The app and the account each play a part
The recovery copy uses AES-256-GCM encryption on the device. The key stays on the device and also has copies in iCloud Keychain and an encrypted CloudKit field. The provider cannot access the private CloudKit database.
Avoid an absolute promise
With Standard Data Protection, Apple holds CloudKit service keys. Eligible encrypted CloudKit fields gain end-to-end protection with Advanced Data Protection. iCloud Keychain is separately end-to-end encrypted. Some backup metadata remains outside end-to-end protection.
Review your recovery choices
Use Apple’s current setup guidance to review account protection and recovery requirements. Availability can differ by account and region. Keep an appropriate recovery method and inspect a successful Coldbore recovery point.
Reviewed October 2, 2026.
Sources Coldbore on the App Store · Apple iCloud data security overview · Apple Advanced Data Protection setup