Local migration assurance

Leave the cloud.
Keep the proof.

Inventory every photo, name every difference, and decide what each phone will do next—before your family cuts over.

Read-only · local · provider-neutral

Warm photo frames pass through three transparent verification layers into a cyan archive vault.
sourceverifyarchive
0photos uploaded by us
SHA-256byte-level evidence
99.5%+accounting target
1 filesigned cutover record

The safe way out

One path through the uncertainty.

The tool observes. You decide. Your source and archive remain untouched.

  1. 01

    Inventory both sides

    Read Takeout sidecars, dates, album hints, rendered edits, media types, byte sizes, and SHA-256 hashes.

    read-only
  2. 02

    Account for differences

    Match exact bytes, surface missing items, and require a plain-language reason for every accepted exception.

    verifiable
  3. 03

    Freeze the cutover plan

    Record uploads, deletions, conflicts, and offline behavior per device. Sign only when the evidence is ready.

    reviewed

Live readiness gate

See what “accounted for” means.

This browser demo calculates only the gate. The CLI performs the real local scan.

Ready100.000% accounted · 0 unresolvedReady to review and sign. Keep the old cloud during the retention window.

Four commands, one record

From folders to a signed manifest.

Install from source today. Factory-built release binaries follow the same interface.

terminal — local
cargo install --git https://github.com/B-Divyesh/sf-photo-exit-manifest
$ photo-exit-manifest init --output policies.json
$ photo-exit-manifest run \
    --source ~/Takeout/Google\ Photos \
    --destination /Volumes/FamilyArchive \
    --policies policies.json \
    --out ./exit-manifest \
    --sign "Alex Morgan"

ready_for_cutover: exit-manifest (100.000% accounted)

Defensive Takeout reader

Adjacent and title-indexed JSON sidecars are recognized. Duplicate album copies collapse by content hash while retaining album labels.

Honest failure modes

No hashes means planning-only. Missing files, absent album labels, edited copies, and unsafe retention policies keep the manifest on hold.

Automation-ready

Every command is non-interactive. Add --json for scripts; exit code 2 means evidence exists but cutover is not ready.

Optional Family Pack

Make the device decisions together.

The free CLI performs unlimited inventories, comparisons, exceptions, JSON exports, and signed manifests. A $29 one-time license unlocks this browser-based multi-device policy builder and reusable policy files.

  • No subscription
  • No photo access
  • License works across your browsers
Buy Family Pack — $29

Sociobot / Dodo is merchant of record. Refunds are handled there and revoke the license.

Restore a purchase

The free CLI remains fully available.

Unlock the Family Pack to build this file in your browser.

Device policy builder

Device 1

Keep the old cloud for now

Proof first. Cutover second.

Start with the free CLI