Cloud storage: who can actually read your files?
Drive, iCloud, Dropbox — what 'encrypted' means, when the company can see your photos, zero-knowledge options, and a sane backup habit.
Upload a photo to the cloud and it feels like it vanished into a vault with your name on the door. The honest picture is less romantic: your files sit on someone else's computers, in buildings you will never visit, under contracts you scrolled past. Cloud storage is useful. It is not the same as a disk in your desk unless the encryption story says so.
Google Drive, iCloud, Dropbox, OneDrive — different brands, same category of questions: who can read this, what happens in a breach, and what "encrypted" is doing in the brochure.
Who can read your files?
For most consumer clouds, the company can access plaintext if required — by their own systems for scanning, by employees in rare support cases, or by legal process. They encrypt data on disk so a stolen hard drive is not an open book, and they encrypt traffic in transit. That protects against some attackers. It does not mean the provider is cryptographically unable to open your docs.
End-to-end encrypted products (or zero-knowledge designs) aim higher: only your keys decrypt the content. Features get harder — server-side search, easy sharing previews, some integrations. Marketing loves the phrase "encrypted." The question to ask is encrypted from whom.
What about photos and backups?
Phone backups often include messages, photos, and app data. Default settings favor recovery convenience over maximum privacy. Advanced protection modes exist on major platforms; they require setup and discipline with recovery keys. Lose the key, lose the backup. That tradeoff is the point.
Shared links are another leak path. A "anyone with the link" document is one forward away from the wrong inbox. Review sharing quarterly like you review app permissions.
Breaches and insider risk
Providers get breached. Credentials get phished. Support tools get abused. Your risk is not only nation-states; it is also the employee account that should not have had broad access. Unique passwords, passkeys, and two-factor on the cloud account matter as much as the storage tech.
If you sync a password manager database or tax PDFs, treat that account like a bank.
A sane way to use the cloud
Assume business and casual files are fine in mainstream clouds with a locked-down account. Put truly sensitive material in an end-to-end vault or encrypt before upload with a tool you control. Keep an offline copy of irreplaceable things — the 3-2-1 backup idea still applies when one of the 2 is "the cloud."
The cloud is someone else's computer. That sentence is a meme because it is true. Use it anyway for what it does well — sync, share, survive a stolen laptop — and stop pretending a logo equals a sealed envelope.