Simple Privacy Fix #7

Store Your Files Without Handing Over the Keys


The Issue

Most cloud storage isn’t private by default. Google Drive, Dropbox, OneDrive — the provider holds the keys to your files, encrypted or not. That means staff, automated scanners, or a legal request can all get access to what you’ve stored, without you ever knowing.


The Privacy Risk

For a folder of vacation photos, that risk barely registers. But travel documents, financial records, or anything you’d rather no one else ever see — that’s a different story. There are two ways to actually fix this, in order of how much they change.


Encrypt Before It Leaves Your Device

The simplest fix: keep using whatever cloud storage you already have, but encrypt files on your device before they’re uploaded. The provider only ever sees scrambled data.

CryptomatorCryptomator
Works With Any Cloud Provider

Open source, client-side AES-256 encryption. Create a vault, point it at a folder on Google Drive, Dropbox, Nextcloud, or any local disk, and everything inside is encrypted before it ever syncs. The desktop apps (Windows, macOS, Linux) are free and open source. Mobile apps (iOS, Android) are free to view your vaults; unlocking full read/write access is a one-time purchase of €29.99, charged separately per platform.

Windows
macOS
Linux
Android
iOS

Visit cryptomator.org


Or Keep It Off The Cloud Entirely

The strongest option: don’t hand your files to a third party at all. A network-attached storage (NAS) device on your home network stores everything locally, syncs across your own devices, and never touches a server you don’t control.

A Home NAS
Full Control, No Subscription

Most consumer NAS brands (Synology and QNAP are common examples) run apps for automatic photo backup, file sync, and even calendar and contact sync via CalDAV/CardDAV — so your data stays on hardware in your own home rather than a data center. Keep it off the internet and segmented from untrusted devices for the best protection. The trade-off: no automatic offsite backup unless you set one up yourself, and sync between devices generally requires them to be on your home network (or connected via VPN).

Windows
macOS
Android
iOS

Also worth knowing:

  • Proton Drive — zero-knowledge encrypted cloud storage, Swiss jurisdiction. Especially worth it if you’re already using Proton Mail, VPN, or other Proton apps, since it folds neatly into that ecosystem.
  • iCloud Advanced Data Protection — free for iPhone/Mac users, end-to-end encrypts most iCloud data once switched on. Worth enabling even though it’s imperfect: mail, contacts, and calendar stay outside the encryption for interoperability reasons.
  • MEGA — zero-knowledge encrypted cloud storage, widely used, not personally tested by us.

From the Blog

Further reading from the Pretty Simple Privacy blog.


Quote

Mastodon
Scroll to Top