Is it safe to keep a photo of your ID on your phone?

The risk is rarely the copy itself. It is the camera roll it lives in.

Short answer

Keeping a copy is usually reasonable — you need your passport number on a trip, or a document for a form. Keeping it loose in your camera roll is not, because the gallery syncs to the cloud, shows previews, and is readable by every app you have given photo access. Keep the original in encrypted, on-device storage, and keep a separate redacted copy for anything you actually send.
  • The camera roll is the problem, not the copy. It syncs, previews, restores from backup, and is readable by any app with library access.
  • Encryption at rest is what makes a lost, stolen or resold phone a non-event.
  • Keep two versions: the original locked away, and a redacted, watermarked copy for sending.

You almost certainly have one. A photo of your passport data page, taken before a trip. A scan of your ID card from the last time an agency asked. A picture of your driving licence you took at a car hire desk two years ago and never thought about again.

Keeping a copy is not the mistake. It is genuinely useful — you need your document number for a visa form, a booking reference, an insurance claim. The mistake is almost always where it is kept, and for most people that is the camera roll.

What actually goes wrong in the camera roll

None of the following is a break-in. They are all the photo gallery working exactly as designed, which is precisely why a document scan does not belong in it.

  • It syncs. iCloud Photos and Google Photos are on by default on most phones. The moment the picture lands in the gallery, it also lands in an account on a server — one with its own password, its own recovery flow and its own breach history. You now have two copies to protect instead of one.
  • Every app with photo access can read it. Full-library access is still routinely granted to messaging apps, editors and shopping apps. An app that can read your library can also run text recognition across it, which turns “a photo of a passport” into “a passport number, a date of birth and an MRZ” without anyone looking at anything.
  • It appears where you did not put it. Recents. The share-sheet picker. “Memories” and year-in-review montages. The thumbnail strip that scrolls past when you hand someone your phone to show them a different photo.
  • It comes back. Deleting a photo moves it to “Recently deleted” for around 30 days. And a phone restored from backup restores the whole library — including the scan you deleted two years ago and had stopped thinking about.

The cumulative effect is that a single tap in a camera app creates a file that is hard to fully account for and harder to fully delete. That is the opposite of what you want from your most sensitive document.

What “kept safely” actually means

Three properties, and all three matter:

  1. Encrypted at rest, under a key you hold. Not a key the operating system hands to any app that asks — one that is released only by your PIN, passphrase or biometrics.
  2. Outside the general photo library. So it does not sync, does not preview, does not appear in a picker and is not readable by apps you granted photo access for something else entirely.
  3. Separate from the copy you share. The version you send should never be the version you keep.

Be clear about what this does and does not buy you. Encryption at rest makes a lost, stolen, repaired or resold phone a non-event: whoever ends up with the storage has a file they cannot open. It does not protect an unlocked phone in someone else’s hands, and it does nothing about sending the file to the wrong person. Those are different problems, and the second one is what redaction is for.

Keep two versions, not one

The version you keep and the version you send are doing different jobs, so they should be different files:

  • The original, locked away, for the handful of checks that are legally required to see the complete document — a bank’s anti-money-laundering verification, guest registration at a hotel in much of Europe, a statutory right-to-work check. When redacting your ID won’t work draws that line precisely.
  • A redacted, watermarked copy, for everything else — which is most of what you are actually asked for. Cover the document number, the machine-readable zone, your date of birth and your signature; leave the name and photo if the recipient has to match them. How to redact a passport or ID has the field-by-field detail.

Making the redacted copy in advance is the part people skip, and it is the part that decides how the request goes. Nobody carefully redacts a passport at a check-in desk with a queue behind them; they send the original.

What about a password manager, or an encrypted note?

Any of these beats the camera roll, and if you already keep documents in 1Password, Bitwarden or an encrypted note, you are ahead of most people. Two honest trade-offs, though. First, most of them upload — end-to-end encrypted in the good cases, but still a copy on someone’s server, tied to an account that can be locked, subpoenaed or breached. Second, none of them help with the thing you actually have to do next, which is produce a safe copy to send. You end up exporting the original to the camera roll to edit it, which puts you back where you started.

Doing it in Anonymize my ID

The app was built around this exact shape, and everything below happens on the phone with no server involved:

  • The built-in camera takes the photo inside the app, so the shot never lands in your camera roll in the first place.
  • The encrypted vault keeps what you choose to keep: the redacted copies, and the untouched originals behind them. Files are encrypted with AES-256 under a key derived from your PIN or passphrase mixed with a secret held in the phone’s secure hardware, so a copy of the files on their own cannot be attacked. Face ID, Touch ID and Android’s biometric prompt can unlock it too, and the key is discarded the moment the app is backgrounded.
  • Nothing syncs, nothing uploads, nothing is backed up to us, and you can delete a single item or erase the whole vault at any time.
  • It is off until you turn it on. By default the app still keeps nothing.

The honest caveat is the same one that makes it worth using: there is no recovery. Nothing is uploaded, so there is no copy anywhere for anyone to restore from. If you forget your PIN or passphrase, the files stay unreadable — including to us. Set a passphrase instead of a PIN if you would rather have something you can write down and keep somewhere safe.

The other valid answer: keep nothing

For a lot of people the right call is simply not to hold a copy. Your passport is in a drawer; photograph it when a form actually asks, redact it, send it, delete it. That is the smallest possible footprint, and if you are rarely asked, it costs you nothing.

Keeping a copy is for when you are asked often enough that re-photographing every time is friction you will eventually skip — which is when the unredacted original gets sent. Either answer is fine. Leaving the scan loose in the camera roll, indefinitely, is the one that is not.

Keep a copy of your ID on your phone safely

  1. Decide whether you need the original at all. Most requests are satisfied by a redacted copy. Keep the full document only if some check you actually face requires it — a bank's own verification, a hotel check-in abroad, a statutory right-to-work check.
  2. Capture it without going through the gallery. Use an app with its own camera, so the shot goes straight into the app rather than into your photo library. If you already have the photo in the camera roll, import it and delete the original — including from 'Recently deleted'.
  3. Store it encrypted, on the device. Put the file in storage that encrypts at rest under a key only your PIN, passphrase or biometrics releases, and that does not sync to a cloud account.
  4. Make the redacted copy now, not when you are asked. Cover the document number, the machine-readable zone, your date of birth and your signature, and add a watermark naming the recipient. Keep that copy alongside the original so sending it is one tap.
  5. Turn off photo-library access for apps that do not need it. On iOS and Android, review which apps hold full library access and drop them to 'selected photos' or none. This is the single change that removes the most silent readers.
  6. Re-check it once a year. Passports and ID cards expire, and an old scan is a liability with no upside. Delete the copy when the document is replaced, or when the trip it was for is over.

Frequently asked questions

Is it illegal to keep a photo of my own ID?

No. You are entitled to hold a copy of your own document. Germany is the one place where the rule is written down explicitly — § 20(2) PAuswG confirms the holder may copy their own Personalausweis — and nowhere in the EU does data protection law restrict what you do with your own data. The rules apply to organisations that hold a copy of yours, not to you.

Is iCloud Photos or Google Photos safe enough for a passport scan?

They are well-defended, but they are still an account, on a server, that survives your phone. Apple's Advanced Data Protection makes iCloud Photos end-to-end encrypted if you turn it on; Google Photos is not. Either way the safer answer is not to hand a document scan to a general-purpose photo service in the first place.

Should I keep the original or only a redacted copy?

Both, kept apart. The redacted, watermarked copy is what you send to hosts, landlords, clients and platforms. The original is only for the handful of checks that legally require the complete document, and it should sit in encrypted storage in the meantime.

What happens to a stored copy if I lose my phone?

If it was in your camera roll, it is in the finder's hands the moment the phone is unlocked, and it is also in your cloud account. If it was in encrypted storage locked by a PIN or passphrase, the files are unreadable without that secret — which is also why there is no way to recover them if you forget it.