You upload a file to Google Drive, iCloud, or OneDrive, and somewhere in the back of your mind you check a box: encrypted, safe, done. That assumption is doing more work than it's earned.
Two questions actually decide how much protection you have, and most people never ask either one: encrypted for whom, and stored under whose laws? Neither question is about where the data center physically sits. Server location is almost irrelevant. What matters is who legally controls it.
"Encrypted" gets used like it's one thing. It's really three different situations, and marketing pages rarely say which one you're getting.
No encryption at all. Rare to admit outright, but some free or basic tiers genuinely offer nothing beyond standard account security.
Encrypted, but the provider holds the key. This is the default for most mainstream consumer storage. Your files are protected from an outside attacker, but the company itself can technically still read them — for a support request, a legal order, an internal investigation, or a breach of their own systems.
Zero-knowledge encryption. Only you hold the key. The provider stores data it genuinely cannot read, no matter who asks.
The question that actually matters isn't "is it encrypted?" It's "who holds the key?" Everything else follows from that one answer.
This isn't a technical limitation. Zero-knowledge encryption is well understood and not particularly hard to build — smaller providers already do it. The biggest platforms default to provider-held keys anyway, and the incentives explain why.
Keeping your files tied to their ecosystem — their photo tools, their document editor, their search — makes switching providers a real hassle, not just a preference. A provider that can read your files can also nudge you toward paying for more storage the moment you get close to a limit, a much harder sell for a service that genuinely can't see what you're storing. And a vague privacy policy is simply easier to write than a precise one a lawyer would have to stand behind later.
None of that makes provider-held-key storage useless — it's genuinely fine for a lot of what people store. It does mean the convenient default was chosen for the company's reasons more than yours, which is worth knowing before deciding what belongs there.
Even a provider that encrypts your file contents typically still sees the metadata around it — the file name, its size, when it was created and modified, who you've shared it with. A privacy policy that says "your files are encrypted" and stops there is often true and incomplete at the same time.
Pick the provider holding the file you'd least want exposed, and give yourself five minutes to find its actual encryption model — not the marketing headline, the specifics. Most providers publish this in a security whitepaper or trust center page, not the page that sells you storage space. If you can't find a straight answer in five minutes, that's itself the answer: the company either doesn't want to make the claim precisely, or doesn't expect you to go looking.
If you can't verify what a provider actually does with your key, the simplest fix is to stop relying on them to. Encrypt the file yourself before it ever leaves your device, and the provider's policy stops being the thing standing between your data and anyone who asks for it.