Six-weekend reversible organization plan
Weekend 1, read-only inventory: record each source's owner, sync behavior, item/file count, bytes, date range, types, metadata and authority. The iPhone is probably a view of iCloud Photos, but verify library identity rather than adding 9,200 to a unique total. Mark shared albums as externally owned contributions. Verify whether Time Machine contains the Photos library and document its latest successful backup; syncing alone is not account-loss protection. No move or delete.
Weekend 2, recovery foundation: encrypt drive B, copy or export the Android originals, Photos originals plus metadata-supported export, Google data, and critical documents while retaining source structure. Because 2 TB appears sufficient from supplied sizes but full totals are not reconciled, check free space first. Create manifest with source path or asset ID, size, modified/capture time and SHA-256 where available. Compare counts/bytes and restore a photo, RAW+JPEG pair, edited item with metadata, PDF, and Android video to a separate test location. Drive A remains a second historical source, not overwritten.
Weekend 3, staged documents: copy to staging, classify into YYYY/Area/Project, apply the filename rule only when date is known, and keep an old-to-new manifest. Tax folders through 2031 and identity scans are retention/private gates. Check links, permissions and sample opens before any source change.
Weekend 4, photo structure: inside a working copy/library, create year/event albums and optional manual person keywords. Preserve favorites, edits, captions, timestamps, private location and RAW+JPEG pairing. Do not require face recognition. Shared albums remain separate with owner and export limitations recorded.
Weekend 5, duplicate review: SHA-256 groups only byte-identical files. Label edited JPEGs, RAW+JPEG, bursts, screenshots, app exports, sidecars and near-duplicates separately. Build a candidate manifest showing every copy, proposed keeper, reason, owner and whether backup/restore passed. Both adults review; child-location and identity paths are redacted from the shared view. No automatic deletion.
Weekend 6, migration close: reconcile source/staging/destination counts, bytes, hash exceptions, metadata samples, albums and permissions. Approved exact duplicates move to recoverable quarantine for at least 60 days; deletion manifest records approval and recovery location. Originals stay until all restore tests and approvals pass.
Target with current resources: primary working libraries/accounts; encrypted drive B as offline backup when disconnected; drive A retained as a separate historical copy where usable. This approximates multiple copies and media, but does not guarantee full 3-2-1 because off-site independence and all source coverage require verification. Monthly: import, classify, review failed sync and quarantine. Annually: inventory totals, update exports, inspect drive health, review sharing/location permissions, and restore samples. Account-recovery credentials are managed outside the content archive and never written into manifests.