Why Archibou will never read your photos — A manifesto against the panopticon
By the Archibou Team
"You are blind to photos, there could be paedophile photos in there and you would never see them." We were really asked that question. Our answer is yes. Completely. And it is a choice. Here is why refusing to monitor everyone, all the time, is the only position compatible with privacy, the GDPR, and the rule of law.
Prologue: the awkward question
During a conversation about Archibou, a friend challenged us bluntly:
"You are blind to photos, there could be paedophile photos in there and you would never see them."
She is right. If someone stores illegal content on Archibou, we will not see it. We do not want to see it. We do not want to have the technical means to see it.
This is not naivety. It is not irresponsibility. It is a philosophical, legal and technical position — assumed, documented, and shared by many of those who defend digital freedoms in Europe.
This article is our manifesto: why we refuse the panopticon, even with the best intentions in the world.
I. Yes, we are blind. And it is deliberate.
Archibou is a French cloud, based on Nextcloud, hosted in France, with no automatic analysis of your files, no resale, no AI training on your photos.
In practice, this means:
- no scanning of your images on upload;
- no hash compared against a database of banned content;
- no automatic reading of your documents;
- no proactive moderation of your folders.
Others do it. Google automatically analyses content hosted on Drive and Gmail — it is written in its terms. In January 2021, that analysis led to the closure of the account of a French lawyer who stored on his Drive case files from criminal proceedings containing images of minors. Google reported the account to the US NCMEC, which relayed it to the authorities. In January 2025, the Paris Court of Appeal (case No. 21/10238) ruled the closure was not wrongful. Moral of the story, which we will tell in detail in a forthcoming article: storing sensitive data with a provider that scans means accepting its rules, its jurisdiction, and the absence of remedy1.
We do the opposite. We consider Archibou as an extension of your private computer. You have the right to store whatever you want on your hard drive, your USB stick, your NAS. Nobody requires Dell, Seagate or your USB stick manufacturer to monitor what you put on it. Why would you require it from your cloud?
Being blind, for us, is not a bug. It is the architecture.
II. The panopticon means monitoring everyone to catch a few
In 1791, philosopher Jeremy Bentham imagined the panopticon: a circular prison where a single invisible guard can watch every inmate at any time. Inmates never know whether they are being watched, so they behave as if they always were. Michel Foucault reused the image in 1975 in Discipline and Punish: the most effective power is the one that no longer even needs to be exercised, because everyone censors themselves.
Systematically scanning every cloud and every messenger is the panopticon applied to 450 million Europeans.
The most emblematic European project is Chat Control (CSA Regulation). In its harshest version, it would impose automated detection of child sexual abuse material even inside encrypted messengers, via client-side scanning before encryption2. La Quadrature du Net, EDRi and the Stop Scanning Me coalition firmly oppose it3. In November 2023, the European Parliament voted to exclude mass scanning of encrypted communications4. The European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB) ruled in 2024 that generalised scanning is disproportionate5.
And they are not alone: on 13 February 2024, in Podchasov v. Russia, the European Court of Human Rights ruled that weakening encryption to monitor everyone violates Article 8 of the Convention (right to privacy)6. The UN High Commissioner for Human Rights warned in 2022 against generalised client-side scanning7. More than 300 researchers, including from the Max Planck Institute, warned about the ineffectiveness and risks of such systems8.
The international principle has existed since 2013: the 13 Necessary and Proportionate Principles, signed by more than 400 organisations, require any surveillance to be lawful, necessary, proportionate, authorised by a judge, and not mass surveillance9.
In other words: refusing the panopticon is not a whim of a small French host. It is European and international law.
III. The trap: two biases that make debate impossible
Why, then, is the debate so difficult? Because child protection appeals to two powerful biases:
1. Emotional bias. Children are being harmed. The emotion is legitimate, immense, and it short-circuits reason. Who would dare say "I refuse to scan" in front of a victim? Nobody wants to look like an accomplice.
2. The shortcut. It must be removed as early as possible, therefore everything must be monitored all the time. The shortcut sounds logical: the earlier we scan, the more we protect. Except that "as early as possible" means "before any suspicion", hence "everyone, all the time, by default".
That is exactly the reversal of the burden of proof: you are no longer presumed innocent until proven guilty. You are permanently scanned in case you might be guilty. It means treating everyone as a suspect by default, continuously and without end.
We advocate the opposite: no mass surveillance, and resolute action when something is proven.
IV. Monitoring everyone does not protect children
This is the hardest argument to hear, but it is documented.
First, it does not work well. Hash systems (PhotoDNA and the like) produce false positives. In January 2022, Google Drive blocked text files containing just "1" for "copyright violation", with no possible remedy10. Apply that error rate to criminal accusations: account blocked, report to the US authorities, life ruined — because of a bug.
Second, it can be circumvented. Serious criminals encrypt their own files, switch platforms, change one pixel to change the hash. Those left caught in the net are ordinary users, mistakes, misunderstood professional files — like that lawyer.
Finally, it is a security flaw. Imposing a scanning backdoor in every phone, every cloud, every messenger means building a surveillance infrastructure that any state, any attacker, could hijack. The EFF has repeated it for years: there is no such thing as a "backdoor just for the good guys"11.
Protect children, yes. But with targeted means: investigation, infiltration, international police cooperation, reporting by victims, judicial action. Not with an invisible guard in every pocket.
V. Our position: obey the judge, not suspicion
Let us be clear: we respect the law. Fully.
If a judge, as part of an investigation, asks us to delete data or hand over information as part of a legal procedure, we will comply.
But under three non-negotiable principles, mirroring exactly what the 13 Necessary and Proportionate Principles, La Quadrature du Net and EDRi require:
1. Architectural integrity: we will not build a backdoor.
We will not add mass scanning "just for this case". If the architecture does not allow us to see, we will say what we can do — suspend an account upon a court decision, provide connection logs we lawfully hold — and what we cannot do. This is the N&P principle of integrity of communications and systems: you do not weaken everyone's infrastructure for one particular case. It is also the core of La Quadrature's and EDRi's refusal of client-side scanning.
2. Judicial authority only: the judge decides, never the algorithm.
That is, upon a decision by a French judge, in a court, as part of an adversarial procedure with defence rights. Not on a mere automated alert, not on an injunction from a US platform, not on an opaque denunciation. These are the N&P principles of legality, competent judicial authority and due process: any interference must be provided for by law, pursue a legitimate aim and be ordered by an independent judge.
3. Strict proportionality: targeted, never massive.
Justice investigates suspects. It does not wiretap 60 million people permanently "just in case". These are the N&P principles of necessity, adequacy and proportionality: the measure must be strictly necessary, the least intrusive possible, and proportionate to the aim pursued. Mass surveillance fails this test by definition — that is exactly what the EDPS and the EDPB ruled in 2024 on the CSA Regulation, and the ECtHR in Podchasov v. Russia.
That is also what the GDPR requires (minimisation, purpose limitation, proportionality): targeted, authorised, reviewable surveillance — never massive and blind.
VI. What this changes for you, in practice
Choosing a blind cloud is not choosing a complicit cloud. It is choosing a cloud that treats you as a citizen, not as a suspect.
- Your family photos are not analysed to train an AI, nor compared against US police databases.
- Your professional documents (lawyers, doctors, journalists, associations) do not go through an analysis engine subject to the CLOUD Act.
- Your account cannot be closed by a robot that thought it saw a banned hash in your "1.txt" file.
- If justice needs you, it goes through a French judge, a French procedure, with your defence rights. As with a house search.
It is the same logic we defend on sovereignty: data hosted in France, auditable open-source software (Nextcloud), a host that does not read, does not resell, and that you can leave at any time with your data.
We do not claim to solve child sexual abuse or terrorism. We claim not to sacrifice the privacy of 99.99% of innocent people for a promise of security that, technically and legally, does not hold.
Epilogue: the choice ahead
Bentham dreamed of a perfect prison. Digital technology gives us the means to build it at continental scale — with glasses that film what you look at, messengers that re-read themselves before encrypting, clouds that report before storing.
Or we can decide that some places stay private. That your hard drive, your USB stick — and therefore your cloud — are not a public square under video surveillance.
We have chosen. Archibou will be blind. And that is why it will see you like no one else: as a customer to protect, not as a suspect to monitor.
Sources
Article published by Archibou. October 2026.
May be freely shared and reproduced under CC-BY-4.0 licence, with attribution.
-
Paris Court of Appeal, 24/01/2025, case No. 21/10238; CNB 19/02/2025. A case we will cover in a dedicated forthcoming article. ↩
-
Proposed CSA Regulation / Chat Control, status 2025-2026. EDRi Stop Scanning Me dossier. ↩
-
La Quadrature du Net, EDRi, Stop Scanning Me coalition; stopchatcontrol.fr; CHATONS 08-09/2025; Framablog. ↩
-
European Parliament, mandate adopted November 2023: exclusion of mass scanning of encrypted communications. ↩
-
EDPS / EDPB, joint opinion 2024 on the CSA Regulation: generalised scanning disproportionate. ↩
-
ECtHR, Podchasov v. Russia, 13/02/2024: weakening encryption = violation of Art. 8. ↩
-
UN OHCHR, 2022: warning against generalised client-side scanning; 2014 reports and Special Rapporteurs. ↩
-
Open letter, 300+ researchers, Max Planck Institute: risks and ineffectiveness of mass scanning. ↩
-
Necessary and Proportionate Principles, 2013, 400+ organisations. ↩
-
BleepingComputer 25/01/2022 + 18/02/2022; TorrentFreak 25/01/2022; The Register 25/01/2022; Presse-Citron 27/01/2022. ↩
-
EFF, dossiers against client-side scanning and backdoors. ↩