Cloud Storage and Client Privacy

Online storage of your insurance agency's data makes syncing and sharing files convenient. It can also endanger your client's privacy.

A NextAgency Resource

Last Updated: June 25, 2026

Cloud storage software makes it easy to share files with clients and sync your insurance agency’s data across your office computer and other devices. But this software can expose your agency’s and your client’s data to companies seeking to monetize it. Here’s what you need to know to protect yourself and those who rely on you.

Synopsis:

Health insurance agencies have a legal and moral responsibility to keep their prospects and clients personal health information private. And most go to great lengths to do so. This article identifies a potential data leak insurance agencies too often overlook. To be fair, it’s a privacy leak that most people overlook: entrusting data to cloud storage software like Google Drive, Dropbox, Microsoft OneDrive, and iCloud. 

Cloud storage software, sometimes referred to as file syncing or file sharing software, are used by millions of consumers and businesses. They often choose a particular platform based on convenience and never consider the privacy implications. After all, some of these platforms are free. They come installed on their computer or phone. Yet life and health insurance agencies, because of their legal responsibility to protect their clients’ health and financial information, can’t afford to ignore the privacy consequences of their choice of software.

Insurance agencies that use an agency management system or CRM like NextAgency already benefit from a platform built to keep their data secure and private. NextAgency even enables you to securely share files you post to the platform. But NextAgency is built to help you make sales, provide service, and manage your insurance agency. For extensive file syncing and sharing of all your agency data, including files and documents you maintain outside of NextAgency, you need software built for that purpose.

This article explores the privacy trade-offs agencies unknowingly make and identifies practical, affordable cloud storage alternatives that handle sensitive client data without feeding corporate data gathering efforts.

Your Insurance Agency and Client Data is Valuable

We live in a world where privacy is increasingly rare. Our phones and cars disclose our locations nearly 24 x7. We invite devices that listen to what we say into our homes. These devices sometimes share what they hear with strangers and store on servers for corporate use. A February 2026 working paper from Bruegel — a respected Brussels-based economic think tank — estimated that personal data collection accounts for 20-30% of the combined net income of Google and Meta. Based on 2025 revenue figures that amounts to approximately $34-$50 billion per year. And that’s just from two companies.The FTC, in a 2025 “Issue Spotlight,” estimated that over $225 billion in revenue is generated by online behavioral advertising and the data ecosystem. It’s common knowledge in tech circles that if consumers aren’t paying for a product, they are the product.

Simply put: your personal information has real value.

Now think about the kind of information you have about prospects and clients. You possess information about their jobs, their income, their health history, perhaps their net worth and more along with their phone numbers, social security numbers, and contact information. This is information that brokers (both legal and illegal) highly value.

Absolute privacy is probably impossible in 2026. An insurance agency has a presence in its community. It has a web site and may be on social media. Complete privacy is an unrealistic goal for a functioning business. But privacy today is not about being invisible; it’s a question of surface area. The key is not 100% secrecy, but limiting what, where and how you expose information. The smaller your exposed surface area the less the stalker ecosystem sees. Every piece of data you deny them is a win, both for you and the clients who trust you with their information.

About Those Cloud Storage, File Sharing and File Syncing Platforms

Life and health insurance agencies are awash in data, much of it electronic. They have gigabytes, if not terabytes of information about prospects and clients, employers and employees, dependents, and sub-agents. Not only is it necessary for running an insurance agency, various laws and regulations require that insurance agencies store this data for years — even for clients they no longer work with. 

All this data is much easier to store digitally where it can be shared with clients and accessed by multiple devices. Cloud storage, file sharing, and file syncing software make this file management simple. Many of these platforms, like Google Drive, Microsoft OneDrive and Dropbox are free up to a point and come pre-installed on your desktop, laptop or phone. If you need more space than comes in their free package, they enable you to add additional storage at a low cost which is much less than yet another Steelcase file cabinet. And unlike physical file cabinets, you can share specific digital documents or folders with others over the internet. Storage and convenience at no or low cost. What’s not to like? (Well, we’ll get to that).

If you use an insurance agency management system or CRM like NextAgency some of your  agency’s data is stored in the cloud, securely and privately. NextAgency enables you to share files stored in NextAgency with clients and others. But NextAgency and the others are built to help you manage your business, track compensation, and to simplify selling and servicing your clients. And they can only protect and share the files you enter into your agency management system or CRM. Your agency has files and other documents stored locally. For most insurance agencies, this means using software that is built specifically to store files in the cloud and make sharing and syncing these files easy.

Google Drive, Microsoft OneDrive, Dropbox, and iCloud dominate the world of file sharing and storage. Most insurance agencies use one of these platforms. They are genuinely useful, easy to learn, deeply integrated into tools like email that insurance agencies already use, and they’re offered free or at greatly subsidized rates. The friction of switching feels high. The cost of staying feels low. And it’s just an online file cabinet that syncs with their local drive. The data is secured by promises from major companies. So it must be private, too, right? Well, maybe not. Let’s look at each of them.

Important Note: the following descriptions are authored by Claude AI which is more capable of researching these platforms than the author and actually “understanding” the implications of what it learned.

Google Drive: The Most Capable, The Least Private

Google Drive is the default for agencies using Gmail, Google Docs, or Android devices. It’s fast, collaborative, and deeply integrated with everything Google makes. It’s also the product of a company whose entire business model is built on understanding its users well enough to sell advertising against that understanding.

Google encrypts files in transit and at rest using AES-256 — the same standard banks use. But Google holds the encryption keys, which means Google can read your files. Significantly, as of 2025 and into 2026, Google’s Gemini AI has been integrated into Drive, Docs, Gmail, and Chrome. Gemini analyzes your documents for “contextual assistance” — summarizing files, answering questions about their contents, and learning from patterns across your account.

Users in the United States were opted into Gemini by default. Users in the European Union, UK, Japan, and Switzerland were opted out by default — a distinction that reflects how different jurisdictions treat user consent, and that should tell agencies something about whose interests the default settings serve.

Can agencies opt out? Technically, yes. In practice, Google has tied the Gemini opt-out to other useful features — disabling Gemini in Gmail also disables spellcheck, smart compose, and priority inbox sorting. Security researchers have called this a dark pattern, designed to make opting out costly enough that most users don’t bother. A class-action lawsuit filed in November 2025 — Thele v. Google LLC — alleges Google enabled these features without user consent.

The bottom line on Google Drive: Excellent product. Serious privacy trade-off. The AI integration makes the trade-off significantly worse in 2026 than it was two years ago.

Dropbox: Different Business Model, Similar Problems

Dropbox’s business model is subscriptions, not advertising — which means it doesn’t have Google’s incentive to profile users for ad targeting. That’s a meaningful distinction. But Dropbox’s privacy practices have generated controversy of their own.

In late 2023, Dropbox quietly enabled a setting that shared user files with OpenAI as part of its Dash AI product. Users discovered this when they noticed the toggle in their settings. Dropbox CEO Drew Houston apologized and clarified that the toggle enables AI features — but the episode revealed that Dropbox considers AI access to user files a default-on feature rather than something users explicitly choose.

Dropbox’s own privacy policy states it uses machine learning and AI to analyze how users interact with the service and to build models that identify keywords and topics from documents. This baseline analysis is not opt-outable; only the third-party sharing (to OpenAI) can be disabled.

The bottom line on Dropbox: Better than Google on privacy motivation, but not meaningfully better in practice. The AI is in your files either way.

Microsoft OneDrive: The Office Default With Mysterious AI

OneDrive comes with Microsoft 365, which means many agencies already have it without having deliberately chosen it. Microsoft’s enterprise security practices are strong, and Microsoft’s business model — like Dropbox’s — is subscriptions rather than advertising. But Microsoft has integrated Copilot AI across its entire product suite, including OneDrive, in a way that makes disabling it genuinely complicated.

Copilot in OneDrive can summarize documents, answer questions about file contents, and process up to 20 files simultaneously. There are documented reports of the Microsoft 365 mobile app automatically uploading local files for Copilot analysis before users open them. Disabling Copilot requires app-by-app action — there’s no single switch — and only administrators can disable it for OneDrive Business. Individual users on personal or family plans have less control.

When asked what happens to user data during Copilot processing, Microsoft has not provided a clear public answer.

The bottom line on OneDrive: The best of the mainstream incumbents for agencies already on Microsoft 365, but zero-knowledge encryption is not available and Copilot integration is persistent and difficult to disable.

iCloud Drive: Apple’s Better Privacy — With a Catch

Apple’s business model is hardware and services. Apple is not in the advertising business, and Apple has historically taken privacy more seriously than its competitors. iCloud Drive reflects this: Apple handles user data more carefully than Google or Dropbox, and doesn’t feed it into an ad-targeting machine.

But standard iCloud Drive is not zero-knowledge. Apple encrypts files and holds the encryption keys — meaning Apple can access your files and can be compelled to hand them over by law enforcement. Apple does offer a feature called Advanced Data Protection that upgrades iCloud to genuine zero-knowledge encryption. Most users have never heard of it and have never turned it on.

Apple has also integrated Apple Intelligence across its product suite. The opt-out here is the easiest of the four mainstream platforms: one toggle in Settings, no collateral damage to other features. Apple Intelligence also relies primarily on on-device processing, and when cloud processing is required, it uses Private Cloud Compute — an architecture that Apple has made independently verifiable by security researchers.

The meaningful gap for health insurance agencies: Apple does not offer a HIPAA Business Associate Agreement (BAA) for iCloud. Any agency that stores or shares Protected Health Information needs a signed BAA with its storage provider. Apple’s absence here is a disqualifying limitation for health agencies.

The bottom line on iCloud: Better than Google, Dropbox, and OneDrive on privacy philosophy. Zero-knowledge only with Advanced Data Protection enabled — most users never do this. No HIPAA BAA available.

There Are Alternatives for Life and Health Insurance Agencies

None of the mainstream platforms offer zero-knowledge encryption by default. Zero-knowledge means the file is encrypted on your device before it leaves — the provider never holds the decryption key and cannot read your files even if compelled to do so. No AI. No analysis. No building of profiles from your document contents.

Their lack of zero-knowledge encryption means the big four vendors and their employees can read your files. It means government agencies can obtain your files through legal process. And it means each vendor’s AI systems can analyze your files to improve their products.

There are alternatives. Three file sharing and storage platforms offer genuine zero-knowledge encryption: Tresorit, Proton Drive, and Sync.com. There is a trade-off, however. None of the three offer the collaborative document editing that Google Docs or Microsoft 365 provide. Agencies that co-edit documents in real time will still need one of the mainstream platforms for that specific function. The private alternatives work best as the place where sensitive files live and are shared — client records, commission statements, carrier contracts, benefits analyses — while collaborative drafting happens in a separate environment.

Here’s what you should know about these alternatives. Note: Again, these summaries are courtesy of Claude AI.

Tresorit: The Gold Standard for Regulated Industries

Tresorit was founded in Switzerland in 2011 and has spent over a decade building specifically for industries that can’t afford a data breach: healthcare, legal, financial services. NextAgency uses Tresorit for secure file storage.

Files are encrypted on your device before upload using AES-256 encryption. Tresorit never holds the decryption key. Even if Tresorit’s servers were compromised, the files would be unreadable. The company is headquartered in Switzerland, which operates under privacy laws that exceed GDPR standards and are outside US legal reach — meaning a US government subpoena cannot compel Tresorit to hand over file contents it cannot decrypt anyway.

Tresorit offers granular sharing controls: encrypted links with passwords, expiration dates, download limits, and viewer restrictions. It signs HIPAA Business Associate Agreements. It integrates with Microsoft Outlook and Teams for secure attachment handling.

The limitations are honest ones. Tresorit is the most expensive of the three private alternatives, with business plans starting at $24 per user per month. There is no real-time collaborative editing — Tresorit is a place to store and share files, not to write them together. Setup takes 15 to 30 minutes rather than the near-zero onboarding of Google Drive. The software is closed-source, which means users must trust Tresorit’s security claims rather than verify them independently.

For agencies in regulated industries handling sensitive health data, those limitations are acceptable. The combination of Swiss jurisdiction, zero-knowledge encryption, HIPAA BAA availability, and a fifteen-year clean security record makes Tresorit the strongest privacy option in the market.

Proton Drive: Privacy by Philosophy, Value by Design

Proton began in 2014 when a group of scientists who met at CERN built an encrypted email service because they were troubled by what they’d learned about surveillance. That origin story matters because it reflects how Proton builds products: privacy is the architecture, not a feature added on top.

Proton Drive offers zero-knowledge end-to-end encryption. Its client applications are open-source, which means independent security researchers can verify that the software does what Proton claims. It is headquartered in Switzerland. It explicitly states: no ads, no data harvesting, no AI training on your files.

Proton Drive has added real-time collaborative editing through Proton Docs and Proton Sheets — a capability that sets it apart from Tresorit and Sync.com, though the collaboration tools are still less mature than Google Docs. Proton is developing a software suite that matches against Google’s offerings: mail, calendar, cloud storage, meetings, password manager, a VPN, and  even an AI (Lumo). Some are offered for free; others are by subscriptions and those subscriptions often include multiple Proton offerings. Visit Proton’s website to see all their offerings and pricing to see why it is the strongest value of the three private alternatives if the agency is willing to migrate email as well.

Bottom line on Proton: HIPAA BAAs are available from Proton on all plans — notably more accessible than most competitors, who restrict BAA availability to higher-tier business plans. With their suite of platforms Proton is one of the more convenient ways to escape the ecosystem of the likes of Google.

Sync.com: The Most Accessible Entry Point

Sync.com is a Canadian company that has offered zero-knowledge encrypted cloud storage since 2011 — fifteen years without a documented data breach. It is the most affordable of the three private alternatives and, by most reviews, the easiest for non-technical users to set up and use.

Like Tresorit and Proton Drive, Sync.com encrypts files on the device before upload and never holds the decryption key. Unlike the other two, zero-knowledge encryption is included on every plan, including the free tier — a rare commitment that signals how central privacy is to the product’s identity. Canadian privacy laws are generally regarded as stronger than their U.S. equivalent, but not as robust as European or Swiss laws.

Sync.com integrates with Microsoft 365 for document editing. The interface is described as clean but somewhat dated — functional without being beautiful. They support online collaboration and include tools for drive backups. You can explore its services and pricing on at Sync.com.

Bottom line on Sync.com: A solid and affordable alternative for life and health insurance agencies looking for data privacy and that don’t need a lot of extras.


Comparing Your Insurance Agency’s Cloud-Based File Storage Options

Information verified June 2026. Confirm current information on their websites.

Dimension
Google Drive
Dropbox
OneDrive
iCloud Drive
Tresorit
Proton Drive
Sync.com
Setup Time0–5 min0–5 min0–5 min0–5 min15–30 min5–15 min5–15 min
Ease of UseExcellentExcellentVery GoodExcellent (Apple only)GoodVery GoodGood
Mobile AccessExcellentVery GoodGoodExcellent (iOS only)Very GoodVery GoodGood
CollaborationExcellentGoodVery GoodLimitedNoneLimitedNone
Zero-Knowledge EncryptionNoNoNoOnly with Advanced Data Protection enabledYesYesYes
Bank-Level SecurityNoNoNoOnly with Advanced Data Protection enabledYesYesYes
AI On Your FilesYes — Gemini, opt-out is cumbersomeYes — Dash/OpenAI; partial opt-out onlyYes — Copilot; app-by-app opt-outYes — Apple Intelligence; easy opt-out; on-device processingNoNoNo
HIPAA BAA AvailableYes (paid plans, requires configuration)Yes (business plans only)Yes (business plans, requires configuration)NoYesYes (all plans)Yes (paid plans)
JurisdictionUSUSUSUSSwitzerland — exceeds GDPR; outside US legal reachSwitzerland — exceeds GDPR; outside US legal reachCanada — stronger than US; Five Eyes member
ReliabilityExcellentExcellentExcellentExcellentExcellentVery GoodVery Good

The Most Vital Privacy Protection: Humans

The right tools only protect an agency’s data if they’re used correctly. A few practices that apply regardless of which platforms an agency chooses:

File sharing hygiene

Use encrypted links, not email attachments. When sharing sensitive documents with clients or carriers, emailed attachments are unprotected once they leave your outbox. Tresorit, Proton Drive, and Sync.com all support encrypted sharing links with passwords and expiration dates. Mainstream platforms support sharing links too, but without zero-knowledge encryption, the protection is incomplete.

Revoke access when someone leaves. A former employee with access to a shared folder full of client records is a liability. Every platform described in this article supports access revocation — but it only works if someone does it. Make it part of the offboarding checklist.

Everyone gets their own login. Shared credentials mean no audit trail, no accountability, and no clean way to revoke one person’s access without affecting everyone. Individual accounts for every team member is not optional — it’s basic security hygiene.

Know where your files actually live. Many agency owners can’t answer this question clearly: which files are on which device, which are in the cloud, and who has access to each. A ten-minute inventory — written down — is worth doing once and revisiting annually.

Privacy Is a Choice

Complete privacy in 2026 may not be achievable, but privacy is not binary. You can do something. You can choose how much data to entrust with whom and whether affordable alternatives exist with comparable functionality. In most cases, there is.

The tools described in this article — Tresorit, Proton Drive, and Sync.com for file sharing — are not fringe products. They are used by millions of individuals and hundreds of thousands of businesses globally, including healthcare practices, law firms, and financial services organizations that handle sensitive data under regulatory obligation. And NextAgency. They work. They’re affordable. The setup friction, measured honestly, is a few hours.

There is a choice insurance agencies need to make. Convenience and collaboration or privacy and data sovereignty. There was a time when they had no real choice but to use offerings from the corporate data machine. Today there is.

Learn More:
Additional resources for life and health insurance agencies on technology, marketing, running your agency, and more are available through the NextAgency Resource Center.
Author Information:

This article was written by Alan Katz, NextAgency co-founder, along with Claude AI, which did much of the research. AIs, and humans, make mistakes. Please confirm information before relying on it.