Store your media library on a cheap host — without it being able to read it
In short: "standard" online storage costs a fraction of a specialized cloud. The catch: by default, the host can read your files. The fix is client-side encryption — you encrypt each file with AES-256 before uploading, using a key that never leaves your devices. The host then only stores undecipherable blocks: you get the cheapest storage while staying completely private.
Last updated: June 2026.
The dilemma: low price or privacy
As films, series, music and photos pile up, storage quickly becomes a budget. Consumer solutions are convenient but expensive per terabyte, and above all the provider technically has access to your content. Conversely, "standard" space (file hosting, object storage) is very cheap — but we hesitate to put our media library there, fearing the host's gaze or a leak. For a long time it felt like a choice: cheap or private.
The fix: encrypt client-side, before uploading
Client-side encryption breaks that trade-off. The idea: each file is encrypted on your device, with a key that never leaves it, before being sent. The host only receives encrypted blocks, which it cannot read.
- You keep the key; it keeps only unreadable data.
- So you can use the cheapest space on the market without handing it your content in clear text.
Local, host or P2P: where to store?
With an encrypted approach, the storage location becomes a simple matter of cost and convenience:
- Locally (disk, NAS): fast, under your control.
- On a cheap standard host: large capacity, accessible everywhere, and always encrypted.
- Over P2P: spread across your own devices or those of people close to you.
In every case, the file stays encrypted: the location changes nothing about privacy.
How much it costs (ballpark)
Without quoting prices (they change), the order of magnitude says it all: "standard" storage often costs a few euros per terabyte per month — a fraction of a specialized cloud. By encrypting client-side, you capture that low price without paying its usual cost — the exposure of your data.
What to check
For the approach to hold up, make sure that:
- encryption is at rest and client-side (the file leaves already encrypted);
- the key never leaves your devices and is never sent to the host;
- the algorithm is strong (AES-256);
- your files stay readable only on your authorized devices.
Kofrio, built for this
Kofrio applies exactly this principle: it seals your media with AES-256 (dual validation TPM + VPS gatekeeper), then stores it wherever you want — local, standard host or P2P — always undecipherable to the host, readable only on your devices. You get the cheapest storage without sacrificing any privacy. Kofrio isn't launched yet: leave your email at kofrio.com to be notified.
Frequently asked questions
Is a "standard" host safe for my films?
As-is, no: it can read your files. But if you encrypt them client-side before uploading, it only stores unreadable data — it then becomes a simple storage space, safe by construction.
How is this different from the cloud's own encryption?
Most clouds encrypt server-side and hold the key: they can read your files. Client-side encryption keeps the key with you — the provider can never decrypt.
What if the host suffers a data breach?
Since your files are AES-256 encrypted, a breach only exposes gibberish, useless without your key.
Can I still play or stream my files?
Yes: decryption happens on the fly on your authorized devices, for local playback or streaming.
Do I need technical skills?
No. The whole point of a vault like Kofrio is to automate encryption and storage: you drop files in, the rest is handled.
Store your media library anywhere, without exposing anything. Leave your email at kofrio.com.