Myths Busted: Real Companies Where \"Encrypted\" Still Meant the Company Could Read It
· 4 min read
You've probably seen the headline before: "Your data is encrypted — totally private!"
It sounds reassuring. But as we've watched the news over the past few years, that promise has been tested — and sometimes broken — in very public ways. The myth isn't just theoretical. Real companies, real users, and real headlines have shown what happens when encryption keys stay with the provider instead of with you.
Here at TreeNotes, we've always believed privacy isn't something you hope for — it's something you design from the roots up. So let's look at a few recent stories that prove why the difference between "encrypted" and truly private matters.
Telegram: The default that wasn't default
Millions of people switched to Telegram thinking "encrypted messaging" meant no one could see their chats. But here's the catch that security experts have been pointing out for years (and still are in 2026): regular chats and every group conversation use server-side encryption. Only special "Secret Chats" (which you have to turn on manually, one-on-one) use true end-to-end encryption.
That means Telegram's servers can read, store, and — if legally required — hand over the content of most conversations. Founder Pavel Durov has faced legal pressure precisely because the company can access that data. It's a perfect example of the myth in action: the padlock is there, but the company quietly holds a spare key.
Apple iCloud: When governments came knocking
In 2025, the UK government issued secret orders demanding Apple create a backdoor into encrypted iCloud backups. Apple's response? They removed their strongest privacy feature — Advanced Data Protection — for UK users entirely.
Without that feature, standard iCloud (photos, notes, backups, documents) uses server-side encryption. Apple controls the keys. That means the company can access your data — and, under legal pressure, may have no choice but to comply. The result: millions of everyday users suddenly lost the option for real privacy, all because the keys weren't in their hands. Your late-night journal entry or family photos? Not as locked as you thought.
Zoom: The claim that led to court
Back in 2020 (but the lesson still echoes), Zoom heavily advertised "end-to-end encryption." The FTC disagreed — and won. Turns out Zoom's servers held the keys, so the company could theoretically decrypt and view meetings. They settled the case and had to stop making those misleading claims.
People were discussing health issues, business strategies, even therapy sessions under a false sense of total privacy. The encryption was there… but it wasn't theirs.
The pattern: Who holds the keys?
These aren't isolated glitches. They're what happens when a company keeps control of the keys. Breaches, government demands, or even internal access — your data becomes readable the moment the provider decides (or is forced) to unlock it.
At TreeNotes, we took a different path from day one.
Your notes are encrypted on your device before they ever leave it. The keys are created from your password and never touch our servers. We literally cannot open them — not for support, not for debugging, not even if someone shows up with a warrant. It's the same principle we've always stood for: true client-side, zero-knowledge encryption.
Think of it like planting a seed in your own garden. The tree that grows — every branch of your thoughts, every private reflection — stays protected by roots only you control. No one else gets to walk through and read the leaves.
So next time you see an app promising "encrypted notes" or "secure messaging," ask the important follow-up: Who holds the keys?
Your thoughts deserve real protection. Start free on TreeNotes—client-side encrypted from day one.