PixPolorer · 2026
A Windows catalog for photos and video on disk
In progressIndependent engineer
A large personal photo and video library that lives on a computer should not have to move to the cloud. Requiring upload, an account, and a network connection is the wrong model when some files must never leave the machine.
The constraint
It has to work offline. It has to be a real Windows program. It needs a vault for the files that stay private. There are no interface pictures on this page yet. I will not invent one.
Built with
Qt 6C++RustSQLite
How it works
Files stay on disk. The C++ / Qt host owns the window. Rust crates do hashing, catalog work, and vault cryptography over FFI. SQLite holds the catalog.
The calls that shaped it
Each decision with the pressure that forced it and the price it keeps costing.
Qt 6 and a C++ host
The usual shortcut wraps a browser engine in a desktop shell and calls the result a desktop app. That brings a browser's memory profile to a program whose only job is reading files on disk.
The shell is a real desktop application, native on Windows with QML for the interface.
The cost: The interface is authored in QML and bound to C++, so there is no web framework underneath to lean on.
Rust over a C FFI
Hashing and authenticated encryption are the parts most likely to be got subtly wrong, and they are also the parts a C++ host would otherwise maintain itself.
Hashing (BLAKE3), catalog operations, and cryptography (Argon2id, XChaCha20-Poly1305) sit in Rust crates. The host does not reimplement them in C++.
The cost: Two toolchains to build and ship, and every crate boundary is an FFI surface that has to stay stable.
SQLite as the catalog
The library changes while the program is open: files are added, moved, and deleted outside it. A catalog that has to be re-imported drifts from the disk it describes.
The library is local. Smart albums are queries that update as the catalog changes.
The cost: The catalog belongs to one machine, so there is no built-in way to share it across two.
Vault as a product surface
Files that must never leave the machine need a place that is visibly private. A buried setting is easy to trust and hard to verify.
Encryption is a path through the application, with keys derived on the machine.
The cost: Vault membership is a decision per file, and recovery has to work with no server to help.
This is the heaviest desktop work on the site, and it is being built, not dressed up as shipped. The engineering so far is the architecture and the vault design.
If a Windows catalog that never leaves the machine sounds like your situation, write with the size of the library and the OS you run.
Where it stands
In progress. The architecture and security design are complete; interface updates will follow as the beta reaches a public build.
- In progress. The architecture and the vault design are complete; the interface is the remaining work.
- Catalog operations, hashing, and vault cryptography sit in Rust crates behind a C FFI, and the C++ host does not reimplement them.
- Smart albums are queries against the local catalog and update as it changes.
- There is no interface picture on this page, because there is not one yet.
What was handed over
- Build instructions for the host and the Rust crates
- Catalog schema and what a smart album actually is
- Vault recovery notes. Without this the work is incomplete.
- Installer when the application is ready to ship