In 2021, Apple announced plans for on-device CSAM (child sexual abuse material) detection that would scan photos before they uploaded to iCloud, comparing them against a hashed database. After sustained criticism from security researchers, the Electronic Frontier Foundation, and its own employees, Apple paused the rollout — but the underlying tension it exposed hasn't gone away. Governments in the UK, EU, and elsewhere have continued pushing for mandatory scanning obligations, and Apple has separately faced a lawsuit alleging it failed to implement adequate CSAM protections at all, showing the pressure runs in both directions.
What Is and Isn't Being Scanned Today
- iCloud Mail: Apple has scanned iCloud Mail attachments for known CSAM hashes for years, a practice common across major email providers.
- The paused on-device proposal: The 2021 plan would have scanned photos before iCloud upload using on-device hash matching, a technical approach privacy researchers warned could be expanded to scan for other content categories entirely, not just CSAM.
- Communication Safety features: A separate, opt-in feature for child accounts scans for nudity in Messages — different from the paused library-wide scanning proposal, but part of the same broader trend toward on-device content analysis.
- The "slippery slope" concern: Security researchers, including those at Princeton, published research demonstrating that CSAM-style scanning infrastructure could be repurposed by governments to scan for other content — political material, protest documentation, or anything else a government decides to add to the hash list.
The Only Way to Guarantee You're Not in Any Scanning Pipeline
Any scanning system, whether server-side or on-device, requires your content to pass through it at some point — typically at upload to a cloud service. Stash removes that pathway entirely: files stay encrypted on your device and are never uploaded anywhere, meaning they never enter a pipeline that could be scanned, hashed, or matched against any database.
Photos That Never Reach iCloud
Because scanning proposals have historically been tied to the iCloud upload process, keeping photos entirely local and out of iCloud sidesteps that pipeline by design, not as a workaround.
An Architecture With No Scanning Point to Add
Stash has no server component where a scanning feature could be introduced later, by policy change or legal mandate. There's no upload step for a scan to attach to.
Why This Matters Regardless of Your Opinion on CSAM Detection
Whatever you think about the specific goal of CSAM scanning, the infrastructure question is separate: once a device has scanning capability built in, expanding what it scans for is a policy decision, not a technical one. Keeping personal files off any synced system avoids that question altogether.
Download Stash from the App Store
