Stored but Not Safe: How Major Cloud Backup Services Profit From Your Private Files
For millions of Americans, cloud storage has become as routine as locking the front door. You finish a tax return, upload it to Google Drive. You snap a photo of your passport before a trip and let iCloud back it up automatically. You sync a folder of work contracts to OneDrive without a second thought. The assumption underlying all of this is straightforward: the files are encrypted, they are yours, and no one else is reading them.
That assumption deserves serious scrutiny.
The business models powering the world's most popular cloud platforms depend, in varying degrees, on understanding what you store. Encryption—the word that appears most prominently in every provider's marketing material—does not mean what most users believe it means in this context. And the gap between what these services promise and what they actually deliver is wide enough to drive a data broker's truck through.
What 'Encrypted' Actually Means on Google Drive, iCloud, and OneDrive
All three platforms encrypt your data in transit and at rest. This is accurate, and it is also largely irrelevant to the privacy question. The critical distinction is who holds the encryption keys.
In the default configuration for all three services, the provider holds the keys. Google can decrypt your Drive files. Apple can decrypt your iCloud backups—and has done so in response to law enforcement requests on thousands of occasions. Microsoft holds the keys to your OneDrive content. Encryption, in this context, protects your files from external attackers, not from the platform itself.
Google's terms of service grant the company a broad license to scan Drive content for purposes that include safety enforcement, service improvement, and advertising-related machine learning. The company's automated systems analyze document content, image subjects, and metadata to refine the behavioral profiles that underpin its advertising business. When you store a PDF of your medical records in Drive, Google's systems can and do process that file.
Apple occupies a more nuanced position. The company has made genuine privacy commitments and offers end-to-end encryption for certain iCloud data categories—including Health data and iCloud Keychain—under its Advanced Data Protection feature, which requires manual activation. However, standard iCloud backups, iCloud Drive files, and iCloud Photos are not end-to-end encrypted by default. Apple retains the ability to access this content and cooperates with lawful government requests.
Microsoft's OneDrive scans uploaded files for content that violates its terms of service, a process that necessarily involves reading file contents. The company's privacy documentation acknowledges that data may be used to improve Microsoft products and services, and that certain signals from your stored content inform features across the Microsoft 365 ecosystem.
The Metadata Problem No One Talks About
Even setting aside content scanning, metadata retention represents a substantial and underappreciated privacy exposure. Every file you upload carries with it a constellation of contextual information: creation timestamps, modification history, geolocation data embedded in photos, device identifiers, IP addresses logged at upload, and the behavioral patterns revealed by which files you access, when, and from where.
This metadata persists even when file content is deleted. Providers retain access logs, sync histories, and usage patterns for periods that vary by platform and are rarely disclosed with precision. For a determined adversary—whether a data broker purchasing aggregated signals, a litigant serving a subpoena, or a government agency with appropriate legal authority—this metadata can reconstruct a detailed picture of your activities without ever opening a single file.
Third-Party Partnerships and the Downstream Data Trail
All three major providers maintain third-party relationships that can extend the reach of your data beyond the platform itself. Google's advertising partners receive signals derived from user behavior across all Google services, including Drive activity. Microsoft integrates OneDrive data into its broader commercial intelligence infrastructure. Apple's third-party app ecosystem, while more tightly controlled than Google's, still creates vectors through which data can flow to external parties when you grant application permissions.
The practical implication is that your cloud backup does not exist in isolation. It is one node in a larger data graph that these companies maintain about you, and that graph has commercial value.
Auditing What Your Provider Already Knows
Before migrating to an alternative, it is worth understanding the current scope of your exposure. Each major provider offers data access tools that reveal a portion—though not all—of what they retain.
Google: Navigate to myaccount.google.com and access the Data & Privacy section. Download your full data archive via Google Takeout. Review the activity log associated with Drive to see access timestamps and device records. Check your Google Ad Settings to observe the interest categories Google has inferred from your behavior.
Apple: Visit privacy.apple.com to request a copy of your Apple data. Review which iCloud data categories are and are not covered by Advanced Data Protection in your device settings under Apple ID > iCloud > Advanced Data Protection. Note that enabling this feature requires setting up account recovery contacts and may limit some Apple support capabilities.
Microsoft: Use the Microsoft Privacy Dashboard at account.microsoft.com/privacy to review your activity history, browsing data, and the data Microsoft associates with your account. Download your data via the export tool and examine the OneDrive activity logs.
This audit will not reveal the full scope of internal processing—no provider publishes that—but it will give you a concrete sense of what is visible and retained.
Privacy-Respecting Cloud Storage Alternatives
Several providers have built their services around genuine end-to-end encryption, where the provider holds no keys and cannot access your content under any circumstances.
Proton Drive (proton.me/drive) is operated by Proton AG, a Swiss company subject to Swiss privacy law. All file content and metadata are end-to-end encrypted by default. Proton has published independent security audits and maintains a strong track record of resisting government data requests. Storage plans begin at no cost for limited capacity, with paid tiers offering expanded storage at competitive rates.
Tresorit is another Swiss-based provider offering zero-knowledge encryption across all plans. It is particularly well-regarded in professional and enterprise contexts, with features designed for secure collaboration. Pricing is higher than consumer alternatives, but the security architecture is robust.
Cryptomator takes a different approach: rather than replacing your existing cloud provider, it encrypts your files locally before they are uploaded. You can continue using Google Drive or OneDrive as the storage backend while ensuring that the provider sees only encrypted ciphertext. Cryptomator is open source and free for desktop use.
Filen is a newer entrant offering zero-knowledge cloud storage with a generous free tier and end-to-end encryption across all content. It is worth monitoring as the service matures.
Making the Transition Without Losing Your Data
Migrating from a mainstream provider to a privacy-respecting alternative does not require abandoning your existing files immediately. A practical approach involves three phases: audit your current storage to identify what is actually sensitive, migrate those high-priority files to a zero-knowledge provider first, and then evaluate whether lower-sensitivity content warrants migration or can remain in place with adjusted privacy settings.
For iCloud users specifically, enabling Advanced Data Protection before any migration extends meaningful protection to your existing stored content at no cost and with minimal friction.
The broader lesson here is one that applies across the privacy software landscape: convenience and privacy exist in tension, and the most frictionless services are frequently the ones that extract the highest data cost. Cloud backup is no exception. Understanding what your provider actually knows—and choosing accordingly—is a straightforward step toward meaningful control over your digital life.