The “Private” Folder in Your Drive Isn’t Private to the Model
Microsoft says they don’t train on your files. The thing being said and the thing being denied are different. Here’s the distinction nobody…
The “Private” Folder in Your Drive Isn’t Private to the Model
Microsoft says they don’t train on your files. The thing being said and the thing being denied are different. Here’s the distinction nobody at your cloud provider wants you to learn.

When Google or Microsoft says your cloud storage is “encrypted,” they are telling the truth.
When you conclude that this means they can’t read it, you are making a leap they have not made for you.
The word “encryption” is doing about three different jobs in cloud marketing copy, and most users don’t know which one is in play in any given sentence. The result is a widespread, comfortable misunderstanding: that the files in your Google Drive, your OneDrive, your iCloud — labeled “private,” tucked into folders you didn’t share — are inaccessible to the company hosting them.
They aren’t. They never have been. And in 2026, with Gemini and Copilot reading across your entire workspace to “help” you, the gap between what you think privacy means and what these companies have promised is wider than at any point in the history of cloud storage.
This article is a short, plain-language guide to the difference. Once you see it, you cannot un-see it.
The three kinds of encryption
There are three encryption regimes used in consumer cloud storage. They sound similar. They are not similar.
Encryption in transit. Data is encrypted between your device and the company’s server using TLS — the same thing that puts the padlock in your browser. This prevents anyone on the network in between (your coffee shop’s wifi, your ISP, a man-in-the-middle attacker) from reading your files as they fly through the air. It does nothing about what the company can do with the file once it lands.
Encryption at rest. Data is encrypted on the company’s disks. This protects you if someone steals a hard drive out of a Google data center. It does not protect you from Google itself, because Google holds the keys. They can decrypt your file any time they want, for any reason — to serve you a search result, to run an AI feature, to respond to a subpoena, to investigate a TOS violation, to train a model if their policy permits, or because an employee decided to look.
End-to-end encryption (E2EE), also called “zero-knowledge” encryption. Data is encrypted with keys only you hold. The company stores ciphertext — random bytes — and has no technical ability to read it. Subpoena them and they can hand over the bytes, but the bytes are useless. This is what Proton Drive, Tresorit, Sync.com, and a handful of others provide. It is what iCloud provides only if you’ve turned on Advanced Data Protection. It is not what Google Drive, OneDrive, or default iCloud provide for the bulk of your files.
The crucial distinction is the second one versus the third. “Encrypted at rest” and “end-to-end encrypted” sound like they describe similar things. They describe opposite things. In the first, the company has the keys. In the second, they don’t.
Every consumer cloud storage service on Earth uses encryption at rest. A tiny minority uses E2EE. The marketing copy on both says “your data is encrypted.”
The AI features are the proof
You don’t have to take any company’s word for which kind of encryption you’re getting. Their AI features will tell you.
Microsoft’s Copilot in OneDrive can summarize your files, compare them, answer questions across multiple documents, and now — as of a February 2026 update — run “agents” that synthesize information across up to 20 documents simultaneously. Microsoft’s own architecture documentation describes the mechanism: when you query Copilot, it reads the relevant files via Microsoft Graph, sends the content plus your prompt to GPT-4 inside Microsoft’s “service boundary,” and returns a response.
This mechanism is not compatible with end-to-end encryption. It can’t be. If Microsoft couldn’t decrypt your files, GPT-4 would be summarizing random bytes. The feature exists because the provider has the keys.
Google’s Gemini integration with Workspace works the same way. “Help me write” in Docs reads your existing document. “Summarize this thread” in Gmail reads your inbox. The Drive sidebar that answers questions about your files reads your files. These features are evidence that Google can read your files. They could not exist otherwise.
This is the diagnostic test, and it’s a clean one: if your cloud provider offers AI features that work on the content of your files, your files are not end-to-end encrypted.
Microsoft can tell you, truthfully, that they don’t use your files to train their underlying models. That’s a different statement from “we can’t read your files.” They can read your files. They have to, to make Copilot work. The training-data question is downstream of the access question. The access is the prerequisite, and the access is conceded by the existence of the product.
“Private” is a sharing label, not an encryption label
The single sneakiest piece of language in consumer cloud storage is the word “private.”
When you set a Google Drive folder to “private,” you have changed exactly one thing: other Google users cannot find it via sharing links or search. Google can still read it. Google’s automated systems still read it for malware scanning, CSAM detection, AI training where permitted, and the operation of any AI feature you’ve enabled. “Private” means “not shared with other users.” It does not mean “encrypted from the host.”
OneDrive uses the same convention. iCloud uses the same convention. Dropbox uses the same convention. This is not a conspiracy; it’s a UX decision made fifteen years ago, before “AI reads your files” was on anyone’s radar. But in 2026, the linguistic ambiguity does real work. Many users believe their “private” folder is a sealed container. It is a clearly-labeled-as-not-shared container, sitting on a disk owned by a company that has the keys.
What’s actually in your Drive
Worth pausing on for a moment, because most people have never enumerated this.
For a normal user, the contents of their cloud storage in 2026 typically include:
- Tax returns and W-2s
- Mortgage documents, lease agreements, closing paperwork
- Passport scans and driver’s license images
- Health records, lab results, insurance documents
- Children’s birth certificates and school records
- Bank statements going back years
- A draft will or estate planning documents
- Photos of vacations, kids, family events
- Work documents containing client information
- Personal journals, half-finished essays
- Receipts, warranties, things you scanned and forgot about
This is a substantial fraction of the documentary record of your life. None of it, on Google Drive or OneDrive or default iCloud, is end-to-end encrypted. All of it is technically readable by the company that hosts it, and all of it is accessible to the AI features that have been progressively introduced over the last two years.
If a friend asked you to leave a box containing your tax returns, passport, and medical records at their house, you would think carefully about whether you trusted them. You have left the equivalent box at Google or Microsoft. The fact that it’s a digital box on a server has obscured what’s in it.
The fix is unusually easy
Unlike some privacy migrations, this one is mechanically simple. You’re not changing protocols or learning new workflows. You’re moving the same files from one bucket to another.
The hosted answer: Proton Drive — included in the Proton Unlimited plan at $9.99/month with 500GB. End-to-end encrypted. Folder sync on macOS, Windows, iOS, Android. The sharing experience is more clunky than Google Drive (encrypted sharing requires either a recipient with a Proton account or a password-protected link), but the trade-off is that Proton, by design, cannot read what you store.
Other E2EE options: Tresorit, Sync.com, Filen, and Mega all offer zero-knowledge cloud storage with varying feature sets and prices. Tresorit is the enterprise pick; Sync.com is the consumer pick most similar to Dropbox.
The Apple answer: Turn on Advanced Data Protection in iCloud settings. This extends end-to-end encryption to iCloud Drive, Photos, Notes, Voice Memos, Reminders, and device backups. It’s off by default. It requires you to set up a recovery contact or recovery key, because if you lose access, Apple genuinely cannot help you (which is the point). Most Apple users have never turned it on. If you’re an Apple household, this is the single highest-leverage privacy action you can take today.
The middle-ground answer: Cryptomator. This is a free, open-source tool that creates encrypted “vaults” you can store inside any cloud storage — Google Drive, OneDrive, Dropbox, whatever. The files inside are E2EE; the provider sees only encrypted blobs. The cost is that AI features on those files break (you can’t summarize what you can’t read), but that’s also the proof that it’s working.
The self-hosted answer: Nextcloud with its end-to-end encryption module, running on your own hardware. Covered in detail in the self-hosting walkthrough.
The closing argument
The phrase “we encrypt your data” has been doing decades of dishonest work in cloud marketing copy. It is technically true and substantively misleading, which is the most powerful kind of statement a corporation can make.
The thing you should want, if you care about this at all, is not encryption-in-general but the specific kind where the company you’re paying cannot read what you store. That kind exists. It is not the default. It is offered by a small number of providers who have built their business around it, and it is supported on Apple devices if you flip a single switch most users have never noticed.
The AI features rolling into Workspace and Microsoft 365 are not the privacy violation. They are evidence of a privacy choice your provider made long before the AI features existed. The AI just made the choice visible.
Now you can see it. What you do about it is up to you.
메타데이터
- post_id
- dfb8d4ce207a
- slug
- the-private-folder-in-your-drive-isnt-private-to-the-model-dfb8d4ce207a
- url
- https://medium.com/@lennart.dde/the-private-folder-in-your-drive-isnt-private-to-the-model-dfb8d4ce207a
- canonical_url
- https://medium.com/@lennart.dde/the-private-folder-in-your-drive-isnt-private-to-the-model-dfb8d4ce207a
- author_url
- https://medium.com/@lennart.dde
- status
- ok
- fetched_at
- 2026-06-29 22:44:20