I have never put anything I classify as very confidential on Google Drive. It’s not because I believe Google will one day blackmail me, but if it’s not my server, I shouldn’t act like I completely trust it. So I kept my kids’ photos and confidential spreadsheets away from it.
But I tested Cryptomator, and once I saw what Google Drive was actually getting, I realized I didn’t need to keep my most sensitive files away from it.
I put my real files behind a vault Google Drive was already syncing
Then I went looking for what actually left my computer
I had heard about Cryptomator, and it sounded interesting, but I needed to test it firsthand. So, I built a Cryptomator vault called “Vault for MUO”, and dropped in some files; a mix of CSV exports, some images, and spreadsheets. The goal was to give it the kind of folders I typically love to keep safe.
This folder sat inside my Cryptomator folder, which sat inside my Google Drive sync folder on my computer. When you launch Cryptomator and unlock the vault, it mounts the vault as a virtual drive on your computer. I opened this mounted vault and could see all the files I had dropped into that folder. They opened as expected and retained the original filenames. Nothing looked different or out of place.
This felt ordinary at first, but it’s the entire point of this service. It’s not asking you to change how you normally use files and folders. It requires you to trust that files leaving your computer won’t be recognizable. However, this requirement was the part I didn’t want to take on faith. So I went looking for what Google Drive was actually holding.
I opened Google Drive and didn’t recognize my own folder
Here’s what the cloud-side view showed me, item by item
The copy Google Drive held didn’t look like what I had saved. I didn’t see my photos or spreadsheet, rather it showed folders named “c” and “d”, a file called vault.cryptomator (with a backup), a masterkey.cryptomator (with its own backup), and a plain-text file Cryptomator drops into every vault. Those recognizable Cryptomator files also made one thing obvious: Google Drive could tell that this was an encrypted vault, even though it couldn’t see the files inside it.
It gets stranger when you open “c” or “d”. All you get are scrambled strings combining letters and numbers that really do not map to anything you have. Encrypted identifiers replaced my daughter’s folder names, the camera-generated photo filenames, and the CSV titles. This was far different from Google Drive hiding my files behind a password. It simply never got a readable version to start with.
|
What Google Drive sees |
Normal upload |
Inside the Cryptomator vault |
|---|---|---|
|
Filenames |
Readable |
Encrypted |
|
Folder names |
Readable |
Obfuscated/encrypted |
|
File contents |
Readable |
Encrypted |
|
Recognizable content |
Yes |
No |
|
File size |
Visible |
Visible |
The last row was the most surprising for me. I was thinking an encrypted file blurs the actual file size. Apparently, Cryptomator dropped file-size obfuscation in version 1.2.0. Hiding file size is a different problem, and it isn’t something the current vault format tries to solve.
The basic sync workflow doesn’t change. Google Drive still syncs the encrypted vault across my devices, while its versioning and recovery features operate on the encrypted files rather than my original files. The only place where the folder appears normal is on my machine after I unlock the vault.
The files vanished—but the evidence that I had files remained
Where the privacy claim actually stops
It was tempting to say Google Drive sees nothing after seeing the version that Google Drive holds. But that may not be exactly true.
Google Drive still sees that a vault exists, how much data the stored files occupy, and metadata such as file and folder timestamps and counts. Cryptomator doesn’t hide all metadata because the cloud service still needs enough information to synchronize the vault. What it doesn’t get is the readable content, original filenames, or original directory structure.
In other words, Cryptomator takes away the readable names and contents without hiding every piece of metadata about the vault.
Cryptomator encrypts file contents but doesn’t affect Google account logs such as login history or device data.
I changed what I let Google Drive see
Opening this vault once was interesting, but the real test was living with it. I made certain changes: added a few new photos, renamed a CSV file, and deleted a folder. After letting Google Drive sync, I locked my vault. Google Drive had no idea what the files were, but that folder still synced perfectly because it noticed something had changed.
UsingCryptomator adds an extra step—locking and unlocking the vault—which is some form of friction. You also don’t get previews of the vault content, and search stops working inside it; it’s just not possible for Google Drive to parse what’s hidden.
These are practical costs of using this tool, but they are a fair price to pay for keeping my files encrypted without giving up Google Drive. Cryptomator tops my list of useful tools that improve Google Drive security.
- OS
-
Windows, macOS, Linux
- Developer
-
Sebastian Stenzel
- Price model
-
Free, Open-source
Cryptomator is an open-source application for encrypting files. It allows you to store files securely in a cloud service or network drive.