Guide

How do I sync documents between my PC and my phone using my own cloud storage?

How do I sync documents between my PC and my phone using my own cloud storage?

Put the documents in a folder that an ordinary sync client watches — Drive, OneDrive, iCloud, Dropbox, Syncthing — and encrypt them before they enter it, so the provider stores ciphertext it cannot read. The sync client moves bytes and does not need to understand them, which is why this works with any provider and survives changing your mind about which one.

Almost everyone already pays for, or is given, enough cloud storage for a lifetime of documents. Documents are small; it is photographs and video that fill accounts. So the interesting question is not which storage to buy, it is how to use the storage you have without handing the provider readable copies of your passport.

The shape that works

Three layers, kept separate, and the separation is the whole idea.

  1. The documents, as ordinary files.
  2. An encryption layer that turns them into something unreadable, on your machine, before anything is uploaded.
  3. A sync client that moves the encrypted bytes between your devices via whatever account you already have.

Because layer three only ever sees ciphertext, it does not matter which provider it is, and swapping providers is a matter of pointing a different client at the same encrypted folder. You are using them as a courier rather than as a custodian — and a courier can be replaced without renegotiating anything.

The trap is doing this in the wrong order. Encrypting a file after it has been in a synced folder means a plaintext copy has already been uploaded, and it may still be there: most providers keep deleted files and previous versions for weeks by design.

Choosing the encryption layer

Two designs, and the difference matters for phones specifically.

A single encrypted container. One large file — a VeraCrypt volume, an encrypted disk image, a 7-Zip archive — that you unlock and use as a folder. Simple and very well understood. The drawback for syncing is that changing one document inside it can cause the whole container to be re-uploaded, and two devices editing it at once is a genuine risk to the file rather than an inconvenience.

Per-file encryption. Tools like Cryptomator and gocryptfs encrypt each file separately, so sync moves only what changed, and file names are encrypted too. This is the design built for cloud sync, and it is the one with usable mobile apps — which for this particular question is decisive.

What the provider can see under per-file encryption is worth being precise about: not the contents and not the names, but the number of files, their approximate sizes, and when each one changed. That is metadata, it is real, and no scheme of this kind hides it. For household documents it is almost always an acceptable trade; it is worth knowing you are making it.

Or skip the provider entirely

If the goal is only getting files between your own devices, you do not need a cloud account at all. Syncthing synchronises folders directly between machines over an encrypted connection, with no server in the middle and no account anywhere. It is free, open source, and runs on Windows, macOS, Linux and Android.

The trade is availability rather than security. A cloud provider is always awake; two laptops and a phone are not, so devices that are rarely on at the same time can drift for days. And Syncthing is not a backup — see below, because that distinction catches people out badly.

A common arrangement is both: Syncthing between the devices for speed and privacy, and an encrypted copy in a cloud account as the off-site backup. They solve different problems and neither substitutes for the other.

Sync is not backup, and this is the expensive lesson

A sync client's job is to make every copy identical, which means it faithfully replicates a deletion. Delete a folder on the laptop and it disappears from the phone a few seconds later. Corrupt a file and the corruption is copied. Encrypt everything with ransomware and every device receives the encrypted version promptly.

Providers do mitigate this — most keep version history and a recycle bin for a period, typically 30 days — and that has saved a great many people. But it is a limited window, it usually does not survive the container-file design above cleanly, and it is not something to rely on without having tested it.

What you actually need alongside sync is one copy that nothing automatic can reach: an external drive you plug in occasionally, or a backup service with its own retention. Then, once a year, restore from it on a different machine. An untested backup is a belief, not a backup.

Conflicts, and the phone problem

Two devices editing the same file before they have seen each other's changes produces a conflict. Sync clients handle it by keeping both and renaming one — document (conflicted copy 2026-09-01).pdf — which is the correct behaviour and also the reason those files accumulate unread for years.

For a document archive this is rarer than it sounds, because the files are mostly written once and read many times. It becomes real with a container-file design, where the container is a single file that both devices write to. Two things prevent nearly all of it: unlock the container on one device at a time, and let the sync finish before you leave.

On phones there is a second, less obvious problem: mobile sync apps are usually on-demand rather than continuous. The file list is present; the file is fetched when tapped. That is a sensible use of storage and battery, and it means the document you were counting on is not necessarily on the phone when you have no signal at the airport. If a document has to be available offline, mark it for offline access explicitly and check it, because the default is not that.

Questions

Does the provider know what my files are called?

It depends on the tool. Cryptomator and gocryptfs encrypt the file names as well as the contents, so the provider sees directories of meaningless names. Some simpler tools encrypt only the contents, which leaves "Mortgage offer.pdf" and "Divorce petition.pdf" perfectly legible in a listing. File names carry a surprising amount, so check this specifically rather than assuming that "encrypted" covers it.

Is this better than the provider's own encryption?

It is a different guarantee. Every mainstream provider encrypts at rest and in transit, which protects you from someone stealing a drive out of a data centre. It does not protect you from the provider itself, from a subpoena served on it, or from someone who gets into your account — because in all three cases the provider can decrypt. Encrypting before upload closes those, at the cost of one more thing to operate and one more key you must not lose.

What happens if I forget the passphrase?

You lose the documents, completely and permanently, and there is no support line that can help. That is the same property that makes the scheme worth using, so it has to be planned for rather than hoped about: write the passphrase down, store it physically somewhere safe, and make sure one other person can find it. There is a guide on exactly that problem — see the related links below.

Will this work with a work account?

Technically usually yes, and it is often a bad idea. Documents in an employer-controlled account can be subject to retention policies, legal holds and administrator access, and the account can be closed the day you leave — with everything in it. Personal documents belong in a personal account.

How much storage do I need?

Less than you expect. A thousand scanned pages at ordinary quality is a few gigabytes, comfortably inside the free tier of every mainstream provider. Encryption adds a negligible amount. If your account is full, it is almost certainly photographs and video doing it, which is one more argument for keeping documents in their own account or their own encrypted folder.

Where Keepsake fits

Keepsake is our product, so read this part with that in mind. Everything above is true whether or not you use it, and most of it you can do with a folder and an afternoon.

This is how Keepsake syncs, and there is no Keepsake server involved in it. The vault is encrypted on your device and the encrypted file goes through your own Google Drive, OneDrive, Dropbox or iCloud account — so the storage is yours, the bill is one you are already paying, and we hold no copy to lose or to be asked for. Editing on the desktop and reading on the phone works because the apps understand the vault format rather than because a service brokers it.

The Cryptomator-plus-your-provider arrangement above is a genuinely good answer to the same question and we would not argue with anyone using it. What it does not give you is expiry tracking, OCR that fills the details in, or a plan for someone else opening the vault when you cannot. If you only need encrypted files on two devices, use the free tools; they are excellent at it.