Cryptee
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Cette fiche Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Estonian-incorporated zero-knowledge encrypted photos / notes / docs PWA (Cryptee, 2018, John Ozbay), bootstrapped, open source.
Cryptee propose un hébergement européen en Estonie, mais une maison mère ou un sous-traitant américain laisse une exposition matérielle au CLOUD Act. Référencé dans la catégorie Partage de fichiers.
Notes d’évaluation
Cryptee (Tallinn, Estonia; founded June 2018 by John Ozbay) is a 100% bootstrapped Progressive-Web-App for zero-knowledge encrypted notes, documents, journals, photos, and files: AES-256 client-side encryption before data leaves the device, fully open source for public audit, Estonia is outside the 14-Eyes intelligence-sharing arrangement, and no VC/PE involvement on the cap table; however the verified sub-processor list (2026-06) shows the primary host is Google Cloud (a US-owned hyperscaler), with Cloudflare, Stripe and Sentry also US, so CLOUD Act exposure is material on a structural reading, though client-side AES-256 encryption means Google stores only ciphertext and Cryptee holds no keys; EU-owned with open-source clients, and the privacy policy and terms are publicly readable at crypt.ee/privacy and crypt.ee/terms (the /help/* paths recorded in earlier audits were simply wrong), but there is still no DPA document anywhere on the public site, the key documentation gap for procurement buyers.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Cette fiche Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
Autre Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- 5 · 4 US
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Non
-
Sous-traitants divulgués: Oui
-
Clients open source: Non
-
Certification tierce: Non
Aller à
À propos de Cryptee
Cryptee is an Estonian-incorporated privacy-first Progressive Web App for encrypted photos, documents, notes, journal entries, files, and personal media, founded on 1 June 2018 by John Ozbay (a cybersecurity researcher, designer, and privacy activist based in Tallinn) and 100% bootstrapped with no outside investment. The product is engineered as a Google Photos / Google Docs / iCloud Photos / Evernote replacement for users who specifically want their cloud data to be unreadable to anyone except themselves: every document, note, photo, and file is encrypted client-side with AES-256 before it leaves the device, and Cryptee mathematically cannot read the content. The source code is open and publicly available for independent audit. Cryptee positions itself as particularly relevant for victims and survivors of domestic abuse, journalists and reporters, and activists: users whose threat model assumes the cloud provider could be coerced.
For an EU-sovereignty audit Cryptee is structurally exemplary. Estonia is an EU member with a long-standing reputation for digital infrastructure and e-Residency, and crucially Estonia is outside the Five-Eyes / Nine-Eyes / Fourteen-Eyes intelligence-sharing arrangements, a positioning argument the vendor makes explicitly. Combined with zero-knowledge encryption, AGPL-style code openness, and a bootstrapped cap table with no US capital, Cryptee delivers an exceptionally clean EU-owned, EU-hosted, no CLOUD Act exposure posture. Privacy advocacy partnerships include the Electronic Frontier Foundation (EFF) and Privacy International. As a small solo-led operation, Cryptee does not pursue formal ISO 27001 / SOC 2 attestations.
Pricing in EUR: Free tier (limited storage); €3/month (Plus); €9/month (Pro); €27/month (Studio); annual discounts available. No SSO, audit log, or on-prem options at this scale. Best fit: individual privacy-conscious users, journalists, activists, NGOs, and small teams whose threat model demands true zero-knowledge encryption and minimal regulatory surface area. Procurement-grade enterprise buyers with SSO/audit/compliance documentation needs should choose Proton Drive or Tresorit instead.
Carte des sous-traitants · 5
-
Cloudflare Portugal, Unipessoal Lda. USPortugal
CDN and security services
-
Google Ireland Ltd. (Google Cloud Platform) USIrlande
Cloud infrastructure / data storage and hosting (primary host)
-
Sentry Software Netherlands B.V. (Sentry.io) USPays-Bas
Error collection and reporting
-
Stripe.com USÉtats-Unis
Payment processing (subscriptions after 2021-02-21)
-
Paddle.com Market Ltd non-USRoyaume-Uni
Payment processing (subscriptions before 2021-02-21)
| Prestataire | Pays | Finalité | Propriétaire |
|---|---|---|---|
| Cloudflare Portugal, Unipessoal Lda. | Portugal | CDN and security services | US |
| Google Ireland Ltd. (Google Cloud Platform) | Irlande | Cloud infrastructure / data storage and hosting (primary host) | US |
| Sentry Software Netherlands B.V. (Sentry.io) | Pays-Bas | Error collection and reporting | US |
| Stripe.com | États-Unis | Payment processing (subscriptions after 2021-02-21) | US |
| Paddle.com Market Ltd | Royaume-Uni | Payment processing (subscriptions before 2021-02-21) | non-US |
Source : liste publiée des sous-traitants de l’éditeur, lue le 26 août 2026.
Référentiels & certifications · aucune répertoriée
Matrice de fonctionnalités
Tableau 2Fonctionnalités de Cryptee
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Suisse · 4 €/moisBasé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Suisse · 10 €/moisHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Suisse · 4 €/moisSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Non Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Basé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
4 €/mois |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
10 €/mois |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Non
Open source: Non
|
4 €/mois |