With all the marketing that Apple makes around confidentiality, and all the recently surveillance of government surveillance worldwide, you hope that the data from all your Apple Cloud services are locked.
You can be surprised that many things, depending on the settings you choose, are not as secure as you think. Here, we will state the difference between the two different encryption methods from Apple, discuss the advanced data protection mode and let you know which services are encrypted in what ways.
All encryption is not the same
Apple uses two different encryption forms for iCloud services. The most basic type is what the company calls encryption “in transit and on server”. The other more secure method is end -to -end encryption.
In transit and on server: Your Apple device has a decryption key, as is Apple servers. When you save data on the cloud, it is encrypted on your device so that the prying eyes spy on your network cannot understand it. It is stored encrypted on Apple servers, so if a hacker has access, everything will be blurred and useless.
But, and it's crucial, Apple do Hold the decryption key and can Decrypt data on its servers. It could do so for regular use (to analyze data to provide services) or at the request of governments (laws on how these requests are made vary from country to country).
If you ever lose access to your account, Apple can help you recover your data if you prove that you are the legitimate owner of the account.
End -to -end: E2E encryption means that your Apple device has the decryption key, which is linked to your biometric of access / front / tactile ID ID, and stored in the secure element equipment. It is encrypted on your device and remains encrypted when transmitted to Apple servers, where it is stored encrypted.
Apple made not Have the decryption key and has no way of making your data readable at all. It does not matter that this obtains a legitimate request for the application of the law or if it wishes to analyze your data to provide services – Apple cannot see your data and has no way of accessing it.
If you ever lose access to your Apple account and you have to recover it, Apple has no way of helping you recover the E2E encrypted data.
Advanced data protection
In 2022, Apple made available a new feature called Advanced Data Protection. To use it, your Apple account must have two -factor authentication and you must have a set of recovery keys or recovery contact.
Advanced data protection takes almost all iCloud services and improves them towards E2E encryption. It makes them a lot More secure, because Apple cannot decipher your data even if it wants, but it has the compromise to allow you to permanently lose your data if you lose access to your Apple account and cannot recover it with a recovery key or contact.
To activate ADP on your iPhone or iPad, access the settings, press your name, then press iCloud. Select Advanced data protection And turn it on. You can learn more about the advanced data protection here.
How your iCloud data is encrypted
The following table lists the different types of iCloud data for each of Apple's services and the ways they are quantified.
Note that three types of data are never encrypted from start to finish, even with advanced protection of activated data: iCloud mail, contacts and calendar. It is a compromise necessary to ensure that data can be used in third -party applications. Other mail / contact / calendar customers, in particular those you access with something other than your own Apple device, could not use this data if E2E was encrypted.
| Data type | Standard encryption | Advanced data protection |
|---|---|---|
| iCloud mail | In transit and server | In transit and server |
| Contacts | In transit and server | In transit and server |
| Calendars | In transit and server | In transit and server |
| ICloud backup (device and messages) | In transit and server | End -to -end |
| ICLOUD drive | In transit and server | End -to -end |
| Photos | In transit and server | End -to -end |
| Notes | In transit and server | End -to -end |
| Reminders | In transit and server | End -to -end |
| SAFARI SIGNS | In transit and server | End -to -end |
| Siri shortcuts | In transit and server | End -to -end |
| Memos vocaux | In transit and server | End -to -end |
| Pass wallet | In transit and server | End -to -end |
| Free form | In transit and server | End -to -end |
| Invitation to apple | In transit and server | *special |
| Passwords and keychain | End -to -end | End -to -end |
| Health data | End -to -end | End -to -end |
| Journal data | End -to -end | End -to -end |
| Home data | End -to -end | End -to -end |
| Messages in iCloud | End -to -end | End -to -end |
| Payment information | End -to -end | End -to -end |
| Apple card transactions | End -to -end | End -to -end |
| Cards | End -to -end | End -to -end |
| Quick keyboard vocab | End -to -end | End -to -end |
| Safari | End -to -end | End -to -end |
| Screen time | End -to -end | End -to -end |
| Siri information | End -to -end | End -to -end |
| Wi-fi passwords | End -to -end | End -to -end |
| W1 and H1 Bluetooth keys | End -to -end | End -to -end |
| Memoji | End -to -end | End -to -end |
Several services, such as messages and emails, have specific exceptions and warnings that you may want to be aware. You can find out more about them in this Apple support document.
Also note that some metadata is always stored with standard encryption. The backup of your device can be encrypted E2E, but Apple stores data such as the name, model, color and serial number using standard encryption, as well as the list of applications and file formats for each backup and date and time of backups.



