← Back to blog

Dropbox is encrypted. That is not zero-knowledge.

· TinyX · 4 min read

Dropbox is encrypted. That is not zero-knowledge.

People type “dropbox zero knowledge” into Google for a reason. Marketing said the files are encrypted. That sentence is true — and it is not the same as zero-knowledge.

If you care who can open your files, the useful question is not “is it encrypted?” It is who holds the key.

Encrypted at rest is not zero-knowledge

Dropbox’s own help docs are clear about the default model. How Dropbox keeps your files secure states that files at rest are encrypted with 256-bit AES, and that data in transit is protected with TLS. The same page also says, plainly: “Dropbox doesn’t offer client-side encryption. Dropbox also doesn’t support the creation of your own private keys.”

That is standard cloud storage encryption: Dropbox (or its key-management stack) can decrypt what it stores so the product can search, preview, sync, and share. Encryption here protects disks and pipes. It does not mean Dropbox cannot read file contents.

Zero-knowledge is a different claim. The provider never holds a usable copy of your decryption key. Ciphertext on their servers is not something they can open — not for support, not for features that need plaintext, not under ordinary operational access.

Those two models often get flattened into one word: “encrypted.” Search behavior follows the marketing.

Dropbox does offer E2EE — on team plans, for specific folders

Dropbox has been honest that default encryption and end-to-end encryption are not the same thing. In Encrypted team folders: an overview, Dropbox answers its own FAQ — “Isn’t Dropbox already encrypted?” — by explaining that E2EE “adds an additional layer of privacy” with exclusive control over encryption keys, and that it is recommended for highly sensitive data while “standard Dropbox encryption” may suffice for less sensitive files.

That E2EE feature is real. It is also scoped:

  • Available for teams on Business Plus, Advanced, and Enterprise — not personal / Professional accounts by default
  • Applies to encrypted team folders admins create, not every file in the account
  • Comes with known feature limits (shared links, previews, search indexing, Transfer, and more are restricted for those folders)
  • Mobile app access for encrypted folders is limited; Dropbox documents that E2EE is not available in the Dropbox mobile app the same way

Dropbox’s engineering write-up on implementing end-to-end encryption for teams is equally direct: they already encrypt at rest with AES-256, and customers seeking E2EE want a model where only they possess the decryption key, so not even Dropbox can access file contents.

None of that is a gotcha. It is Dropbox describing two different products under one brand. The confusion appears when “Dropbox is encrypted” is heard as “Dropbox is zero-knowledge for my personal share links.”

What TinyX means by zero-knowledge

TinyX encrypts files in the browser with AES-256-GCM before upload. The decryption key is never sent to TinyX servers. We store ciphertext we cannot open. That is the whole point — not a Business-plan folder add-on, and not “trust us, the disk is encrypted.”

On top of that, sharing defaults toward control instead of permanent open doors:

  • Free: outgoing file share with expiry and passwords (upload drops / inbound client uploads are not on Free — they start on Pro+)
  • Pro / Max: higher caps plus upload drops so clients can send files in without an account, still under client-side encryption

Caps, for clarity: Free 150MB per file / 10GB storage; Pro $9 / 1GB / 100GB; Max $29 / 5GB / 300GB. Full detail is on pricing and features.

For a broader product comparison — sync suites versus controlled external handoffs — see TinyX vs Dropbox. For why “anyone with the link” from years ago is still a live risk on classic cloud shares, see share links that never expire.

A short checklist when someone says “it’s encrypted”

  1. Who holds the key? Provider-managed keys ≠ zero-knowledge.
  2. Is client-side encryption the default for the files you actually send, or an enterprise folder mode?
  3. What breaks when keys leave the provider? Previews, server search, and some share types often require plaintext on their side.
  4. Does the link die? Encryption does not revoke a permanent “anyone with the link” URL.

If you searched “dropbox zero knowledge” because a pitch deck said “encrypted,” you were asking the right follow-up. Encrypted storage is table stakes. Zero-knowledge is a statement about custody of the key.

TinyX is built for the second claim: client-side AES-256-GCM, key never on our servers, expiry and passwords on Free, upload drops from Pro up. Start at pricing or skim features.