iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A backup provider can be unable to read your files and still store them. “Doesn’t store a single byte of my data” and “can’t read my data” are different claims, and only the second is what most encrypted backup designs actually deliver. The first needs a defined scope before it means anything. This article explains how to tell the two apart, what the provider can still see even when it cannot decrypt your content, and the recovery trade-off that comes with keeping the keys out of the provider’s hands.
What “not a single byte” would have to mean
The phrase covers at least four different things, and a vendor may be honest about one while staying silent about the others:
- Plaintext content: the readable versions of your files. This is the claim that most encrypted backup services can support.
- Ciphertext: encrypted backup objects. A service can hold these without being able to open them. Holding them is not the same as holding your readable data.
- Metadata: account details, timestamps, file sizes, object counts, and similar information about the backup itself. Encryption of file contents does not automatically hide any of this.
- Support and operational data: login records, billing information, logs, and anything exchanged with the support team.
A statement that a provider stores “no data” at all would have to cover every item above. A statement that it cannot read your content covers only the first. Ask which one your app means. The app in the title is not named here, so its exact claim and its architecture cannot be checked from this article. What follows is a general model you can apply to any backup product.
Recommended Free Tools
Encryption at rest is not the same as provider-held keys
Many people assume that data stored in encrypted form is private from the company that stores it. That assumption is often wrong. Apple’s description of its default iCloud protection says data is encrypted in transit and at rest, but the keys are kept in Apple data centers, so Apple can help with recovery when you lose access to your account or devices. Apple Support, “iCloud data security overview” sets out this arrangement.
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
The practical distinction is who holds the key. If the provider holds it, the provider can decrypt the data, and the encryption protects you mainly against outsiders who do not have access to the provider’s systems. If only you or your trusted devices hold it, the provider can store the data but cannot read it.
How end-to-end encryption changes key custody
End-to-end encryption moves the keys to the user’s side. Apple offers this as an optional setting for iCloud. With Advanced Data Protection turned on, iCloud Backup is end-to-end encrypted, and the keys are available only on trusted devices. Apple Support, “How to turn on Advanced Data Protection for iCloud” covers the setup. Apple’s Apple Platform Security guide on iCloud Backup security describes the underlying design in more technical detail.
Apple is a useful example because the two modes are documented side by side. The table below shows what changes when you switch.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors| Question | Standard iCloud data protection | Advanced Data Protection (optional) |
|---|---|---|
| Where the keys are held | In Apple data centers | Only on trusted devices |
| Can Apple help restore protected data? | Yes, Apple can assist with recovery | No. Apple does not have the keys needed to restore protected data |
| Who handles recovery if access is lost? | Apple can assist | You do, using your own recovery methods |
Apple’s support guide for Advanced Data Protection puts the consequence plainly: “If you use Advanced Data Protection, you’re responsible for your data recovery.” The protection that keeps Apple from reading your backup is the same thing that leaves you without a provider-side fallback.
Rank #2
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Why the recovery cost matters
A provider that cannot decrypt your data cannot reset your access to it either. If you lose the trusted devices and the recovery methods, the encrypted backup may be permanently unreadable. Before you switch to any key-custody arrangement, confirm that you have working recovery methods and that you know how to use them.
Vendor claims about client-side and zero-knowledge encryption
Backup vendors use terms such as “client-side encryption,” “zero-knowledge,” and “AES-256” to describe their designs. Those terms describe a claim, not an independent audit. Comet Backup’s security page describes AES-256 encryption and immutable storage, as Comet Backup, “Secure Backup: AES-256 & Immutable Storage” presents them. Tresorit’s Tresorit, “Zero-Knowledge Encryption” page describes its own provider-inaccessible key model. Both pages are vendor statements about how their products are designed, and neither confirms how any other app works.
A label does not tell you where encryption happens, so check the design rather than the name. The questions below are the ones that separate a real architecture from a slogan.
What an end-to-end encrypted backup looks like in practice
Meta Engineering’s September 10, 2021 post on WhatsApp’s optional encrypted backups is a concrete example of the model. The company wrote that neither WhatsApp nor the backup service provider will be able to access their backup or their backup encryption key. That is a statement about a design announced in 2021. It is not a current independent audit, and it does not describe how WhatsApp’s backups work today.
Rank #3
- High capacity in a small enclosure – The small, lightweight design offers up to 6TB* capacity, making WD Elements portable hard drives the ideal companion for consumers on the go.
- Plug-and-play expandability
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- SuperSpeed USB 3.2 Gen 1 (5Gbps)
The example shows the point of this article. An encrypted backup can sit on a third party’s servers. The provider holds the bytes but not the means to read them. The backup still exists remotely, which is why the title’s claim should be read as “cannot read” rather than “does not store.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to check a backup app’s claim
- Find where encryption happens. Look for whether files are encrypted on your device before upload. Vendor pages that say “client-side” are saying this; a vague “we encrypt your data” is not enough.
- Ask who holds the key. If the vendor can reset your key or recover your backup without you, it has a copy of the key or a way to obtain it.
- List what is not encrypted. Ask for the documented list of metadata, account data, and logs the provider can see. A design can protect file contents and still expose file names, sizes, and timestamps.
- Confirm recovery without the vendor. Check whether you can restore if the account, password, or device is lost, and what you need to keep safe to do it.
- Test a restore. A backup you have never restored is an assumption. Restore a sample file to a different device before you rely on the service.
Where a provider-blind design does not protect you
Provider-inaccessible keys address one risk: the provider reading your content. They do not, by themselves, protect against a compromised device, a weak password, or the loss of recovery materials. Those risks sit with you. A design that keeps keys away from the vendor can make a lost-key situation a permanent loss of data, so the same architecture that improves privacy can also remove the safety net.
The sources cited here establish key custody and recovery trade-offs. They do not establish a complete threat model for any particular product.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThe Bottom Line
Trust a backup app for the thing it can actually guarantee: that it cannot read your content, if its documentation describes client-side encryption and keys that stay with you. Do not extend that trust to the claim that it stores no data at all, which almost no encrypted backup service can honestly make. Before relying on the app, confirm what it encrypts, what metadata it can see, and how you would recover your backup if you lost your access.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

