Dropbox: How to opt out of 3rd party AI partner access to your Dropbox
Dropbox has introduced AI-powered features that send user files to third‑party partners like OpenAI for processing, controlled by a setting that is on by default for many paid and business accounts, especially outside the EU. Commenters are alarmed that a storage service would enable this without explicit opt‑in, questioning whether users can meaningfully consent, whether the toggle can be trusted, and how this squares with privacy laws and expectations. Many highlight regional differences in defaults, point to the risk of future model‑training uses, and suggest moving to end‑to‑end encrypted or self‑hosted alternatives as a safer long‑term approach.
Feature behavior & rollout
- New setting controls whether Dropbox can send file contents to “third-party AI partners” to power Dropbox AI features.
- Text says data is used only for inference when users invoke AI features (e.g., “ask a question about a file”), not for training, and is deleted within 30 days.
- Currently, the only listed AI partner is OpenAI.
Opt-out vs opt-in and legality
- Many users object that the setting is enabled by default in some regions/accounts, calling it a dark pattern and arguing it should be explicit opt-in.
- Several note that EU/EEA users often see the toggle off by default or not present, and view this as a consequence of stricter privacy regulation.
- Some argue such default-on data repurposing should be illegal generally, not just constrained by EU rules.
Account types, regions, and inconsistencies
- Reports vary:
- Paid US and Canadian business/personal accounts often had it on by default.
- Some EU/UK accounts show it present but off; others don’t see it at all.
- Free accounts often lack the setting; unclear whether that’s because AI features aren’t available or because there’s no opt-out.
- Team/admin console has a separate control that can affect the whole organization.
User experience and trust
- Users are frustrated that a storage service quietly expanded data use to AI partners.
- Some recall past Dropbox missteps (permissions changes, throttling, auth bugs, file scanning) and see this as a pattern, prompting account deletions.
- Others view outrage as overblown given that data is only sent when AI features are explicitly used.
Alternatives and mitigation
- Suggestions: end-to-end–encrypted or privacy-focused services (e.g., Mega, Proton Drive, Sync.com, Skiff, filen.io), self-hosted NAS, rsync/syncthing, or encrypted overlays like Cryptomator.
- Several emphasize encrypting files client-side before any cloud upload so third-party AI access becomes moot.
Broader reflections
- Debate over whether convenience features like AI search justify non-E2E designs.
- Some argue this episode proves general-purpose cloud storage without E2E encryption is inherently untrustworthy.