 1–2, 2026)

Immich crossed 105k GitHub stars with v3.0.0 — the first major with release candidates beforehand.

FeatureWhy it matters
Mobile non-destructive editingCrop/rotate on thumbnails without destroying originals — closer to Apple Photos workflow
Workflows (preview)Drag-and-drop automation — triggers, filters, actions (tagging, etc.)
Recently Added pageFaster "what landed this week" browsing
Integrity checksDetect DB/file mismatches before silent corruption spreads
Background backup improvementsAndroid scheduler uploads full library; iOS parallel refresh
HLS + real-time transcoding (preview)Smoother web video without waiting for full transcode
New web video playerConsistent controls; fixes iOS layout pain
OCR on mobileSearch text inside screenshots and documents

Upgrade path: set IMMICH_VERSION=v3 in .env, run usual Docker compose pull/up. Migration guide — drops pgvecto.rs; mostly API breaking changes for third-party tools, not typical family users.

We maintain a longer Immich overview; this post focuses on 3.0 + privacy economics.


The HN argument — E2EE, trust, and "whose computer?"

The July 2026 thread split along predictable lines:

"Immich is fine — I trust my homelab"

  • You control disk, backups, and network exposure
  • LUKS / ZFS encryption at rest on the NAS protects stolen hardware
  • Tailscale or WireGuard avoids exposing Immich to the open internet — the pattern TREK homelab users and Immich operators share

"I want E2EE — use Ente"

  • Ente encrypts client-side before upload — provider sees blobs, not faces
  • Polished mobile apps, 10GB free hosted tier, self-host escape hatch
  • Tradeoff HN users cite: key loss = data loss unless recovery is set up; upload reliability complaints on self-hosted Ente vs Immich for huge libraries

"Encryption at the wrong layer"

Several commenters noted: on self-hosted Immich, you are the operator — E2EE mainly matters when a third party hosts disks (managed VPS, small cloud seller). Full-disk encryption + VPN is the homelab answer; Ente is the "hosted but blind provider" answer.

ThreatImmich + homelabEnte E2EE cloud
Google reading photos✅ avoided✅ avoided
Stolen NAS at homeDisk encryption helpsN/A (blobs remote)
Rogue VPS adminN/A if self-hosted✅ ciphertext only
You lose encryption keysN/A❌ catastrophic
Family "just works" supportYou are ITEnte closer to consumer UX

Neither replaces consent discipline when sharing links publicly.


Real cost math — self-host vs Google One

Illustrative 2026 numbers for a 2TB family library:

Line itemSelf-host (Immich on NAS)Google One 2TB
Upfront hardware$200–600 (NAS or mini PC + disks)$0
Electricity (~25W 24/7)~$6–10/mobundled
Subscription$0 (AGPL software)~$10/mo
Your time (updates, backups)2–8 hr/mo~0
3-2-1 backup mediaExtra disk or cloud sync ~$5–15/moGoogle's problem
5-year total (rough)$800–1,500 + labor~$600

Self-host wins when:

  • Library exceeds cheap cloud tiers
  • You already run a homelab (Immich pairs with other stacks)
  • You want partner sharing without training Google on kids' faces
  • AGPL sovereignty matters for compliance narratives

Cloud wins when:

  • You will not maintain Docker upgrades
  • Family expects Apple/Google-grade "it just syncs"
  • Off-site disaster recovery without designing it yourself

Privacy beyond storage — blur before you publish

Self-hosting removes Google's indexer; it does not remove consent when you:

  • Share public upload links for weddings and events (Immich supports anonymous album uploads — Immich Public Proxy patterns for exposing only /share)
  • Post screenshots to LinkedIn / X (C2PA labels disclose AI; they do not blur children)
  • Export press or marketing stills

bgblur.com — browser-based AI face blur for photos and video:

  • Face blur tool — detect multiple faces, adjust strength, blur vs pixelate
  • Video face blur — tracked anonymization across frames
  • Selective blur — hide bystanders, keep speakers (consent-based)
  • Files processed for the session; privacy-first marketing claims no permanent storage — still treat any cloud tool as untrusted for highly sensitive material; run local tools when paranoia is appropriate

We covered plate and object blur in AI privacy for video — same principle: redact before distribution, not only before upload.

Workflow: Immich for archive → bgblur for publishable subset → social or public album.


Operational patterns that work (from HN + docs)

Read-only external libraries

Point Immich at a read-only NAS mount — manage files yourself; Immich indexes without owning the canonical tree. External libraries have been available for years; 3.0's integrity checks help catch drift.

text
NAS /photos/YYYY/MM  →  docker volume :ro  →  Immich external library job

Google Takeout → Immich

Pain points from HN:

  • 50GB browser download limits — use curl with session cookies to NAS directly
  • Windows extract — native extract fails on 4GB+ zips; use 7-Zip
  • immich-go — recreates Google Photos albums; resume after server errors

Budget days for 700GB+ imports, not an afternoon.

Network exposure

PatternRiskHN sentiment
Tailscale / WireGuard onlyLow public attack surfacePreferred
Cloudflare TunnelConvenient; watch 100MiB upload limits on videoPopular compromise
Raw port forwardBrute force, CVE rushDiscouraged without CrowdSec

Backups

Immich README: 3-2-1. HN horror stories: upgrade without DB snapshot → months of pain. v3.0 integrity checks help early detection — they do not replace backups.


Immich 3.0 vs Ente — pick your tradeoff

Immich 3.0Ente Photos
Primary designSelf-hosted Google Photos UXE2EE first; cloud or self-host
Face / CLIP searchServer-side MLClient-assisted; evolving
Public event upload linksStrong Immich featureAlbum contribute links
LicenseAGPL-3Open source clients + server
Best forHomelab families, 2TB+ librariesPrivacy cloud with encryption keys
July 2026 buzz3.0 launch, 105k starsGrapheneOS migrants, encryption

You can run both: Ente for pocket daily sync, Immich for home archive master — if you accept duplicate ops (most people pick one).


What people still complain about (honest)

From HN and GitHub discussions — not Immich marketing:

  • iOS backup historically filled phone storage; 3.0 improves scheduling — verify on your library size
  • External library + multi-user thumbnail duplication (same image, per-user embeddings) — roadmap item
  • Nested albums / Lightroom-style folders — still awkward for power organizers
  • No Immich E2EE — feature request, not roadmap commitment
  • Upgrade anxiety — DB migrations on personal archives are stressful; use RC discipline and snapshots

Checklist before you switch

  1. Size your disk — library + thumbnails + ML embeddings ≈ 1.3–2× raw photo size
  2. Plan 3-2-1 backups before importing Google Takeout
  3. Choose access — Tailscale first; public internet last
  4. Decide E2EE need — homelab only vs hosted VPS → Immich vs Ente
  5. Test mobile backup on a small album before 20k photos
  6. Blur faces on anything public — bgblur.com
  7. Upgrade to v3 — IMMICH_VERSION=v3, read migration guide

Related Reading

  • EU driver-facing camera law (2026) — ADDW privacy & bgblur.com
  • Immich: Self-Hosted Photo Library (Overview)
  • Blur License Plates and Video Privacy (BGBlur)
  • LinkedIn & X AI Image Labels — C2PA
  • TREK — Self-Hosted Travel Planner
  • files.md — Local-First Notes
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

Immich v3.0.1 and HN discussion accurate as of July 3, 2026. Official: immich.app, v3.0.0 release notes, GitHub releases. Cost figures are illustrative — meter your hardware and power locally.

Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

May 5, 2026

Immich: self-hosted photo and video library (Google Photos–class, AGPL-3)

What Immich is, who it is for, how it differs from cloud galleries, and what operators should plan for: backups, Docker, machine-learning services, and license trade-offs.

Jul 9, 2026

EU Driver-Facing Camera Law (2026): ADDW Privacy Guide for Drivers and Builders

EU ADDW mandates driver-facing cameras from July 7, 2026. The law says on-device processing; the backlash is about what happens when OEMs, insurers, or debug pipelines export cabin video. Practical privacy guide + bgblur.com tooling.

Jul 27, 2026

ChatGPT Health: Connect Apple Health and Medical Records Safely

OpenAI is rolling out Health in ChatGPT to U.S. adults on web and iOS, with permissioned access to Apple Health and supported medical records. This guide explains what changed from the January pilot, how data and memory controls work, and which health questions remain unsafe to delegate.