Where pCloud's Own Encryption Stops
pCloud has a better privacy story than most mainstream drives β a Swiss company, optional EU data residency, and a real client-side encryption product. The catch is how that product is packaged.
- π° Client-side encryption is a paid add-on β pCloud Crypto is sold separately from your storage plan, as a subscription or lifetime purchase.
- π Only the Crypto folder is covered β everything outside that one special folder is standard server-side encryption, with keys pCloud manages.
- π Regular folders are readable to pCloud β that's what enables thumbnails, media streaming and previews for ordinary files.
- π£ Account takeover reads everything ordinary β if your pCloud login is phished, every non-Crypto file is exposed. Ciphertext stays worthless without your key.
- π§Ύ Sensitive files rarely stay in one folder β scans, statements and exports scatter across a drive over time; an encryption layer you control can live wherever you point it.
What OurClone's Encrypted Vault Actually Does
OurClone's Encrypted Remote wraps your pCloud account in a password-only encryption layer β on a folder you choose, without a separate encryption subscription tied to the provider.
- π Encrypted before upload β files are encrypted on your computer; pCloud only ever receives ciphertext.
- π΅οΈ File names hidden too β names and contents are both encrypted; the vault folder in pCloud's web app shows only scrambled text.
- π Your password is the only key β it never leaves your device, and OurClone keeps no recovery copy.
- π§° Open format, not lock-in β built on rclone crypt, an open and documented standard that isn't tied to pCloud or to OurClone.
- π Any folder you pick β the vault lives where you decide; the rest of your pCloud stays untouched.
- βοΈ Behaves like a normal remote β transfer into it, sync it, mount it, or use it as a backup destination.
The Encrypted Remote is an OurClone Pro feature. One boundary: a vault always wraps a plain remote β you can't build a vault on top of another vault.
How to Create an Encrypted Vault on pCloud
From a fresh install to an encrypted first upload, this takes a few minutes.
- π Connect pCloud β Open OurClone and go to
Add. Select pCloud; a browser window opens to log in and authorize access. If pCloud is already connected for backups or transfers, skip ahead. - π§ Open the Encryption Category β In the
Addpage, the Encryption section sits above the provider grid. Click the Encrypted Remote card (marked Pro). - π οΈ Create the Vault β Name it (e.g.
pcloud-encrypted), pick your pCloud account as the base storage, then choose or create a folder inside it β the vault must live in a folder, not the drive root, and only that folder will hold encrypted data. Set your password (and an optional salt password for extra filename obfuscation), then click Create Encrypted Remote. - π¦ Move Files Into the Vault β Open
Migrate, choose a local folder (or another cloud) as the source and the vault as the destination, then run a copy, move, or sync. Files are encrypted on the fly as they upload. - π Watch It in the Task Center β The
Tasktab shows live progress, speed and any failed files, and history survives app restarts.
Before trusting the vault with anything important, save the password in a password manager β if it's lost, the data cannot be recovered by anyone.
Check What pCloud Can See Now
Open the pCloud web app or the pCloud Drive client and browse into your vault folder. The files carry scrambled names, thumbnails never render, and audio or video won't stream β pCloud is storing bytes it cannot interpret. That's the whole point.
In OurClone, the vault shows a lock badge, and the Manage page lists your real file names β decrypted locally on your machine. Mount the vault as a local drive if you prefer browsing in Finder or File Explorer (requires macFUSE on macOS or WinFsp on Windows).
Frequently Asked Questions
Is the encrypted vault free?
The vault is an OurClone Pro feature. Connecting pCloud, transfers and backups work on the free plan within its limits; see pricing.
How does this compare to pCloud Crypto?
Both encrypt on your device before upload. pCloud Crypto is a provider-specific add-on limited to its special folder; OurClone's vault uses the open rclone crypt format, works on any folder you pick β and the same approach carries over to Google Drive, Dropbox, S3 and every other remote you connect.
What if I forget the vault password?
The data is permanently unreadable. No reset exists β store the password in a password manager.
What is the salt password?
An optional second password that strengthens file-name obfuscation. If set, it's required alongside the main password to read the vault β guard both equally.
Can I keep using the rest of my pCloud normally?
Yes. Sync, sharing and streaming continue to work everywhere outside the vault folder β the vault claims only the folder you chose.
Can I open the vault from another computer?
Yes β install OurClone, connect the same pCloud account, and add an Encrypted Remote pointing at the same folder with the same password (and salt, if set).