This document proposes a privacy-preserving system for controlling the sharing of photos on social networks. It includes modules for photo privacy, social networks, friend lists, and collaborative learning. The system asks users to establish private photo sets that are used to build personal facial recognition engines during distributed collaborative training, revealing only discriminating rules. Algorithms 1 and 2 compute classifiers between users while protecting privacy. Sequence, class, data flow, and flow charts illustrate the design and workflow. The goal is to allow facial recognition without revealing full private photo sets or detailed social connections.