Nextcloud Encryption with Cryptomator: Adding a Personal Layer of Protection to Your Cloud

Fairooza

Desktop Interface
5 min read|24.02.2026

Most people assume their files are safe once they are stored in a private cloud. To a degree, that's true, especially when the hosting infrastructure is locked down, encrypted in transit, and managed under strict data protection laws.

But there's a gap between "safe on the server" and "unreadable by anyone except me." That gap is where Cryptomator fits in.

It encrypts your files locally, before they ever reach the server, so nobody can read them without your password. This guide walks you through how Nextcloud encryption with Cryptomator works and how to set it up on Windows and macOS.

Illustration of a laptop showing a Nextcloud interface with app icons

What Is Cryptomator and Why Does It Matter for Nextcloud?

Cryptomator is a free, open-source encryption tool built specifically for cloud storage. It has become one of the most trusted tools for client-side encryption across cloud platforms, including Nextcloud.

Files are encrypted locally on the user’s device before they ever reach the cloud. Both file contents and file names are protected using strong AES-based encryption. If someone were to look directly at your cloud storage, they would see nothing but unreadable, encrypted files with no way to identify what's inside.

Before You Start

Before setting up Cryptomator, you need a working Nextcloud sync connection on your device. Cryptomator operates on locally synchronized folders, so the Nextcloud desktop client must already be configured.

You will need:

  • The Nextcloud desktop client is installed and configured to sync at least one folder.
  • Cryptomator installed. Download it from cryptomator.org.

If you are a CloudBased Backup customer, you will have received your Nextcloud server credentials during onboarding. Just plug those into the desktop client and you are ready to go.

Cryptomator Nextcloud Setup on macOS

Download Cryptomator for macOS and install it by dragging the app into your Applications folder. You will get a license agreement on first launch. Accept it and move on.

Next, you will see an interface with a "+" icon in the bottom-left corner. Click that and hit "Create New Vault."

Creating a new Cryptomator vault on macOS

Cryptomator now asks you to name the vault. For example, we went with "Nextcloud-Vault". This name becomes the actual folder name inside your Nextcloud directory, so keep it simple. Click "Next."

Now here's the step that matters most. Cryptomator asks where it should save the encrypted files, and you need to point it to your Nextcloud sync folder.

Selecting the local Nextcloud sync folder as the Cryptomator vault location

Select "Custom location," click "Choose," and navigate to your local Nextcloud sync folder. Make sure you select the Nextcloud folder itself, not a subfolder inside it.

If you skip this or pick the wrong location, your encrypted files won't sync to Nextcloud. So double-check before you confirm and then click "Next".

After that, Cryptomator shows you a quick summary of what you've configured: vault name and where it's being stored.

Cryptomator vault stored inside the local Nextcloud sync folder on macOS

You will also notice an "Enable expert settings" checkbox. Leave that unchecked. The defaults are solid and work well for most setups. Click "Next".

Next up is the vault password. Pick a strong one. Don't reuse your Nextcloud login password here. This password is the only thing standing between your files and everyone else.

Cryptomator vault password and recovery key setup during Nextcloud encryption

Cryptomator then asks if you want a recovery key. Choose the option "Yes please, better safe than sorry", and then click "Create Vault".

You'll get a recovery key on screen.

This is your lifeline if you ever forget the vault password. Copy it and store it somewhere safe, like your password manager's secure notes. Just don't store it inside Nextcloud itself.

Once you’ve saved the recovery key, click “Next” to continue.

With everything set up, click "Unlock Now" and type in your password. After the vault unlocks successfully, click “Reveal Drive” when prompted. macOS might ask for a couple of permission approvals at this point. Grant them. Cryptomator will mount the vault as a virtual drive on your system.

Unlocked Cryptomator vault mounted as a drive in Finder

Your vault now shows up in Finder as a mounted drive, just like a USB stick. Whatever you drop in there gets encrypted automatically before it syncs to Nextcloud.

In the Nextcloud web interface, the files inside the vault are only available in encrypted form. This ensures that neither the hosting provider nor the server itself can read the contents of your data.

Encrypted Cryptomator vault files shown in the Nextcloud web interface

The trade-off is that decrypted files are not accessible through the Nextcloud web interface. To work with your documents, the vault must be unlocked locally using Cryptomator.

Cryptomator Nextcloud Setup on Windows

The overall setup process on Windows is the same as on macOS. You install Cryptomator, create a vault inside your local Nextcloud sync folder, set a password and recovery key, and unlock the vault to start working with your files.

The main difference on Windows is how the unlocked vault appears in the file system. After unlocking the vault, Cryptomator mounts it as a drive letter (for example, D: or E:) in File Explorer.

Cryptomator vault mounted as a drive letter in Windows File Explorer

This drive represents the decrypted view of your vault. Any files placed here are encrypted locally before being synced to Nextcloud.

The encrypted vault folder inside your Nextcloud directory, as well as the encrypted view shown in the Nextcloud web interface, behave the same way as on macOS.

Why the Cryptomator Recovery Key Matters

As covered in the setup steps above, Cryptomator lets you generate a recovery key when creating a vault. Many users skip this. Don't.

If both your vault password and recovery key are lost, the encrypted data is permanently unrecoverable. No hosting provider and no support team can help.

For business use, this is especially important. If a team member leaves and their vault password isn't documented, a recovery key may be the only way to access those files. Build recovery key storage into your onboarding and offboarding processes.

The Cloud Assistant That's Always One Step Ahead.

Our Blog

Cloud Insights: Trends, Tips & Technologies

Secure File Sharing for Business: How Companies Use Nextcloud for Collaboration
8 min read|27.03.2026

Secure File Sharing for Business: How Companies Use Nextcloud for Collaboration

Businesses share sensitive files such as contracts, financial records, customer data, and internal documents every day across teams, devices, and external partners. At the same time, the risks are also increasing. The average cost of a data breach in 2023 reached $4.45 million, and many incidents are linked to unsecured cloud-based file transfers. Even a simple mistake, like sending a file to the wrong recipient, can trigger a GDPR violation. Remote work and constant collaboration with client

What Is Nextcloud Used For?
6 min read|26.03.2026

What Is Nextcloud Used For?

Managing files, communicating with teams, and staying organized no longer requires juggling multiple platforms. Modern cloud solutions are built to handle it all in one place, and Nextcloud is one of the most capable examples of that shift. With over 400,000 deployments globally, it has grown into one of the most trusted private cloud solutions available today. This article will discuss what Nextcloud is, walk through its core use cases, and explain who it is built for, giving you a clear pictu

Can Nextcloud Logs Be Cleared?
6 min read|25.03.2026

Can Nextcloud Logs Be Cleared?

Managing a self-hosted cloud environment comes with its share of maintenance tasks, and keeping log files under control is one of them. Over time, Nextcloud logs can grow significantly, consuming disk space, slowing the admin interface, and making it harder to spot relevant errors.  This article will discuss what Nextcloud logs are and whether they can be cleared, where log files are located across different server setups, the distinct types of log files administrators should know, how to

Get in Touch with Our Cloud Experts

Chat with us
Chat

Chat with us

Our friendly team is here to help

Cbb logo
Secure real-time Cloud collaboration from Europe
CloudBased Backup empowers you with Managed Nextcloud, a secure, on-premise collaboration platform offering real-time document editing, seamless video chat, and groupware across mobile, desktop, and web.
Visit us on social media.
Subscribe to our newsletter.
Get exclusive offers and always stay up-to-date.

Reach out directly at

PEWEO SARL

5, Montée des Aulnes

L-6611 Wasserbillig

LU33030425

© 2026 CloudBased Backup. All rights reserved.