An album for an event. Every photo is encrypted in your browser and stored in the
data set your own wallet pays for; only people holding the album's access key can see them. The page folds
every member's data set; there is no server.
With approval, people ask to join from the link and you let them in (or out) by wallet; nobody
holds a shared key. Removing someone stops them seeing anything added afterwards.
Your wallet signs twice: once to lock the album's key to it, once more to check it signs the same way every time.
albums this browser opened
this album is locked
Paste the access key the album's owner sent you. It is never part of the link.
Only people the album's owner approves can see it.
invite people
Send the link and the access key separately (say, the link on a slide and the key in the event chat).
link:
access key:
Anyone with the key can see every photo and add their own. Keys cannot be taken back.
members
People ask to join from the link. Approving sends them the album's keys; removing starts a new
key for everything added afterwards (they keep what they have already seen).
asking to join
members
removed
add photos
What these photos carry. Keep what you want the album to see; the rest is removed.
Photos are resized to 1600px and re-encoded, so the image itself carries no metadata. What you
keep above is stored with the photo, encrypted like it: only people with the album key see it.