Not Skyfire's servers. Not Amazon. Not Google. The bytes stay on your drives, in your house, under your control. Here's exactly what that means — and why it matters.
AES-256
Encryption at rest
Keys derived from your passphrase
TLS 1.3
Encryption in transit
Every connection, every time
Zero
Third-party data access
Skyfire never touches your files
What self-hosted actually means
Every photo, video, and document in FamilyCloud is stored on drives that you own and can physically hold. Not in Amazon S3. Not in Google Cloud. Not on Skyfire's servers. When you open a photo, it travels from your drives to your device — and nowhere else.
All media is encrypted with AES-256 before it's written to disk. Connections between your devices and your FamilyCloud server use TLS 1.3. Your encryption keys are derived from the passphrase you set during setup and never leave your hardware — Skyfire has no copy and no way to recover them.
FamilyCloud does not report usage statistics, doesn't track which files you open, and doesn't send any behavioural data anywhere. The app checks for software updates (you can turn this off). That's the only outbound connection FamilyCloud makes.
Clips from your connected cameras are written directly to your local drives and never transmitted to a third-party server. Live view uses WebRTC peer-to-peer — a direct, encrypted stream from your camera to your phone or TV. No relay server in the middle.
Your media library is indexed on your Mac mini, served from your Mac mini, and stored on drives you own and can physically access. If you stop using FamilyCloud tomorrow, your files are still on your drives — exactly where you put them. No 30-day warning. No export process. No cloud account to log into. They're just files.
During setup you choose a passphrase. FamilyCloud derives your encryption keys from that passphrase using a standard key derivation function. The resulting keys are used to encrypt every file before it's written to disk. The keys never leave your hardware — not to Skyfire's servers, not to anyone.
Every connection between your devices and your FamilyCloud server — whether you're on your home network or accessing remotely — is protected with TLS 1.3. The Skyfire punch-through protocol is a transport layer only; your media stream is encrypted end-to-end before it touches that transport.
Live camera views use WebRTC peer-to-peer connections. The stream goes directly from your camera to your screen — phone, TV, or laptop — without passing through any intermediary server. Recorded clips write to your local drives and stay there.
FamilyCloud's privacy guarantees are architectural, not policy-based. There's no server we'd need to stop logging. There's no database of your files to delete. The system is designed so that collecting your data isn't possible, not just against our policy.
Because your personal media never leaves your home network and is never processed by Skyfire's servers, Skyfire never becomes a data processor for your personal data. That means the obligations created by GDPR, CCPA, and most other household privacy frameworks simply don't apply to Skyfire in the context of your media library — because we never touch it.
Your media is yours. Skyfire sells you software. Full stop.
FamilyCloud is in development. Join the list and be first to know when it's ready.
Notify me at launch