The project itself is cool if you have access to a LLM API endpoint with good privacy (perhaps your own GPU server).
I wouldn't give a LLM run by a US corporation access to my private photographs.
I'd be more worried about the bank statements than the photos.
Would you give it to an LLM run by Chinese, Russian, or European corporation?
I guess PPQ.AI or OpenRouter.AI be of use to you here? Or maybe Apfel (Apple on-device AI) is powerful enough to do this?
He put many of the photographs right there in his blog post - he obviously does not see them as secrets