"Encrypted" has become a checkbox. Nearly every app that stores your files says it: your cloud drive, your notes app, your bank. The word does a lot of work in that sentence, and most of the time it does not mean what you assume.
There are two very different things a company can mean when it says your data is encrypted. Knowing which one you are getting is the whole game.
Encrypted, but they hold the key
Most services encrypt your files at rest and in transit. Your data is scrambled while it sits on their servers and while it travels to your device. That stops a thief who steals a hard drive and a snoop watching the network. It is real protection, and it is worth having.
But there is a catch. The company holds the keys. They scramble your files, and they can unscramble them whenever they need to, because their own systems have to read your files to index them for search, generate previews, scan content, answer a subpoena, or train a model. An employee with the right access can read them too. When a company can read your data, so can anyone who breaks into that company, and so can anyone who legally compels it.
Zero-knowledge: they hold nothing
Zero-knowledge encryption moves the key. Your files are encrypted on your device, with a key only you have, before they ever reach the company's servers. What lands on their side is a sealed box they cannot open. They store it, sync it, and back it up, and at no point can they read a single word of it.
The test is simple. If you forget your password, can the company show you your files again? A yes means they hold your key, and it is not zero-knowledge. If the answer is no, if losing your key means the data is genuinely gone even to them, that is the real thing. The inconvenience is the proof.
How to tell which one you are using
Ask a service these questions:
If I lose my password, can you recover my files? A yes means they hold your key.
Can you read my content to power search, previews, or recommendations? If a feature reads your files, the files are readable.
Where are my files encrypted, on my device or on your server? On-device is the answer you want.
Have you published how the encryption works, or had it audited? A vague answer is its own answer.
Most apps will not pass, and that is not always a scandal. A photo app that shows thumbnails has a reason to read your files. But your birth certificate, your tax returns, your will, and your passwords sit in a different category. For those, the right amount of access for a storage provider to have is none.
The difference that matters
"Encrypted" tells you a company locked the door. Zero-knowledge tells you they never kept a copy of the key. When the documents are the ones you cannot afford to have read, that is the only distinction worth caring about.
