Skip to main content

How It Works

Overview​

Lasco is a mobile app for encrypted photo backup and sync. It connects directly to storage you control, such as S3-compatible storage, a NAS, or an external drive.

There is no photo server to deploy, database to manage, or Docker stack to maintain. Lasco encrypts your library on your device before syncing it.

If you are comparing approaches, see Lasco vs. Immich and Lasco vs. Ente.

Lasco app
LogicEncrypt/decrypt, apply operations, build local state
⇄
upload / download
File Storage
StorageStores encrypted photos and videos.

What is stored on the server​

The remote stores encrypted media, compacted CRDT operations, and the metadata needed to open the library. Each remote also has an identity marker, so Lasco can detect a stale or mismatched storage location before syncing. The library data is organized into three areas:

Media Blobs
Your photos and videos, encrypted at rest
media/YYYY/MM/{UUID}.dataEncrypted original media
media/YYYY/MM/{UUID}.thumbEncrypted thumbnail
Operation files
Encrypted CRDT operations that record every change, such as photo names and album membership
operations/{UUID}.op{tier}_{count}Immutable compacted operations
Library metadata
Library identity, format version, and encrypted master keys
library/library_saltArgon2id salt
library/mk_{username}_{UUID}.encMaster key encrypted with the user's password-derived key

Concrete example​

When you import "IMG_4823.jpg" and name it "Beach Sunset" in the "Summer 2026" album, the server receives:

📁media/
📁2026/
📁04/
🔒3f2a1b4c-9d8e-4f7a-b2c3-1d5e6f7a8b9c.dataencrypted media
🔒3f2a1b4c-9d8e-4f7a-b2c3-1d5e6f7a8b9c.thumbencrypted thumbnail
📁library/
🔒library_saltArgon2id salt
🔒mk_pierre_8d2a1b4c-9d8e-4f7a-b2c3-1d5e6f7a8b9c.encencrypted master key
📁operations/
🔒9a11c2d3-4e5f-6a7b-8c9d-0e1f2a3b4c5d.op1_3MediaCreation, rename, and album membership

Remote concept​

Lasco interacts with remote servers through two operations:

  • fetch Downloads operations and media blobs from a remote server to your device.
  • push Uploads new operations and media blobs from your device to a remote server.

This allows you to push to multiple file servers to achieve replication, or back up to a hard drive by simply plugging in your USB drive and pushing to it.

Because changes are CRDT operations, devices converge on the same library state once they have observed the same data.