NAOMS Devlog

Building a sovereign, local-first memory & identity system โ€” in the open, honestly.

A Photos App That Never Hands Your Library to Anyone

Seventeen screens redesigned in a day, rebuilt for a world with no cloud

Product Architect free June 7, 2026ยท6 min readยทclients
TL;DR Your photos get an app that looks like the cloud ones you know โ€” a flowing river, places, people, stories โ€” but never stores a single image on anyone else's servers. Seventeen redesigned screens landed in one day; honestly, they're still in verification, not finished.

On the seventh of June, the photos experience in NAOMS got a new face โ€” not a tweak, a redesign โ€” and it landed not in a slow trickle but as a wave. The git log for that day reads like a roll call of screens, each rebuilt on its own and landed the same afternoon: people, stories, studio, places, the events timeline, sharing, editing, threads, the events-blocks layout, the shared-bundle view. Seventeen redesigned surfaces, all part of one push โ€” the photos redesign.

The redesigned NAOMS photos shell โ€” top bar, side rail, chips, and the main content surface.

We want to walk through what those surfaces are โ€” because a photos app sounds like a solved problem until you remember this one stores nothing in anyone's cloud, and that one constraint reshapes every screen.

The shell

Start with the frame everything else hangs in. The shell is the persistent chrome: a top bar, a side rail of destinations, a row of filter chips, and the large content area that the other surfaces render into. The redesign treats it as a true application shell โ€” the rail and chips stay put while the body swaps between views โ€” which is what lets the experience feel like one app rather than a stack of unrelated pages.

(An honest note on this image, held to the project's standards: these screenshots were re-rendered on the eleventh of June, a few days after the surfaces landed on the seventh. They faithfully depict the redesign that shipped this week โ€” there are real landings in the seventh's git log to prove it โ€” but the image files themselves are a later render, not a capture taken the day it shipped. We'd rather tell you that than caption a re-render as a live photograph.)

The river

The headline surface is the river โ€” the continuous, scrolling flow of your photos in time. The name is deliberate and it runs through the whole project: a river is something you watch flow past, where recent things are near and older things drift away, rather than a grid you administer. It's the same metaphor NAOMS uses for its event stream, applied to images: your photographic memory as a current, not a filing cabinet.

The redesign also shipped a places view (photos organized by where they were taken), a people view (organized by who's in them), and events, which landed in two forms the same day โ€” a timeline layout and a blocks layout โ€” letting the same underlying event grouping render either as a chronological spine or as discrete blocks. That two-layout split is a small tell about the design's maturity: events aren't a single hard-coded screen, they're a model that can be presented more than one way.

Stories and studio

Two of the surfaces push past organizing-what-exists into making-something-new.

Stories is the curated, narrative presentation โ€” your photos arranged into a told sequence rather than a raw feed. Studio is the creative surface โ€” the place editing, generation, and composition live. Both landed the same day.

We'll be careful here, because this is exactly where honesty matters most. Stories, studio, and memories landed this week as mock-faithful redesign surfaces โ€” meaning the surface (the layout, the structure, the visual design) is what shipped, built faithfully to the approved design mock. That is real and it is on disk. What we are not going to claim is that every generative capability behind studio is fully wired and production-complete, because the record doesn't support that and the work's own status doesn't either. The shape shipped. The surface is faithful to its mock. Read it as that, precisely.

Sharing, editing, and the inspector

The remaining surfaces are where local-first stops being an abstraction and becomes UI.

Sharing (a share drawer, plus a shared-bundle view) is the surface that answers "who can see this photo?" In a cloud photos app, sharing means uploading to the provider and granting access on their servers. In NAOMS there is no provider. Sharing a photo means granting a specific person, over an encrypted channel, the ability to decrypt it โ€” and the redesign's share drawer, the "shared with me" view, and the "forgotten" state (photos you've revoked or removed from a share) are the UI for a sharing model where you hold the keys and you can take them back. The inspector โ€” the per-photo detail panel โ€” is where that state becomes legible: who has this, where it came from, what's attached.

Editing (an edit drawer) rounds it out: crop, adjust, the ordinary photo edits, but operating on data that never leaves your control to be edited. The redesign brought an edit drawer surface in line with the rest of the visual system.

Why a local-first photos app looks familiar but isn't

Here's the architectural point worth carrying away. The redesigned photos experience looks like the cloud photo apps you know โ€” a river, places, people, stories, sharing. That familiarity is intentional; people shouldn't have to relearn what a photos app is to use a sovereign one. But underneath, every surface answers a different question than its cloud cousin:

  • The river renders your local event stream, not a server-side feed.
  • People and places are computed on your device, not by a provider's vision API mining your library.
  • Sharing grants decryption keys over an encrypted channel, not access on someone's servers โ€” and "forgotten" is a real revocation, not a hidden-but-retained flag.
  • The inspector tells the truth about provenance and access because the system actually knows it, rather than trusting a remote service's account of who can see what.

The redesign's achievement is making that look ordinary. The hardest part of sovereign software is that the sovereignty is supposed to be invisible โ€” the photos app should just feel like a photos app, while quietly never surrendering your library to anyone.

The honest status

Now the part the project's discipline requires us to state plainly. Seventeen redesigned surfaces landed on the seventh of June โ€” that is verifiable in the git log, branch by branch, and it is genuinely a lot of ground covered in a day. But the photos redesign is, as of this writing, still being verified โ€” not celebrated, not closed.

That distinction is the whole honesty discipline of this devlog in one example. "The surfaces landed" is true. "The photos redesign is finished" is not something we can tell you, because it's still being verified, and verification is exactly the phase where mock-faithful surfaces get checked against real data and real flows to see whether they hold up. The redesign shipped. It is being proven. Those are two different sentences and we're only entitled to the first one.

What landed this week is a coherent, redesigned photos experience across seventeen surfaces, faithful to its design mock, on a foundation that stores your photographic memory as a river you own rather than a library you rent. What comes next is the verification that turns "the surfaces landed" into "the redesign shipped." We'll write that sentence when it's earned.

Related: Your Files, Without a Cloud Looking Over Them ยท Forgetting Is a Feature.


Written by AI agents from real project logs; owned and edited by Mujo.

โ† more in Product   home โœฆ   all โ†’