Search Your Own Photos on Your Own Machine โ and It Won't Fake a Match
The live photos view reads the place and moment your camera wrote into each picture, resolves the coordinates to a real place name entirely on your device, draws them on a map, and lets you narrow what you see by typing a place or filtering by time and source โ while every search that would need a model to read your pixels stays plainly silent instead of guessing.
Open the photos view, search your own pictures, and two things are true at once that rarely are together. The search runs entirely on your own machine โ nothing is uploaded, no library shipped off to a company that runs the clever features for you. And when the app can't answer a question yet, it tells you so plainly instead of faking a result. Type a place and the pictures in front of you narrow to it. Ask for only the shots with a location, or only a slice of time, or only the ones you captured versus the ones you brought in, and the view tightens to match. Meanwhile your device has quietly worked out where each picture was taken and can draw them on a map. None of it leaves your machine.
That combination โ real search you can trust, done locally, that would rather admit a gap than paper over it โ is the part worth slowing down for.
A map your own device draws
Most cameras and phones write a location into each photo at the moment you take it. That information is already sitting inside your pictures โ you own it. What the photos view does is read it, gather the pictures that share a stretch of the world, and resolve the raw coordinates into a name you'd actually recognize โ a city, a place โ using a table of the world's places that lives on your machine. Then it plots them on a map you can pan and zoom, the pins tightening into clusters as you pull back and spreading out as you lean in.
None of that consults a photo service in the cloud. There is no step where your library is shipped off so someone else's servers can build the index and hand you back a map. The map is drawn from what your camera already recorded, worked out where the pictures already are โ on your device. This is the same promise behind search that never phones home, now pointed at the messiest, most personal data most people own.
Narrowing what's in front of you
Alongside the map there's a search box and a row of filters, and they do the plain, honest thing: they narrow the pictures you're looking at. Type a place and the view tightens to the pictures that carry it. Ask to see only the ones with a location, or only a source โ the shots you captured versus the ones you brought in โ or only a slice of time, and it narrows to match. When nothing fits, it doesn't shrug and show you a random grid; it says, in words, that nothing matched what you asked for, and hands you a way to clear it.
That the pictures you see are always your real ones is the newest guarantee here, and it wasn't free. For a stretch of its early life the photos view carried stand-in sample data to make the screens easy to demo โ and we took it out. Under a real sign-in there is now exactly one path: your genuine library, or an honest empty space when there's nothing there yet. No seeded fakes dressed up to look like your life. The search you run is over your own pictures, or over nothing โ never over a convincing fake.
flowchart TD A[Your photos stay on your device] --> B[Your machine reads where each photo was taken and when] B --> C[Coordinates resolved to real place names, locally] C --> D[A map, plus search and filters to narrow by place, time, or source] D --> E[Nothing uploaded] F[Reading what is actually inside a picture needs a model you install] -.still building.-> G[Until then the app says so plainly instead of guessing]
The search that isn't here yet โ and says so
There's a richer kind of photo search everyone now expects: type "dogs at the beach" and have the software find the picture from what it depicts, not from where or when you took it. That one is different in kind. It needs a model that actually reads the pixels โ and running that on your own hardware, rather than by shipping your library to someone who runs it for you, is a real piece of engineering we're still building. You can read where that's headed in the deeper write-up on finding a photo by what's in it.
What we will not do is pretend it's already working. So in today's live view, the search understands the things your device can know for free โ where a picture was taken, when, and how it got into your library โ and the controls that would depend on a model reading your pixels, like grouping the people in a photo, are plainly inert rather than quietly faking an answer. A result that looks confident but is wrong is worse than no result, because nothing tells you it happened. So the honest boundary is drawn in the open: this part works now, that part is not here yet, and the app would rather show you nothing than bluff.
That's not an accident of an unfinished screen. It's the same rule that runs through everything here โ any test that passes over a gap is a lie, and a screen that answers over a gap is one too.
The honest ledger
To keep our own rule, here's exactly where the line sits today:
- Live and yours to use: your real photos, never stand-ins; a map that works out where each located picture was taken and names the place, drawn entirely on your device; and a search-and-filter box that narrows what you're viewing by place, time, or source โ all on your own machine, with nothing uploaded.
- Not here yet: searching by what a picture actually shows โ the scene, the objects, the text printed inside it, grouping the people in it. That needs a model you'd install and run on your own hardware, and until it's there those searches stay silent rather than guess.
The reason to build a photos app that never hands over your library is that you can trust it โ and trust isn't something you bolt on at the end. It has to be in every screen that would rather tell you it found nothing than pretend it found something. Open your pictures, search them on your own machine, and know precisely how the answer was reached.
Written by AI agents from real project logs; owned and edited by Mujo.