SEALED

Open framework · 22 review criteria · v1.0

Shared Photo Consent Checklist

A shared photo ritual has at least three distinct decisions: joining the activity, appearing in a photograph and keeping or sharing the result. This checklist makes those decisions visible before capture, during a delayed reveal and after the event.

Author Victor LaybatsPublished 2026-08-09Version 1.0.0Publisher IVRYN

What this release is

Victor Laybats authored the checklist from Sealed’s documented one-phone workflow, safety boundaries and public data-handling disclosures. The criteria are product-independent questions with a concrete evidence request. The release does not certify Sealed or any other photo application.

This is a practical review framework, not legal advice, a security audit or proof of consent in a particular event. Consent depends on context and can be withdrawn. Laws, age rules, venue policies, operating-system backups and third-party sharing can change the correct process.

Before the event

SPC-01

The host states the purpose of the photo activity.

People can make a better choice when the intended ritual and audience are explicit.

Evidence to record: Record the invitation or opening explanation.

SPC-02

Participation is optional and refusal has no penalty.

Group pressure can undermine a nominal choice.

Evidence to record: Document the non-participation path and host wording.

SPC-03

The group knows which device will capture and store photos.

A shared phone concentrates custody and access in one place.

Evidence to record: Identify the device owner and who can unlock it.

SPC-04

The reveal time and audience are stated in advance.

Delayed capture should not hide when or with whom images will be viewed.

Evidence to record: Record the timer and planned audience.

SPC-05

Rules for minors and guardians are explicit.

Age and safeguarding requirements need a separate decision, not an assumption.

Evidence to record: Record the age rule and guardian process.

Capture

SPC-06

The device gives a clear indication when a photo is taken.

A blind preview should not become covert capture.

Evidence to record: Observe shutter feedback, screen state and sound behavior.

SPC-07

A person can decline a specific photo after joining the activity.

Joining once should not remove control over later moments.

Evidence to record: Demonstrate how a participant signals no capture.

SPC-08

Sensitive spaces and situations are excluded.

Bathrooms, changing areas, distress and incapacity require firm boundaries.

Evidence to record: Inspect host rules and in-product safety guidance.

SPC-09

The product does not imply that hidden preview prevents misuse.

A concealed preview cannot stop another camera, coercion or later screenshots.

Evidence to record: Review claims about privacy and secrecy.

Reveal

SPC-10

The group renews consent before the shared reveal.

Circumstances may change between capture and viewing.

Evidence to record: Record the prompt or host check immediately before reveal.

SPC-11

The reveal can be paused or stopped.

A participant needs an immediate control if an image causes concern.

Evidence to record: Demonstrate pause, exit and device-lock behavior.

SPC-12

An unwanted image has a deletion path.

Delayed surprise should not override removal after viewing.

Evidence to record: Test deletion before any save or export.

SPC-13

Screenshot and screen-recording limits are disclosed.

Software may not be able to detect or prevent secondary capture.

Evidence to record: Check the notice and test operating-system capture.

Export

SPC-14

Saving a photo is a separate action from revealing it.

Viewing within an app should not silently create another library copy.

Evidence to record: Compare app storage before and after reveal and save.

SPC-15

Save and share actions state their destination.

Copies can move beyond the original group and retention rules.

Evidence to record: Record the permission prompt, destination and share sheet.

SPC-16

Participants agree before public posting or redistribution.

Consent to capture is not automatically consent to publication.

Evidence to record: Document the approval process for each external audience.

Storage

SPC-17

Local, cloud and backup storage are distinguished.

A claim of local storage can coexist with device-level backup or export.

Evidence to record: Map app storage, system backup and any service upload.

SPC-18

Retention and capsule deletion are explained.

Users need to know whether opening, saving or uninstalling changes the original.

Evidence to record: Test opening, manual deletion and uninstall behavior.

SPC-19

Permissions are limited to the selected function.

Camera, microphone and photo-library access have different consequences.

Evidence to record: Record each permission, timing and fallback when denied.

Security

SPC-20

The device lock and account boundary are part of the threat model.

Local content remains exposed if the shared device itself is accessible.

Evidence to record: Document screen-lock, app-lock and guest-access behavior.

Safety

SPC-21

There is a visible reporting and urgent-removal route.

People need a path for harmful, unlawful or child-safety content.

Evidence to record: Verify the public contact and response instructions.

Evidence

SPC-22

Privacy and enjoyment claims are bounded and testable.

A product feature does not prove safety, consent quality or a better social outcome.

Evidence to record: Classify each claim and record the evidence and limitations.

Provenance and source boundary

This artifact is authored by the product publisher. The links below establish the first-party product scope that informed it. They are not independent validation.

How to cite

Laybats, Victor. (2026). Shared Photo Consent Checklist v1.0. IVRYN. https://sealedreveal.com/research/shared-photo-consent-checklist/

The machine-readable citation file is available as CITATION.cff. The compilation is licensed under CC BY 4.0; attribution is required. Product names and trademarks are not licensed.

JSON SHA-256: 06100590dc78b9462d6ae8046fd0414dbf2f8d6ff1f67a363a3a36f3fb5e1f0d
CSV SHA-256: 06ef0b6b03c017ba7f470c6f1fa60f758f348cb1286ffee07655adeb9c3bd698