3 Consumer photo and video storage is one of the largest storage workloads on the internet. Social apps, messaging services, photo backup apps, dating apps, marketplaces and telco personal clouds collectively store hundreds of billions of images and videos, with millions more arriving every hour. Each upload must be stored durably, processed into multiple sizes and formats, served quickly to users around the world and kept for years at a cost low enough to support free tiers. The architectural patterns behind these services are well established, and they apply to any app that stores user media at scale. This article explains how consumer apps store billions of photos and videos: the upload path, object storage design, metadata, derived variants, deduplication, tiering, delivery, privacy and cost control. For the broader file storage context, see our hub on SaaS file storage. The upload path A typical upload flow: Client upload: the app uploads the photo or video directly to object storage using a presigned URL or through an upload service, often in chunks with resumable uploads for large videos and unreliable mobile networks. Validation: the service checks file type, size and integrity and scans for malicious content. Metadata record: the service creates a database record with the owner, timestamps, device information and storage location. Processing: asynchronous workers generate thumbnails, resized versions, transcoded video renditions and features for search or moderation. Availability: the item appears in the user’s library and feeds once processing completes. Direct-to-storage uploads keep large media flows off application servers, which reduces cost and improves reliability. Object storage as the foundation Consumer media is a natural fit for object storage: Immutable content: photos and videos are written once and rarely modified. Massive object counts: billions of originals plus many more derived variants. HTTP-native delivery to CDNs and clients. Scale-out growth by adding nodes. Efficient protection with erasure coding across nodes and sites. See erasure coding vs replication. Object keys are usually generated identifiers rather than user-provided names, which spreads load evenly and avoids exposing personal information in paths. Metadata at scale The metadata layer stores who owns each item, albums, sharing permissions, captions, locations, faces or tags and pointers to each stored variant. At billions of items, metadata stores are sharded across many database nodes, typically by user. Metadata access patterns, such as loading a user’s timeline, drive database design more than storage capacity does. Derived variants Each upload produces several variants: Thumbnails at multiple sizes for grids and previews. Display versions sized for phones, tablets and screens, often in efficient formats. Video renditions at multiple bitrates for adaptive streaming. Posters and animated previews for video. Variants can multiply object counts several times over. Some services generate variants on demand and cache them, rather than storing every size permanently, trading compute for storage. The right balance depends on access patterns: popular sizes are pre-generated; rare ones are created when requested. Deduplication Identical files are common: the same image forwarded in many chats, the same meme posted by many users or repeated backups from the same device. Content hashing lets services store one copy and reference it many times. Deduplication must respect privacy and deletion: when one user deletes their copy, the content must remain for others, and when the last reference is removed, it must actually be deleted. Some services limit deduplication to within a user’s own library for privacy reasons. Tiering by age and access Access to consumer media drops sharply with age. A photo is viewed most in its first days, occasionally afterward and rarely years later. Services use tiers: Hot tier for recent uploads and popular content, often fronted by CDNs. Warm tier for older content still accessed occasionally. Cold tier for rarely accessed originals, on the densest, lowest-cost storage. Moving content between tiers based on age or access frequency lowers cost while keeping everything retrievable in reasonable time. See hot storage vs cold storage. Delivery CDNs cache popular images and video segments close to users. Origin storage serves cache misses and long-tail content. For video, adaptive streaming formats deliver the right bitrate for each network. Origin storage must handle high request rates for small images as well as throughput for video. See video origin server storage. Privacy and regulation Consumer media is deeply personal. Requirements include: Data protection law such as GDPR in Europe, with rights of access and deletion. Data location commitments in some markets, where users or regulators expect domestic storage. Deletion that works: when users delete media or accounts, originals, variants, cached copies and backups must be removed within defined periods. The scality.com post on data deletion verification covers how to evidence it. Access control and encryption to protect content from unauthorized access, including by staff. Metadata minimization, such as stripping location data from shared images where appropriate. Reliability Users rarely forgive lost photos. Protect against drive, node and site failures with erasure coding and multi-site distribution, monitor durability continuously and protect against software bugs or operator errors that could delete data at scale, for example with delayed deletion or soft-delete windows. Cost control At this scale, small efficiencies matter: Efficient formats for display variants and video renditions. Erasure coding rather than full replicas. Dense, energy-efficient hardware. Tiering cold content to the lowest-cost storage. Deduplication where appropriate. Lifecycle rules to remove orphaned variants and temporary files. Owned infrastructure at large scale, avoiding per-request and egress charges that grow with a read-heavy consumer service. Track cost per stored gigabyte and per active user, and tie them to product decisions such as free storage limits and video quality. Content moderation and safety Consumer platforms that allow sharing must detect and remove illegal and harmful content, and many jurisdictions now impose explicit obligations, such as the EU’s Digital Services Act for online platforms. Moderation pipelines scan uploads with automated classifiers and hash matching against known illegal content, route uncertain cases to human reviewers and act on user reports. Storage design must support quarantining content quickly, preserving evidence where the law requires and removing content everywhere, including CDN caches and variants, once a decision is made. Access to quarantined content must be tightly restricted and logged. A sizing illustration Consider an illustrative app with 20 million monthly active users who each upload an average of 30 photos and two short videos per month. If photos average 3 MB and videos 40 MB, monthly uploads are about 1.8 PB of photos and 1.6 PB of video, roughly 3.4 PB of originals per month before variants. Display variants and video renditions might add another 30 to 50 percent. Over a year, that is more than 50 PB of new content before deduplication and tiering, which is why consumer media platforms obsess over formats, deduplication and cost per gigabyte. Machine learning on media Search, recommendations, automatic albums and moderation all rely on models that analyze images and video. These pipelines read originals or display variants and store derived features. Keeping media and processing in the same data center or region avoids costly data movement and helps with privacy commitments. Growth planning Media storage grows with users, uploads per user and media size, which keeps rising as phone cameras improve and video becomes more common. Forecast these drivers separately. See storage capacity planning. Checklist: consumer photo and video storage Upload directly to object storage with resumable, chunked uploads. Store originals immutably with generated object keys. Shard metadata by user and design for timeline queries. Decide which variants to pre-generate and which to create on demand. Deduplicate where privacy and deletion rules allow. Tier content by age and access. Deliver through CDNs with a capable origin. Implement verifiable deletion across originals, variants and caches. Protect durability across failures and operator errors. Track cost per gigabyte and per active user. Putting it together Consumer apps store billions of photos and videos by combining direct uploads to object storage, sharded metadata, smart variant generation, deduplication, tiering and CDN delivery. Underneath, scale-out object storage provides the durability, capacity and economics that make free tiers viable. The same patterns serve social platforms, messaging apps and telco personal clouds alike, with privacy, deletion and data location obligations built in from the start. Frequently asked questions Where do apps store user photos? Typically in object storage, with metadata in sharded databases and CDNs delivering popular content. Do apps store every image size? Not always. Many pre-generate common sizes and create rarer ones on demand, caching the results. How do apps reduce photo storage costs? With efficient formats, erasure coding, tiering, deduplication, lifecycle cleanup and, at scale, owned infrastructure. What happens when a user deletes a photo? The original, its variants, cached copies and eventually backups should be removed within defined periods. Why is object storage used for media? It handles billions of immutable objects, scales out, serves content over HTTP and protects data efficiently. Further reading See SaaS file storage, SaaS regional data residency, telco personal cloud storage, self-hosted file sync and share storage and video origin server storage.