
Two things have to keep happening
A cloud photo library is not a shoebox in a loft. A shoebox requires nothing of anybody. It sits in the dark for forty years, survives three house moves and a change of ownership, and is still perfectly readable when somebody finally opens it.
A cloud library survives only as long as two things keep happening. Somebody has to keep paying, and somebody has to be able to log in. Stop either one and the library does not sit quietly waiting for you. It begins winding down.
That is the shift almost nobody has fully absorbed. We moved the entire family archive from a medium that survives neglect to a medium that is destroyed by it, and we did it because the new medium was more convenient in every way that is visible day to day. The cost only becomes visible at exactly the moment nobody is in a position to deal with it.
What actually happens when the payments stop
The sequence is fairly consistent across providers, even though the details differ and change.
It begins with warning emails, sent to the address of the person who is no longer reading them. This is worth pausing on: the entire escalation process is aimed at somebody who cannot respond, and it will run its full course without a single human ever noticing that something has gone wrong.
After some months of non-payment, accounts are typically frozen or downgraded to a free tier. Because the library is far larger than the free allowance, the account enters a state of being over quota. Uploads stop. Then, after a further period, providers reserve the right to begin deleting content to bring the account back within its limit.
The exact timelines vary considerably between services, and providers revise these policies regularly, so check your own provider rather than trusting a number you read in an article. But the shape is consistent everywhere: unpaid storage does not last, and the process is automated, patient, and entirely indifferent to what the files are.
The single-login problem
Even when the bill is somehow still being paid, there is a second and more common failure.
Twenty years of family photographs routinely sit behind one login that exactly one person ever used. That login is protected by measures specifically designed to stop anybody else getting in, and those measures work. A two-factor code sent to a phone number that gets cancelled two weeks after the funeral. A fingerprint or face that no longer exists. A recovery email address on another account nobody can reach either.
This is the part families discover far too late, usually while grieving and on hold with a support line that is not legally permitted to help them. Account recovery processes are built to keep strangers out, and they are genuinely good at it. What they cannot do is tell the difference between an intruder and a daughter. From the system's point of view those two people look identical: somebody who is not the account holder, asking for access to the account holder's data.
Providers are not being unreasonable here. A recovery process loose enough to let a grieving family in would be loose enough to let anybody in. But it does mean that hoping to sort it out afterwards is not a plan. In many cases there is no afterwards.
“Photographs used to survive by accident. Now they only survive on purpose.”
Keep one copy that does not depend on anything
The single most effective thing you can do is keep one copy that has no billing cycle and no login.
An external drive in a drawer is deeply unfashionable and remarkably effective. It does not care whether you are alive. It does not send warning emails. Anybody who finds it can plug it in. Copy the photographs that genuinely matter onto it once a year, and it will comfortably outlive most cloud accounts.
Drives do fail, so if you want to be thorough, keep two and store one somewhere else, at a relative's house or a desk at work. This is the old advice about keeping copies in more than one place, and it survives because it is correct.
Use ordinary folders and ordinary file names. Avoid anything that requires a specific application to open, and avoid proprietary library formats that expect to be read by the software that created them. A folder of JPEGs will still be readable in thirty years. A library file for a photo application that no longer exists is a coin flip.
Write down the map
You do not necessarily need to hand anybody your passwords. What helps enormously is the map.
Which service holds what. Which email address each account is tied to. Whether there is already a shared album that somebody else can reach with their own login. Where the external drive is kept. Whether the phone in the drawer still has the photographs on it, and what its passcode is.
A family that knows where to look can usually solve the rest, or at least knows what to ask for. A family with no map is searching blind, and tends to give up not because the photographs are unrecoverable but because they have no idea where to start and are dealing with a great deal else.
This is also the cheapest step by a wide margin. It costs one page of writing and no money at all, and it can be updated in five minutes whenever something changes.
Use the legacy tools your provider already offers
Several of the large platforms now let you nominate somebody in advance who can request access to your account after your death, or specify what should happen to the account if it goes unused for a long period.
These features are genuinely useful, take a few minutes to set up, and are dramatically easier than any recovery process attempted afterwards, because they are consent recorded while you were still able to give it. They are also, for the same reason, the one route that support staff can actually act on.
The names and specifics differ by provider and change over time, so it is worth going through the settings of whichever services actually hold your photographs rather than relying on a general description. The important thing is to check whether the option exists at all, because most people have never looked.
One caveat: these tools are per-provider. Setting one up covers that account and nothing else. If your photographs are spread across a phone, a laptop, one cloud service and a couple of social platforms, you have several separate arrangements to make, which is exactly why the written map above matters as much as the tools themselves.
Choose the few that matter
Forty thousand photographs is not an inheritance. It is a task nobody will ever complete, and in practice an unreviewed archive of that size gets looked at once, briefly, and then never again.
The photographs that actually get returned to are almost always a small, chosen set. So choose it. Pick a few dozen. It takes an afternoon, and it is the part of this whole exercise that produces something people will genuinely treasure.
Then do the thing that almost nobody does: say who is in them and roughly when. An unlabelled photograph of a person nobody recognises becomes worthless within a single generation, and this is how most family archives actually disappear. Not deleted. Not lost to a failed drive or an unpaid invoice. Simply unexplained, until the last person who could have identified anybody is gone too.
A small, named, described collection stored somewhere that needs no monthly payment will outlast the entire library. It is less impressive as a number and vastly more valuable as an object. That is the version worth building, and it is worth building before it becomes somebody else's job.
Not ready to start a vault yet?
Download our free Digital Legacy Checklist PDF instead. A short, practical starting point for organizing what matters. No account required.


