Skip to content

Cryptee

File sharing · Estonia
Founded 2018 · crypt.ee

Estonian-incorporated zero-knowledge encrypted photos / notes / docs PWA (Cryptee, 2018, John Ozbay), bootstrapped, open source.

Cryptee offers EU hosting in Estonia, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under File sharing.

Assessment notes

Cryptee (Tallinn, Estonia; founded June 2018 by John Ozbay) is a 100% bootstrapped Progressive-Web-App for zero-knowledge encrypted notes, documents, journals, photos, and files: AES-256 client-side encryption before data leaves the device, fully open source for public audit, Estonia is outside the 14-Eyes intelligence-sharing arrangement, and no VC/PE involvement on the cap table; however the verified sub-processor list (2026-06) shows the primary host is Google Cloud (a US-owned hyperscaler), with Cloudflare, Stripe and Sentry also US, so CLOUD Act exposure is material on a structural reading, though client-side AES-256 encryption means Google stores only ciphertext and Cryptee holds no keys; EU-owned with open-source clients, and the privacy policy and terms are publicly readable at crypt.ee/privacy and crypt.ee/terms (the /help/* paths recorded in earlier audits were simply wrong), but there is still no DPA document anywhere on the public site, the key documentation gap for procurement buyers.

Findings

CLOUD Act
Ownership
Sub-processors
5 · 4 US

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: No
Transparency
  • Public DPA: No
  • Sub-processors disclosed: Yes
  • Open-source clients: No
  • Third-party certification: No
Jump to

About Cryptee

Cryptee is an Estonian-incorporated privacy-first Progressive Web App for encrypted photos, documents, notes, journal entries, files, and personal media, founded on 1 June 2018 by John Ozbay (a cybersecurity researcher, designer, and privacy activist based in Tallinn) and 100% bootstrapped with no outside investment. The product is engineered as a Google Photos / Google Docs / iCloud Photos / Evernote replacement for users who specifically want their cloud data to be unreadable to anyone except themselves: every document, note, photo, and file is encrypted client-side with AES-256 before it leaves the device, and Cryptee mathematically cannot read the content. The source code is open and publicly available for independent audit. Cryptee positions itself as particularly relevant for victims and survivors of domestic abuse, journalists and reporters, and activists: users whose threat model assumes the cloud provider could be coerced.

For an EU-sovereignty audit Cryptee is structurally exemplary. Estonia is an EU member with a long-standing reputation for digital infrastructure and e-Residency, and crucially Estonia is outside the Five-Eyes / Nine-Eyes / Fourteen-Eyes intelligence-sharing arrangements, a positioning argument the vendor makes explicitly. Combined with zero-knowledge encryption, AGPL-style code openness, and a bootstrapped cap table with no US capital, Cryptee delivers an exceptionally clean EU-owned, EU-hosted, no CLOUD Act exposure posture. Privacy advocacy partnerships include the Electronic Frontier Foundation (EFF) and Privacy International. As a small solo-led operation, Cryptee does not pursue formal ISO 27001 / SOC 2 attestations.

Pricing in EUR: Free tier (limited storage); €3/month (Plus); €9/month (Pro); €27/month (Studio); annual discounts available. No SSO, audit log, or on-prem options at this scale. Best fit: individual privacy-conscious users, journalists, activists, NGOs, and small teams whose threat model demands true zero-knowledge encryption and minimal regulatory surface area. Procurement-grade enterprise buyers with SSO/audit/compliance documentation needs should choose Proton Drive or Tresorit instead.

Sub-processor map · 5

Source
  • Cloudflare Portugal, Unipessoal Lda. US
    Portugal

    CDN and security services

  • Google Ireland Ltd. (Google Cloud Platform) US
    Ireland

    Cloud infrastructure / data storage and hosting (primary host)

  • Sentry Software Netherlands B.V. (Sentry.io) US
    Netherlands

    Error collection and reporting

  • Stripe.com US
    United States

    Payment processing (subscriptions after 2021-02-21)

  • Paddle.com Market Ltd non-US
    United Kingdom

    Payment processing (subscriptions before 2021-02-21)

Source: the vendor’s published sub-processor list, read 26 Aug 2026.

4 of 5 sub-processors are US-owned or US-based. CLOUD Act exposure applies.

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-08-26).

Capability matrix

Table 2Capabilities of Cryptee

Free storage 0.1 GB
Paid storage (from) 10 GB
Photo sync No
Link sharing Yes
Platforms iOS Android Web

Integration & access

REST API No
SSO (SAML / OIDC) No

Compliance & governance

Audit log No
Self-host / on-prem option No

Pricing & tiers

from €3/mo
Freemium
View pricing page

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement. This is recorded as no public DPA (see How we assess).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    crypt.ee/privacy…
    Open
  • Terms of Service
    crypt.ee/terms…
    Open

Alternatives in this category

  • Switzerland · €4/mo
    EU-Based
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Switzerland · €10/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Switzerland · €4/mo
    EU-Sovereign
    Public DPA: Yes Sub-processors: No Open source: No

Featured in these guides