Dropbox's AI features send your documents to OpenAI's servers, where they sit for up to 30 days. The AI settings are buried in account preferences and contradict each other across different pages. Amazon CTO Werner Vogels publicly warned people to check their Dropbox AI settings. When a Big Tech CTO tells you to check the settings on a competitor's product, something has gone wrong. Dropbox encrypts your files — but keeps the encryption keys. They comply with government requests about 75% of the time. Compare that to Proton Drive or Tresorit, where the company literally cannot read your files because they don't hold the keys. Dropbox's encryption protects your files from hackers. It does not protect your files from Dropbox.
What they claim: Dropbox leadership is committed to privacy.
What we found: Board member Condoleezza Rice: former NSA warrantless wiretapping advocate. 'Drop Dropbox' campaign (2014). Surveillance supporter overseeing file storage.
What they claim: AI features respect privacy and require consent.
What we found: Settings hidden. Default state varied (opt-in for some, opt-out for others). FAQ self-contradictory on OpenAI training. Documents on OpenAI servers 30 days. Amazon CTO warned users. Schneier: 'could tomorrow with a ToS change.'
What they claim: Dropbox securely stores files with encryption.
What we found: AES-256 but holds keys. Not zero-knowledge. US jurisdiction (Five Eyes). ~75% govt compliance. No consumer client-side encryption.
What they claim: Integrations enhance productivity while protecting data.
What we found: 300K+ integrations. OpenAI: documents leave Dropbox, on third-party servers. Integration permissions broad, hard to audit.