No, not by default
iCloud is not zero-knowledge out of the box. Apple encrypts your data in transit and at rest but keeps a copy of the keys, so it can read your files and produce them under a valid legal order. Advanced Data Protection turns on end-to-end encryption for most categories — but it is opt-in, off until you enable it, and it never covers Mail, Contacts, or Calendar.
What zero-knowledge actually requires
Zero-knowledge means the provider cannot read your files, because the keys never exist on its servers in a usable form. Encryption happens on your device, with a key derived from a secret only you hold. The server stores ciphertext and nothing it can turn back into plaintext. Apple's own newsroom calls ADP "end-to-end encryption" — fair language for what it covers. The default iCloud setup is not that.
By default you get what Apple calls standard data protection. Your data is encrypted, and Apple holds the keys in its data centres. That is the same arrangement Dropbox and Google Drive use: encrypted at rest, encrypted in transit, readable by the provider. Those two properties protect Apple's hardware from theft. They do not make your data private from Apple, which is a different question entirely — we walk through why in our security overview.
Standard vs Advanced: who holds the keys
iCloud has two modes, and the only difference that matters is custody of the keys.
- Standard data protection (the default): 14 categories are encrypted, but Apple holds the keys for most of them — iCloud Backup, iCloud Drive, Photos, Notes. Apple can decrypt all of it, so a court order reaches it. Two categories are end-to-end encrypted even here: iCloud Keychain (your passwords) and Health data.
- Advanced Data Protection (opt-in): the count of end-to-end-encrypted categories jumps from 14 to 23. iCloud Backup, Drive, Photos, Notes, Reminders, Safari bookmarks and more move under keys Apple no longer holds. For those categories, this is genuine zero-knowledge.
The catch lives in three words: for those categories.
The three categories ADP never touches
Switch ADP on and three of the most revealing parts of your account stay readable by Apple:
- iCloud Mail. Email has to interoperate with the global SMTP system, which has no end-to-end model. Your mailbox is not E2E encrypted, ADP or not.
- Contacts. Built on
CardDAV, an open standard with no built-in encryption layer. - Calendars. Built on
CalDAV, same constraint.
For a lot of people that is the worst possible exclusion. Your inbox, your full contact list and your calendar describe your life more completely than the documents sitting in iCloud Drive. ADP covers the Drive. It never covers those.
Metadata stays behind too
ADP encrypts the contents of a file. It does not encrypt everything about the file. By Apple's own documentation, some data stays under standard protection even with ADP on, so the service can keep working: the dates and times an object was modified, used to sort your library, and checksums of file and photo data, used to de-duplicate storage across your devices.
Metadata is not a footnote. A modification timestamp plus a per-file checksum is enough to confirm you hold a specific known file, sketch your activity patterns, and link one account to another — all without decrypting a single byte. "The contents are encrypted, the metadata isn't" is a real gap.
It's off until you turn it on
The single most important fact about ADP: Apple ships every account on standard protection. To switch, you open Settings, find Advanced Data Protection, set up a recovery contact or recovery key, and enable it on every device signed into your Apple Account — any device still on an old OS has to be dropped from the account first. Most people never do any of that. If you have not deliberately enabled ADP, your iCloud Backup, Photos and Drive are readable by Apple as you read this.
There is also a jurisdiction wrinkle. In January 2025 the UK government served Apple a secret order under the Investigatory Powers Act demanding access to ADP-protected data. Apple's answer was to pull Advanced Data Protection for new UK users entirely rather than build a backdoor. The standoff ran all year — the demand was withdrawn in August under US pressure, then reissued in October as a UK-only order. A feature a government can pressure a company into disabling is structurally different from one the company was never able to read in the first place.
The price, stated fairly
iCloud+ is cheap at the small tiers, and we won't pretend otherwise. In the US it runs 5 GB free, then $0.99/month for 50 GB, $2.99 for 200 GB, $9.99 for 2 TB, $29.99 for 6 TB, and $59.99 for 12 TB. Twelve terabytes is the ceiling; there is no plan above it.
By contrast, Beebeeb is zero-knowledge on every tier, no exceptions: €1.99/month for 100 GB, €3.99 for 200 GB, then €10.99 for 1 TB. You can scale to 99 TB self-serve at +€10.99 per extra TB, with a custom quote beyond that. At a single 200 GB tier, iCloud is cheaper — that is the honest trade. What the difference buys is that we never hold a key that decrypts your files, and the data lives in Falkenstein, Germany, under EU jurisdiction rather than with a US company answerable to the CLOUD Act. The two are lined up row by row in our honest Beebeeb-vs-iCloud comparison.
The three questions people ask next
"Should I just turn on ADP?" If you are staying on Apple, yes. It is a real improvement and costs nothing. Enable it, set a recovery key, and store that key somewhere safe — once ADP is on, Apple genuinely cannot reset your access. Just remember it never reaches Mail, Contacts, or Calendar.
"Is ADP as private as a zero-knowledge provider?" For the categories it covers, the encryption model is comparable. Where it differs is scope (Mail, Contacts, Calendar and metadata sit outside it), the opt-in default, and jurisdiction. Apple is a US company; its design choices answer to US law and to pressure like the UK order above.
"What if I want this on by default?" Pick a provider where client-side encryption is the only mode, not a toggle. That is the whole premise of Beebeeb, and the migration path — caveats and what is still coming included — is laid out in our iCloud alternatives guide.
Turn ADP on either way. The point was never which logo you trust — it is knowing exactly who can read what before you decide.