Cloud storage looks like a simple purchase: pick a provider, pick a size, pay monthly. The differences that matter show up later, on the day a laptop is stolen, a file is overwritten, ransomware encrypts a shared folder or a client asks how their documents are protected. This guide explains the three choices that decide whether a service will actually help on that day: whether it syncs or backs up, how it encrypts your files, and how it lets you share them.

Start with the free storage you already have

Most people already have some cloud storage: a Google account, an Apple ID or a Microsoft account each comes with a free allowance, and many phones and laptops are set up to use it. For one person with documents and a modest photo library, that free allowance, or the smallest paid tier from the same company, is often enough. The ecosystem you already live in usually gives the smoothest experience: iCloud on Apple devices, Google Drive with Gmail and Android, OneDrive with Windows and Microsoft 365.

Look further when you need more space than the bundled plans offer at a sensible price, when you work across several ecosystems, when you want stronger privacy than the default, or when a business needs admin controls and longer file history.

Sync is not backup

This is the single most misunderstood point about cloud storage. Most popular services, including Google Drive, Dropbox, OneDrive and iCloud Drive, are primarily sync services. They keep the same files identical across your devices and the cloud. That is exactly what you want when you edit a document on your laptop and open it on your phone. It is exactly what you do not want when a file is deleted, corrupted or encrypted by ransomware, because sync faithfully copies the damage everywhere.

The UK's National Cyber Security Centre has reported seeing ransomware encrypt "not only the original data on-disk, but also the connected USB and network storage drives holding data backups". Its advice is to keep at least one backup that an incident cannot reach at the same time as your live files. In its small business guide, the NCSC says backups should not be permanently connected to the device holding the original copy, and that cloud storage is a cost-effective way to keep a copy in a different place.

What rescues a sync user is version history and a deleted files window, so check both before you buy:

  • Google Drive's help pages say a previous version of an uploaded file "might be permanently deleted after 30 days or if there are 100 newer versions", unless you mark it "Keep forever".
  • Dropbox's version history page lists 30 days on its Basic, Plus and Family plans, 180 days on Professional, Essentials, Business and Standard, and 365 days on Business Plus, Advanced and Enterprise.

Thirty days sounds generous until you discover a problem in week five. If your files matter, either choose a plan with a longer history or add a separate backup: a backup service that keeps independent copies, or an external drive that you connect, update and disconnect. Many households and small offices use both: sync for daily convenience, and a backup that sync cannot overwrite.

Encryption: who holds the keys?

Almost every reputable service encrypts files in transit and on its servers. The question that matters is who holds the keys. If the provider holds them, it can decrypt your files: to scan them, to help you recover a lost account, or in response to a lawful demand. If only your devices hold the keys, which is usually called end-to-end or zero-knowledge encryption, the provider cannot read your files at all.

The main services take different approaches:

  • iCloud. Apple's iCloud data security overview explains that under standard data protection, iCloud Drive is encrypted in transit and on the server, with keys held by Apple. Turning on the optional Advanced Data Protection makes iCloud Drive, Photos, device backups and other categories end-to-end encrypted, with keys held only on your trusted devices. Apple warns that if you enable it and lose access to your account, it "will not have the encryption keys to help you recover it", which is why you must set up a recovery contact or recovery key first.
  • pCloud. pCloud's encryption page describes pCloud Encryption as client-side, meaning files are "encrypted before it is uploaded. Not on the server". It is sold separately from standard storage and applies to files you put in the encrypted folder.
  • Sync.com. Sync.com says its service includes "end-to-end encryption and zero-knowledge authentication features".
  • Google Drive and Dropbox. On standard consumer plans, the provider manages the keys. That enables convenient features such as search inside documents and web previews.

End-to-end encryption has real trade-offs. If you forget the password or lose the recovery key, nobody can get your files back. Some features, such as web previews, server-side search and easy sharing with people outside the service, may be limited or work differently. For most personal files, a provider-managed service with a strong password and two-step verification is reasonable. For client records, legal or financial documents, or anything you would not want a third party to be able to read, end-to-end encryption is worth the inconvenience.

Security basics that matter more than the brand

  • Turn on two-step verification. Most account takeovers start with a reused or phished password. A second factor stops most of them.
  • Use a unique password, ideally from a password manager.
  • Review connected apps and devices every few months and remove ones you no longer use.
  • Know how recovery works. Set up recovery options before you need them, especially if you turn on end-to-end encryption.

Sharing: convenient links and the risks they carry

Sharing is where most accidental leaks happen. The usual culprit is the public link. Google Drive's sharing help says that with "Anyone with the link", anyone who has the link can open your file "without signing in to their Google Account". Links get forwarded, pasted into chats and indexed in places you did not expect.

Good sharing habits, whatever service you use:

  • Share with named people where possible, so access is tied to an account you can remove later.
  • Use expiry dates on links for anything sensitive. Check whether your plan includes them: Google says link expiration is available only on eligible work or school accounts, and other providers reserve it for paid tiers.
  • Restrict downloads when you only want someone to view a document. Google Drive, for example, lets owners decide whether viewers and commenters can download, print and copy.
  • Audit old shares periodically. Most services can list everything you have shared; revoke what is no longer needed.
  • For businesses, check admin controls: the ability to block public links, see external shares and remove a departing employee's access in one step.

Other things to compare

  • Price per terabyte over time. Compare annual prices for the size you will need in two or three years, not just today. Watch for introductory prices that rise at renewal.
  • Lifetime plans. Some providers sell one-off lifetime storage. It can be good value, but you are betting on the company's long-term survival, so keep a backup elsewhere.
  • Selective sync and online-only files, so a large library does not fill a small laptop drive.
  • File request and large file transfer features if you regularly receive files from clients.
  • Data location. Some businesses need data stored in a particular region; check whether the provider offers a choice.
  • Getting your data out. Check how easy it is to download everything if you leave.

A quick way to choose

  1. Start with the storage built into the ecosystem you already use, and see whether its paid tiers cover your needs.
  2. Decide what you need beyond sync: longer version history, a separate backup, or end-to-end encryption.
  3. If privacy matters most, shortlist services with end-to-end encryption and test the recovery process before you trust them with anything important.
  4. Turn on two-step verification, set sensible sharing defaults and put a recurring reminder in your calendar to review shared links.
  5. Whatever you pick, keep at least one copy of irreplaceable files somewhere your sync service cannot overwrite.

The right cloud storage is the one that fits the devices you already use, keeps enough history to undo a mistake, protects files to the level they deserve, and makes it hard to share more than you meant to. Price comes after those.