Ring is throwing away its key to your videos
Ring's next encryption default destroys its copy of your video keys after 24 hours. That closes a door Ring left open for years. It stops at the moment an owner shares a clip.
Ring is changing who can open old recordings from its doorbells and cameras. A new encryption mode starts rolling out in September. Ring says it will become the default worldwide once the rollout finishes.
The name tells you what it does. TAKE stands for Throw Away the Key Encryption.
Every recording gets an encryption key, the digital equivalent of a key to a locked box. A new one takes over every five minutes. Ring keeps a copy inside a hardened section of its cloud so features like Smart Alerts and Video Search can do their work.
Then Ring throws that copy away. The deletion runs continuously rather than on a daily deadline. Each key gets destroyed once it passes 24 hours old, through a one-way process Ring says cannot be reversed, in a database configured with no backups.
Your phones, tablets, and browsers keep their own keys the whole time. Play a week-old clip and your app hands Ring a temporary key so it can prepare the video. Ring's cloud cannot ask for one on its own.
What changes for you
In practice, after about a day nobody at Ring can open your old video unless your app hands over the key. Not a support agent, not an engineer, not a contractor.
That last one matters. In 2023 the Federal Trade Commission alleged Ring had given employees and contractors broad access to customer video without adequate controls. Ring settled, paid $5.8 million, and agreed to a privacy and security program.
TAKE leaves a window open at the front end. Ring's services can still decrypt video during the first 24 hours to run the features on your account. The change is what happens afterward. Once Ring's copy of the key is destroyed, that access stops being a matter of policy and becomes impossible.
I have been skeptical of Ring for years and I still am. But a company that destroys its own keys has given something up. Policies get rewritten in an afternoon. A destroyed key is gone.
Ring can still send police a locked file
Ring's U.S. guidelines say non-content information, meaning things like your name, address, and email, can be produced under a subpoena. Video counts as content, and Ring says content requires a valid search warrant.
Ring updated those guidelines four days ago. They now say Ring only has access to videos that are not protected by TAKE or end-to-end encryption. The word doing the work there is access. Ring told Gizmodo something the guidelines never spell out. It may still turn over the encrypted video file when valid legal process requires it. So the file can still leave Ring. Ring says it cannot open one.
Ring also says it notifies the account owner before handing anything over, unless it is barred from doing so.
The person on the sidewalk
The keys belong to the camera owner. Everyone else in frame is along for the ride.
Ring's own white paper draws that line in a footnote. The architecture covers video stored on Ring's infrastructure. Anything the owner chooses to share falls outside it, and Ring names the examples itself: share links, the video donation tool, and Neighbors. Once a clip gets passed along, the design stops applying to it.
There is no consent prompt for the delivery driver or the neighbor walking a dog. It is the same gap that runs through Flock cameras. Rules about storage and search can limit misuse after the fact. There is still no way to opt out beforehand.
That fight is already in court. A Virginia man who has never owned a Ring sued Amazon in June over Familiar Faces, Ring's opt-in facial recognition feature, saying his face was scanned while he was visiting friends who do. The allegations are unproven.
Ring built a way for you to lock up your own footage. Whether anybody else in the frame wanted to be there is a question the settings page never asks.

What to check when TAKE reaches you
- Wait for the invitation. Ring says it will notify you when your account is eligible to enroll. Your current setting stays exactly where it is until then.
- Decide camera by camera. End-to-end encryption is set per camera now, so you can run TAKE on the doorbell and end-to-end on the back yard. Switching modes only covers new recordings, and old clips stay under whatever was running when the camera recorded them.
- Know what end-to-end costs. It removes Ring's cloud from the group, which takes Video Search, Smart Video Descriptions, cloud Smart Alerts, and Shared Users with it. Live View and playback keep working. Some older cameras encrypt only once the video reaches Ring's cloud, and those support TAKE but cannot do end-to-end at all.
- Write down the passphrase. Enrollment generates a twelve-word recovery phrase and Ring does not keep a copy. Lose every recovery method and your old video is gone permanently.
- Look at camera-based recovery. Under TAKE, Ring stores a recovery key on the camera itself and turns this on by default. Using it requires standing next to the camera. You can switch it off and keep the other recovery methods. Find it under Control Center, then Video Encryption, then Enrolled Cameras.
What Ring has not shown yet
TAKE is built on Messaging Layer Security, an open standard published by the Internet Engineering Task Force as RFC 9420. Anybody can read that spec and go looking for holes in it. That is a real advantage over a scheme only Amazon can see.
Everything layered on top is Ring's own. The white paper describes sealed hardware that holds the keys, a key database with no backups, and a deletion process that runs one direction only. It also mentions two features most of the coverage skipped. You can cryptographically confirm that your devices are the only ones with access, and every change to that list goes into a log nobody can edit without leaving a mark.
The paper contains no independent audit. Every claim in it is Ring describing Ring.
Ring also acknowledges a limitation directly. Think of the enclave as a vault. The keys get made inside it and stay inside it, and Ring says its own staff cannot get in there.
The vault does not do the work, though. When a feature like Smart Alerts needs to look at your video, the key has to come out of the vault and go over to the service doing the looking. That service runs on ordinary Ring infrastructure. Ring says the key sits in memory there, never gets written to a disk, and gets erased the moment the job finishes. That is a promise enforced by code, and it is a step down from the vault.
Moving those services into vaults of their own is work Ring says it is still exploring. Until that happens, the strongest protection covers the keys while they sit still, and something weaker covers the moment they get used.
Until the invitation shows up, your camera is still running whatever you have today. Open Control Center, tap Video Encryption, and go see what that is.
Sources
- Ring: Introducing TAKE encryption (August 26, 2026)
- Ring: Throw Away the Key Encryption and End-to-End Encryption white paper (August 26, 2026)
- Ring: Privacy and law-enforcement guidelines
- Gizmodo: Ring says its new encryption system could make it harder for police to access videos (August 26, 2026)
- TechCrunch: Amazon faces class action lawsuit over Ring facial-recognition feature (June 2, 2026)
- Federal Trade Commission: Ring privacy and security case