← HomeHow to use

How to use
What’s in this guide
Everything below describes what the product does today, step by step. Read it front to back, or jump to the part you need.
- Getting started
- Your account & security
- Your family
- Uploading
- Your library
- Organizing & finding
- Sharing outside the family
- Public rooms & Discover
- Privacy & AI
- Billing & storage
- Deleting, recovering & leaving
- Bringing a big library across
Video walkthroughs are on the way. For now, every step is written out.
Getting started
VestaNabu is a paid, private home for your family’s photos and videos. There are no ads, no feeds, and no data sales — you pay the bill, so nothing else has to be sold. Everything lives inside your family unless you deliberately share it out.
Create your account
- Go to Create account. You’ll be the payer for a new family and can invite the rest of the family later.
- Pick a handle. The page suggests a handful of @handles; choose one or ask for more with Show me more. You can’t type your own, and the one you pick is yours forever.
- Fill in your display name — the name your family actually sees. Unlike the handle, you can change it anytime.
- Choose a password of at least 12 characters. Common passwords are rejected.
- Enter your email and date of birth. Starting a new family requires being 18 or older; joining an existing family by invitation does not. Phone is optional.
- Click Create account. You’re signed in immediately and land on your dashboard.
Verify your email
Until your email is verified you can sign in and browse, but uploading, inviting family members, and sharing rooms are locked. A banner at the top of every page offers Resend verification; the emailed link is good for 24 hours. Once verified, everything unlocks.
Sign in and out
- Sign in at Sign in with your email and password. Several family members can share one email — if yours is shared, you’ll be asked to pick your account from a short-lived list.
- Prefer a passkey? Click Use a passkey instead and sign in with your handle. You’ll need to add a passkey first under Settings → Security.
- Forgot your password? Use the Reset it link on the sign-in page. The emailed reset link works once and expires after an hour; resetting signs you out everywhere.
- To sign out, open the account menu (the round initials button at the top right) and click Sign out.
Your account & security
Profile
Settings → Profile holds your identity. Your display name is editable anytime; your @handle is permanent. Your email is used for sign-in and password reset — changing it means verifying the new address, and an address already anchored to a different family is rejected. Phone is optional contact detail. A checkbox turns notification email and the in-app bell on or off together — it’s the same master switch as All notifications under Settings → Notifications. Account-recovery mail (password reset, email verification) always sends.
Security
- Change password. Enter your current and new password (12 characters minimum). Changing it signs you out everywhere else; the device you’re on stays signed in.
- Passkeys. Click Add a passkey to enroll this device, then use it on the sign-in page. Each device can have its own. In this version you can add passkeys but not yet list, rename, or remove them.
- Bulk import tokens. Long-lived tokens for the import CLI — see Bringing a big library across. Each token is shown exactly once when minted; revocation is all-at-once via Revoke all.
Notifications
Settings → Notifications (reached from the Settings landing page) has one master switch — All notifications — and eight category toggles: Family invitations, Room invitations, Comments, Mentions, Billing milestones, Room claim windows, Private room requests, and Download requests. Password-reset, email-verification, and billing-lifecycle emails always send regardless. Notifications arrive in the bell at the top of the page; the bell refreshes about once a minute while a tab is open, so give a new notification a moment to appear.
Your family
The family is the trust boundary. It has one or more Payers (full authority: billing, invites, member management) and Members. Everything uploaded to the family library is visible to every member. You can belong to several families at once; if you do, the family name in the top bar becomes a switcher.
Roster and roles
- Settings → Family lists every member with an Adult or Minor badge. Payers additionally see role badges (Original Payer / Payer / Member) and the role controls; members see the roster without them.
- Any Payer can Promote an adult member to Payer. Minors can’t be Payers.
- Only the Original Payer can Demote a Payer back to member or Transfer crown to another Payer — handing over the root of trust while staying a Payer themselves.
- Any Payer can Remove a member (not another Payer — demote them first). Removal is immediate, with no undo: the member’s Vault and Drawer move into a 30-day claim window, private rooms only they own are held 30 days for them to claim, and their family-library photos stay with the family.
- At the top of the page you can set your display name in this family (for example “Mom”) — what other members see on your comments. Leave it blank to use your account name. Your @handle never changes.
Inviting family members
- In Invite to family, invite by @username (with search-as-you-type) or by email. Adults and minors are both welcome; external sharing and public rooms remain adults-only, unlocking automatically at 18.
- Pending invitations are listed with their expiry and can be revoked. Families have a member cap, and pending invitations count toward it.
- Invitees with an account see the invite as a dashboard banner and on the invite link itself; new people get a registration page with the invited email pre-filled and locked. Registering through an invitation link verifies that email automatically; accepting in-app with an existing account doesn’t — use the normal verification banner.
Leaving a family
Members can leave from the bottom of Settings → Family. Photos in your Vault and Drawer — and any private rooms only you own — move into a 30-day claim window; photos you uploaded to the family library stay with the family. Afterward, the Pending claims page lets you Claim into my family (a copy into a family you belong to) or Discard. After 30 days unclaimed content is deleted. Payers don’t get a leave option — closing the family account is a separate flow (see Deleting, recovering & leaving).
Minors
- Adult or minor is computed from the date of birth on the account and flips automatically at the 18th birthday.
- Minors get a Vault like everyone else — their private and flagged uploads land there, sealed. Settings → Uploads additionally offers Ask for a private room, with the honest disclosure: “Your parent will be told this room exists, but cannot see what’s inside.” Each request is approved per room, so a minor can hold more than one.
- Any Payer approves, declines, or later revokes a private room from Settings → Family. On revocation the minor has 72 hours to move anything they want to keep into the library; after that the room and its contents are permanently deleted. Revoking only applies while the owner is a minor — at 18 it becomes an ordinary private room, and external sharing unlocks automatically.
- Payers also get a payer-only Family activity log (joins, leaves, private-room decisions, storage milestones) via the Activity link on the Family page.
Uploading
Uploads happen from the Upload page — reached from the dashboard or the All photos view of the Library. Photos are prepared entirely in your browser: location and camera metadata are separated out, and the file is encrypted with your family’s key before a single byte leaves your device. You’ll see this as a sequence of progress labels; there’s nothing to configure.
- Pick a Destination: the Family Library (default, visible to everyone in your family), the Library plus a specific Room, or one of your Private rooms. A line above shows your default for new photos, with a Change default link.
- Drag files onto the drop zone or click Choose files. Accepted formats: JPEG, PNG, WebP, GIF, HEIC, MP4, and MOV.
- Click Upload. Files go up one at a time; each row shows its progress and ends at Done with a small preview.
You can leave the page — the queue keeps running and a pill in the top bar tracks progress. Closing the browser tab, though, loses anything still waiting. Temporary network failures retry on their own; anything that can’t finish moves to a Needs attention list with a plain-language reason and a Retry button.
Upload defaults
Settings → Uploads controls two things: how new photos arrive (All my photos / New photos from now on / Only what I pick manually) and where they land (Vault / Drawer / Family library). Accounts that haven’t chosen yet — typically brand-new ones created on a phone — are asked both questions once, in two quick steps, before anything else. Changing the destination later asks you to confirm; photos already uploaded keep their current schedule.
Flagged photos — sensitive content, and documents like IDs or passports — always go to your Vault for review, regardless of this setting (choosing Vault as your destination sends everything there too). Document detection runs in the phone apps; in the web app the sensitive-content check runs only when it’s enabled for the deployment. The upload queue doesn’t announce a flag — a flagged item simply lands in your Vault and shows up in the amber “N to review” pill on the Drawer, Vault, and Settings → Uploads pages.
Limits you can hit
- Unverified email. Uploading is locked until you verify (see Getting started).
- Out of storage. At your storage allowance, the first blocked upload explains the next step up; after that, the Upload page shows an “Uploads paused” banner and disables the controls. Adding storage in Billing — or freeing space — switches uploading back on.
- Crossing a billing milestone. If you’re a Payer and a batch would push the family past a storage milestone, a preview asks first — your plan only changes when you change it — with Cancel or Continue. Members never see it.
Very large files upload in chunks automatically, and larger videos also get a short animated preview built during upload — both are transparent; the queue just shows extra progress steps.
Your library
Library has two views, toggled at the top right: Eras — a book of your years, each with its chapters — and All photos, a plain grid of everything. The header also links to Drawer, Vault, Map, People, and Care.
Eras and chapters
- Each year is an era holding chapter cards (title, date range, photo count). Chapters build themselves from your uploads — a fresh library shows “Building your chapters…” for a minute, and new uploads can take a little while to be sorted in. They appear in All photos immediately.
- Payers can add a short note to each year and rename chapter titles.
- A chapter page shows its photos, a small map when any carry a location, Share as room (creates a Room from the whole chapter), and bulk Edit metadata for these photos.
Viewing a photo or video
- Click any tile to open the viewer. Arrow keys (or the on-screen arrows) walk through the list you came from.
- Small videos play right in the page — the whole file is downloaded and decrypted first, so give it a moment. Large videos (over 50 MB) show a looping animated preview instead, with the note “Preview only — download to watch the full video.”
- Below the media: capture date, upload date, and location (with a mini map), plus a More info panel with camera, dimensions, size, and type.
- Download saves the original at full quality wherever downloading is allowed — always on your own family’s content. Add to room puts the asset in a Room; Delete moves it to the Trash (you can delete what you uploaded; Payers can delete anything in the family library; a room’s owners can delete what lives only in their room).
Editing metadata
Edit metadata (single asset) and Edit metadata… (from Select mode in All photos, or a whole chapter) edit when a photo was taken and where. Metadata editing is a Payer tool (plus the owners of a Private room, for its own photos) — members won’t see the buttons. Type an address and click Look up to turn it into coordinates, or enter latitude and longitude by hand. In a bulk edit, only the fields you fill in change; everything else stays as-is on each photo. The address you type is sent to the geocoding service to find coordinates — it never sees the photo or who took it.
Drawer and Vault
- The Drawer is a 24-hour waiting room: photos sent there show a countdown and then move to the family library on their own.
- The Vault is yours alone — things you upload privately plus anything flagged as sensitive or a document. Nothing leaves it by itself.
- On both pages each item offers Move to Library and Move to a private room (into one of your own private rooms — flagged items can always move deeper into your private space). Flagged items add Mark reviewed, which clears the flag; a flagged item never moves on its own, and moving one to the Library asks you to confirm first, since everyone in the family will see it.
- Minors can’t move flagged items to the Library or clear the flag — their flagged content stays sealed to the Vault and their private rooms until 18.
- Movement from the Library is one-way — there is no way to send something from the Library back to the Drawer or Vault.
Trash
Deleting moves things to Trash, where each deletion is held for 30 days and then permanently removed. Restore brings back everything from a deletion in one click — and only the person who deleted it sees the button. Deleted items disappear from everyone’s view immediately; the 30 days are your safety net, not a lingering copy.
Organizing & finding
Rooms
Rooms organize photos for sharing — by event, by trip, by person. The Family Library still holds everything by default. There are two kinds:
- Rooms — every family member can see, add to, and manage them. Anyone in the family can create one.
- Private rooms — visible only to their owners. A Payer creates one (a minor gets theirs by asking — see Minors above), and even the Payer sees only that the room exists and its size (“Private room — metadata only”), never the contents. Owners manage the owner list themselves; added owners must be adults, though a minor owns the private room a Payer approved for them.
Inside a room: Add assets picks from your library, Upload here uploads straight in, Remove from room takes an item out of the room (it stays in the library), and Select enables bulk metadata edits.
Search
Search covers your own and shared content, with tabs for Photos, People, Rooms, Comments, and Members. Inside the Photos tab — and only there — results come from a cascade: exact filename and metadata matches first, then near-spelling matches, then visual-content similarity — a caption tells you which kind of match you’re looking at, and weaker visual matches sit behind a Show more weak matches button. The other tabs are simple searches. You can search naturally (“maria at the beach”); recognized person names and dates are echoed back as chips. Search bars on the Library and inside a room search just that scope. If you belong to several families, pills let you pick which ones to search. Drawer and Vault contents never appear in search results — not even yours; searching starts once something reaches the Library or one of your private rooms. Public rooms from other families are not here — that’s Discover.
People
- People groups detected faces by who they look like, in Named and Unnamed tabs. Click a face to name it; optionally link it to a family member’s @handle and add a birth date (which enables age searches like “maria at 10”).
- Cleanup tools: Merge… combines clusters that are the same person; Separate into new person splits mis-grouped photos out; Not a face suppresses false detections (no undo from the UI). Two on-demand checks suggest likely-same-person merges and likely-different-person splits.
- On a photo, the In this photo strip shows detected faces (family members only — external viewers never see it); you can name a face right there, reassign it, or delete a bad detection. Also in this photo holds manual name tags for people without a detected face.
Care, Map, and arcs
- Care (from the Library header) is a quiet tidy-up inbox: unnamed faces worth naming, and years missing a note. Nothing’s urgent, and nothing changes without your say-so.
- Map plots every photo with location data. Click a pin to open the photo, or a cluster to browse everything at that spot — including a bulk metadata fix for a mislabeled place.
- People on the Library header (distinct from the People directory) draws each named person’s arc across the years — click a year bar to see that person in that year.
Public rooms & Discover
Any room that isn’t a Private room can be made public — visible to any signed-in VestaNabu account, found only through keywords you choose. There is no anonymous viewing: opening a public room without an account lands on the sign-in page.
- A Payer flips Make public in the room’s Sharing section. The confirmation spells out the deal: anyone with an account can view. The People surfaces — face names, birth dates, face groups — are family-only and aren’t shown to public viewers.
- A Public-room keywords panel then takes up to 10 keywords — these are the only thing Discover matches. Photo content is never searched across families. Adding a keyword that looks like a person you’ve named triggers a warning before it’s published.
- Turning public off removes the room from Discover; existing external shares keep their access.
Discover (from the dashboard) searches those owner-chosen keywords — no faces, no content matching, no ranking by popularity. Your own family’s public rooms show up in your results too, so you can check your keywords work. Result cards and public rooms carry a content notice when a room holds flagged material — sensitive images and documents each get their own wording. Public viewers can comment and react like any other viewer, but they can never download — downloads only ever come through a direct share to a specific person.
Privacy & AI
AI on VestaNabu is included in the plan — the switches below are privacy choices, never billing ones. Everything runs against your library only; nothing is compared across users or used for training, ever. And your Vault is a review space, not an archive: its contents are never touched by the cloud AI at all.
The four cloud switches
Settings → AI has four family-wide toggles, each described in plain words with a “Tech details” flip: finding the same person across photos (face clustering), finding photos by what they show (semantic search), sorting photos into rooms (auto-categorization), and spotting near-duplicates for you to look at (library cleanup hints). Payers flip them; members see them read-only with the note “Your family Payer controls these settings.” Off means off — the inference stops running and the data stops being generated; the card shows “Disabled since” with the date. When face clustering is on, some families also get a Face grouping precision slider to make the matcher looser or stricter for future uploads.
What runs on your device
Sensitive-photo detection and face detection (the boxes) run on the device doing the upload; document detection (IDs, passports, tax forms) runs in the phone apps. Your photos aren’t uploaded anywhere to be analyzed. What’s recorded is the result: a flag (a sensitive photo goes to your Vault) or the boxes around faces. There’s no toggle for these because they aren’t cloud features to switch off.
The ledger
At the bottom of the AI page, What VestaNabu’s AI did with your photos lists the last 30 days of AI activity, day by day — how many photos were embedded, clustered, or checked for duplicates, and how many searches ran. Not a promise; a record you can read.
Billing & storage
Billing lives at Settings → Billing. The money surfaces — plan changes, the ledger, invoices, the card on file — are Payer-only; members still see the family’s plan, the Rates tab, and Storage by member, with a note to ask a Payer for the rest. Everything is priced in dollars, and the current numbers always come from the live rate sheet: the Rates tab in Billing, and the public Pricing page. Rate changes carry advance notice, shown as a banner before they take effect.
The three tiers
- Free — storage up to the free ceiling, at no charge. Browsing your own family is always unmetered; a small weekly allowance covers what you view from other families (more below).
- Paid — stepped bands: each step up buys more storage for a bit more per month. The Rates tab lists every band.
- PAYG — past the top band, no cap; storage is billed by daily snapshot.
Change plan on the plan card handles moves. Stepping up raises your upload cap immediately; the remainder of the cycle at the higher band is collected at the next billing. Stepping down is queued to your renewal — you keep the current band until then, and the next bill is simply at the lower rate; no credit or refund for the current cycle. Each step up locks you in for one full cycle before the next step-down is honored. Moving to PAYG removes the cap immediately and is sticky (coming back requires an explicit request and storage below the top band). Cancelling — Cancel paid plan inside Change plan — needs storage at or below the free ceiling and is confirmed by typing “cancel”; you stay on Paid until your renewal date, then move to Free with no further charges and no credit. Everyone stays in the family.
Card, invoices, receipts
Card on file holds your Stripe payment methods — free families don’t need one; a card is captured as part of the first upgrade. Invoices lists every cycle with a printable receipt per invoice (Print on the invoice page) and a Pay now flow for anything unpaid. The daily ledger under Current month shows exactly what accrued, including AI activity marked plan-included — counted, never charged. Library export is free, always.
The free weekly viewing allowance
Free families get a weekly allowance (a rolling 7-day window; the current amount is on the Rates tab) covering what they view of other families’ shared content — your own library is never metered. At the cap: a one-time notice (“Sharing paused for now”), then quieter signals — thumbnail tiles reading “Transfer cap reached” and a small “Transfer paused” pill — until the window rolls over. Pages still load; nothing is charged. No one on VestaNabu pays per view.
Storage signals
- The top bar shows Payers the family’s storage and tier at all times; Storage by member on the Billing page breaks usage down per person for everyone in the family (sizes and counts only — never contents).
- Payers get a one-time banner when the library crosses a storage milestone, and the pre-upload preview described in Uploading. Members see neither.
- At the storage cap, uploads pause until you add space or free some — nothing is lost, nothing is charged.
Deleting, recovering & leaving
Photos and videos
Deleting an asset moves it to the Trash: gone from everyone immediately, recoverable by you for 30 days, then permanently removed (see Your library). Bulk delete from the Library handles up to 1,000 at a time, and one bulk delete restores as one unit.
Rooms
Deleting a room removes the room and its references — the photos stay in the library. When a Payer deletes a Private room they can’t see into, its owners get a 30-day window to claim (copy out) the contents first; unclaimed content is then deleted. Deleting a Private room you own yourself is different: the room and the photos that live only in it are removed permanently, with no 30-day Trash window — the confirmation spells out what goes.
Pending claims
Content routed through a claim window — from leaving a family, or a deleted Private room — waits at Settings → Pending claims for 30 days. Claim into my family starts a copy into your own family (it runs in the background with a progress bar; re-encrypted under your family’s key). The copy counts against your family’s storage allowance — if it wouldn’t fit, add storage or free space first. Discard deletes it permanently, right away, after a confirmation.
Closing the family account
- Reached from the bottom of Settings (“Close family account…”). Only the original Payer can run it; a promoted Payer is asked to transfer the crown back first.
- It is irreversible and immediate: every photo, video, comment, reaction, and face tag is removed; every member loses access; rooms disappear and pending shares are revoked. There is no 30-day window here — account-level deletion has no recovery.
- Any outstanding balance — unpaid invoices, any pending upgrade charges, and (on PAYG) storage accrued so far this cycle — settles on the spot: a small amount is forgiven; anything larger must be paid right there, with a payment form showing the exact amount, and the family closes once the payment goes through. A Paid plan’s current cycle is already paid in advance and its unused remainder isn’t refunded. You confirm by typing the family name exactly, and end up signed out.
Bringing a big library across
For the first import — decades of photos on a computer or NAS — there’s vestanabu-import, a command-line tool that uploads an entire folder tree. It encrypts every file under your family’s key before it leaves your machine, resumes where it left off, and skips anything already uploaded. One binary per platform, nothing else to install.
- Get the binary from Downloads — macOS (Apple Silicon and Intel), Linux (x86_64 and ARM64), and Windows, with notes for first-run on macOS and for running on a NAS.
- Mint a token at Settings → Security under Bulk import tokens: add an optional label, click Generate, and copy the token immediately — it is shown exactly once. Tokens last 90 days; Revoke all retires every token at once (there’s no per-token revoke). Your email must be verified for imports to be accepted.
- On the importing machine, provide the token via the VESTANABU_TOKEN environment variable (or a ~/.vestanabu/import.token file readable only by you), point VESTANABU_API_URL at the service, and run the binary against your photo folder.
Imports land at your upload destination from Settings → Uploads (Vault, Drawer, or Family library), same as any other upload — a per-run --profile flag overrides it — and follow the same storage caps and billing.
Something missing?
If a step here doesn’t match what the product does, that’s a bug in this guide — tell support and it gets fixed.