Method 1: the built-in Hidden album
Select a photo, tap the three-dot menu, choose Hide. The photo leaves your main library views and moves to the Hidden album under Albums › Utilities. Since iOS 16 that album asks for Face ID by default, and you can hide the album row entirely in Settings › Photos.
What it protects against: someone scrolling your camera roll while you both look at vacation pictures. What it does not protect against: anyone who knows iPhones. The Hidden album is the first place people check, precisely because everyone uses it. And because the photos stay inside your library, they keep syncing to iCloud Photos and shared devices signed into the same account.
Method 2: locked notes
The Notes app can lock individual notes with your device passcode or a separate password, and a locked note can contain photos. The content of locked notes is encrypted, which puts this a real step above the Hidden album.
The problems are workflow and leftovers. Getting a photo into a note means it existed in your camera roll first, and it stays there until you delete it and clear Recently Deleted. Notes is built for text with attachments, not for browsing a photo collection — no grid, no albums, no videos playback experience. It works for a handful of documents; it is painful for a photo library.
Method 3: ordinary vault apps
The App Store is full of photo-locker apps, many disguised as calculators. The honest ones encrypt your files; many simply move them into app storage behind a PIN screen and call it a vault. From the outside the two look identical, which is exactly the problem — the marketing never distinguishes them.
Two questions separate the serious from the decorative: is the content encrypted at rest with keys derived from your secret, and what does the vendor see? An app that shows ads, requires an account, or can "recover your photos if you forget your PIN" has answered both questions, just not in your favor.
Method 4: deniable encrypted vaults
A deniable vault encrypts your files and additionally refuses to reveal how many vaults exist. Different PINs open different vaults; a wrong-looking PIN simply shows nothing. If someone demands you open the app, you can comply — with the PIN of a vault that holds nothing sensitive — and the sensitive vault’s existence cannot be proven from the data.
This is the only method on the list designed for the hardest case: not a snooping friend but a person who can insist. That is Sealby’s design, and the same principle exists in desktop tools like VeraCrypt’s hidden volumes. Whichever tool you choose, verify the deniability claim is structural (uniform storage, no vault count anywhere) rather than a marketing word.
The step every method needs: dealing with originals
Whatever you pick, the photo you hide is a copy or a move — the original’s history matters. Import into a vault, then delete from the camera roll, then clear Recently Deleted. If the photo ever synced, remember the other endpoints: iCloud Photos, a shared iPad, a family member’s Mac with Photos open.
The cleanest pattern is to capture sensitive material inside the vault app directly, so nothing ever touches the camera roll. Sealby supports in-app capture for exactly this reason.