Thanks for the ideas. One thing I have wrestled with in the past is how to prevent exposing the third party site email credentials (credentials the page would utilize for accessing Sendgrid, etc.) if the emailing code were hosted in the local and observable JavaScript. With the current server solution, at a minimum the browser and CORS enforcement take care of attempted cross domain access ... which is probably just slightly better than nothing at all.
Let end users provide their own third party site email credentials.
I like that idea. It could be an alternative, an additional option.
You could use something that is not e-mail. From uploading the images to a shared/cloud folder and/or a messenging protocol to notify you.