Priviy
cloud-chiffre-comparisonCOMP

Proton Drive vs iCloud (2026): The Setting Apple Leaves Off by Default

iCloud can be end-to-end encrypted, but only if you switch on a setting Apple leaves off. Three categories stay readable even then. How that compares with Proton Drive.

By Eric Gerard · Editor · Priviy4 min readPhoto via Pexels

The usual version of this comparison says that iCloud is convenient and Proton Drive is private. That is too simple, and it misses the thing that actually decides the outcome for most people: a switch in Settings that Apple leaves off.

iCloud can be end-to-end encrypted, and usually is not

Apple offers Advanced Data Protection, which it describes as an optional setting giving its highest level of cloud data security. When it is on, the user's trusted devices keep sole access to the encryption keys for most iCloud data.

The numbers are specific. With Advanced Data Protection off, which is the state every account starts in, 14 data categories are end-to-end encrypted. With it on, that rises to 23, and the additions include iCloud Backup, Photos and Notes.

Those three are exactly the categories most people would name if you asked what they keep in the cloud. So the real question is not whether iCloud supports end-to-end encryption. It does. The question is whether a given account has it switched on, and by default it does not.

The three categories that never qualify

This part does not change no matter what you enable.

iCloud Mail, Contacts and Calendar are not end-to-end encrypted, including for accounts with Advanced Data Protection turned on. Apple explains why rather than leaving it vague: mail has to interoperate with the global email system, and contacts and calendars are built on the CalDAV and CardDAV standards, which do not provide built-in support for end-to-end encryption.

That is a genuine constraint of interoperable protocols, not a shortcut. Any provider that lets you exchange email and calendar invitations with the rest of the world faces the same limit. It is worth knowing precisely because it is permanent.

A data centre aisle lined with tall server cabinets, network cables visible behind their mesh doors.
A data centre aisle lined with tall server cabinets, network cables visible behind their mesh doors.

Where Proton Drive differs structurally

The meaningful difference is not a feature list, it is the default.

Proton Drive is designed around end-to-end encryption as its ordinary operating mode, rather than as a setting to be discovered. There is no equivalent of "the protection is available, but off until you find it".

That distinction matters more than any specification comparison, because defaults decide outcomes at scale. A protection that requires a deliberate action protects the people who know it exists. Everyone else gets the default, which is why the default is the product.

If you want the underlying concepts, we cover the difference between end-to-end encryption and zero-knowledge storage in end-to-end vs zero-knowledge cloud storage.

Availability is not uniform

One factual point that complicates the picture: Apple has stated it can no longer offer Advanced Data Protection to new users in the United Kingdom.

The practical lesson is not about one country. It is that a protection dependent on a provider's ability to offer it in your jurisdiction is not the same as a protection built into how the service works. Check what is actually available to you rather than assuming the feature exists everywhere.

What to do, depending on where you are

If you stay on iCloud, the single highest-value action is to open Settings and turn on Advanced Data Protection. It moves you from 14 to 23 protected categories and takes a couple of minutes. Set up the recovery method it asks for, because with end-to-end encryption a lost account is genuinely lost.

Do not put your most sensitive material in Mail, Contacts or Calendar and expect it to be encrypted end to end. Those three stay readable to the provider whatever you enable. Notes, which is covered by Advanced Data Protection, is a better place for it than a calendar entry.

If you want the protection to be the default rather than a setting, that is the case for a provider like Proton Drive, and it is a reasonable one. Just be clear that you are buying a different default, not a capability iCloud lacks.

Choix éditorial
4.5 / 5

If you would rather not depend on a setting being on

Proton Drive treats end-to-end encryption as its normal mode rather than an option. Mail and calendar interoperability limits still apply to any provider.

Juridiction Suisse FDPLZero-knowledge par défautFree 5 GB
Voir l'offre

The short version

iCloud is not the unencrypted service it is sometimes described as, and Proton Drive's advantage is not that it invented something Apple lacks. The difference is where the protection sits: on by design, or off until you find the switch. Add the three categories that can never be end-to-end encrypted, and the availability question in some jurisdictions, and you have the full picture.

If you take one action from this article, make it turning on Advanced Data Protection. It is free, it is fast, and most iCloud accounts do not have it.

Category counts, the optional nature of Advanced Data Protection, the Mail, Contacts and Calendar exclusions with their CalDAV and CardDAV rationale, and the United Kingdom availability statement are drawn from Apple's own support documentation, checked at the time of writing. Provider policies change; verify current terms before relying on them. Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.

Frequently asked questions

Is iCloud end-to-end encrypted?
Partly, and it depends on a setting. Apple describes Advanced Data Protection as an optional feature. With it off, which is the default, 14 data categories are end-to-end encrypted. With it on, that number rises to 23 and includes iCloud Backup, Photos and Notes. So the honest answer is that iCloud can be end-to-end encrypted for most of your data, but only if you go and turn it on.
What stays readable even with Advanced Data Protection on?
Three categories: iCloud Mail, Contacts and Calendar. Apple gives the reason: these have to interoperate with the global email system and with the CalDAV and CardDAV standards, which have no built-in support for end-to-end encryption. This is a design constraint of those protocols, not an oversight, and no setting changes it.
How is Proton Drive different?
The main structural difference is the default. Proton Drive is built around end-to-end encryption as its normal mode rather than as an option you enable. With iCloud, the protection depends on a choice most people never make, because the setting is off until someone turns it on.
Does this mean iCloud is unsafe?
No, and that framing is worth resisting. iCloud with Advanced Data Protection enabled is a serious level of protection for the 23 covered categories. The practical problem is not the technology but the default: a protection that is off by default protects only the people who know it exists.
Is Advanced Data Protection available everywhere?
Not universally. Apple has stated it can no longer offer Advanced Data Protection to new users in the United Kingdom. Availability can change by jurisdiction, so check what applies where you are rather than assuming the feature is on offer.
Choix éditorial
4.5 / 5

Get encrypted cloud storage → pCloud

Swiss-based · client-side Crypto add-on · lifetime plans

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre