All articles

Can a company read the data you store? How to tell

Kent — founder, former banking CTO/CIO · August 20, 2026

Can they read it?

Here's a question worth asking of anything that holds your files, messages, or personal details: not "is it encrypted?" — almost everything is now — but "can the company itself read what I put there?" For most services, the honest answer is yes. They encrypt your data and keep the key, so they can decrypt it whenever they choose. Their privacy policy is a promise not to abuse that — "we won't." It is not the same as "we can't."

The difference sounds academic until the day it isn't: a breach, a legal demand, a change of ownership, an employee who shouldn't be looking. In every one of those, "we won't" is only as good as the circumstances. "We can't" holds regardless.

A hardcover ledger held shut by a small brass padlock on a desk

The real question

A lock only helps if you hold the key

Almost everything is encrypted now, so "is it locked?" barely narrows things down. The question that does is who keeps the key — because that's the whole distance between a company that won't read your data and one that can't.

Won't vs. can't

Two kinds of "encrypted"

Two services can both say "encrypted" and mean opposite things. The dividing line is who keeps the key.

Encrypted, key kept

The company holds the key, so it can read your data — and so can anyone who breaches or compels it. "We won't."

Zero-knowledge

The key never leaves you, so the company can't read what it stores — even if it wanted to, was breached, or was ordered to. "We can't."

How to tell

Three quick tests

You usually can't see a company's architecture, but its behavior gives it away. If any of these is true, it's holding a key it could use.

The reset test

Can it reset your password and still show your old data afterward? Then it can decrypt it without you.

The email test

Can it email you the content you stored? Then it can read the content you stored.

The ads test

Does it tailor ads or features to what you put in? Then something is reading it.

A genuinely zero-knowledge service fails all three on purpose: it can't recover your data if you forget your master password, can't email you your content, and has nothing to mine. That's not worse service — it's the proof. The full explanation is in what zero-knowledge encryption actually means, and the broader framing in security vs. privacy.

We can't, not we won't.

It matters most for the data that is you — the identity and documents you'd never want a company quietly reading or selling on. Those belong somewhere the answer to "can they read it?" is no.

Simply Once is zero-knowledge by design: your vault is encrypted with a key only you hold, so we couldn't read your data if we tried.

Part of the guide to protecting your personal data online →

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.