Skip to content
itzgee.com

Blog Self-hosting

Where does your data actually live?

Your photos, files and messages are stored somewhere. Three questions decide how much say you have, and most people get the same answer to all three.

Geeitzgee.comUpdated 28 Sept 20265 min read

Using services other people run is normal, and mostly fine. Almost everyone does it, most of it works well, and doing it yourself takes real effort. Nothing below argues against that.

But it helps to be clear about what the deal really is, because nobody spells it out. You aren’t buying storage. You’re leaving your things in someone else’s building, under rules they wrote and can rewrite, in a country you probably never thought to check.

The three questions

Take away the marketing and it comes down to these.

Where does it live? In the physical sense: which country, and whose laws. That isn’t a small detail. It decides who can legally demand your data, and what rights you have when something goes wrong. Most services will tell you if you look. Hardly anyone looks.

Who can get at it? Not just whether it’s encrypted (scrambled so only someone with the key can read it), but who holds the key. Which staff can open a support ticket and read your files. Which other companies were given a copy as part of running the service.

Who decides what happens next? The price, the storage limit, what you’re allowed to keep, whether the product still exists in two years. When the answer is “someone else”, any of those can change while you’re asleep.

the three questions

the usual deal

Where does it live?

Their buildings, in whichever countries they have picked.

Who can get at it?

Their staff, their systems, and anyone else they have given a copy to.

Who sets the rules?

They do, and they can change them while you are asleep.

running it yourself

Where does it live?

A machine you chose, in a country you chose.

Who can get at it?

The people you chose to let in. Nobody else.

Who sets the rules?

You do, and they do not change overnight.

The same three questions, asked of the usual deal and of running things yourself. The difference isn't that one is safe and the other isn't. It's who gets to answer.

What “taking custody” really means

It isn’t a rebellion, and it isn’t about distrusting everyone. It’s where you end up once you take those three questions seriously.

Your machine, your country, your rules on who gets in. That’s the heart of it. The rest is detail.

The word that matters is custody (being the one who looks after it), not secrecy. This has nothing to do with having something to hide. It’s about being the one who decides: the same instinct that keeps your passport in a drawer at home rather than in a friend’s loft, however much you trust the friend.

What you get

A location you chose. Not a region name in a settings menu, but a known building in a known country under known law. For a UK household that usually means keeping things in the UK, a choice you can only make if you decide where things go.

Access you give, not access that’s assumed. Everyone who can open something is someone you chose to let in. Nobody has a standing key because of their job at a company you’ve never dealt with.

Rules that stay put. The service you set up this year is the service you have next year. Nobody puts the price up, adds a new plan, stops supporting your file type, or quietly starts feeding your content into something you’d never have agreed to.

A way out that’s always open. The files are already yours, in ordinary formats, on hardware you control. There’s no download to finish before a deadline. Leaving is no longer a big event.

What it costs

An honest case has to include this part, because it’s the part that usually gets skipped.

You’re the one who fixes it now. Nobody else notices when a disk starts to fail. Nobody else is on call. If something breaks on a Sunday, it stays broken until you deal with it.

Backups become your job, and backups are the job people skip. A copy on the same machine isn’t a backup. A copy in the same building hardly counts either.

Some of the polish goes. Big providers have large teams making everything feel smooth. The self-hosted versions are often excellent, but sometimes a bit rough around the edges.

The decisions are yours, and you can’t hand them back. Where things live, who gets in, how long you keep them. That’s the whole point, and it’s also work.

Not all or nothing

The version of this that lasts isn’t “delete every account and run everything yourself”. It’s deciding, one thing at a time, which side of the line each thing belongs on.

Family photos, personal documents, your passwords, anything you’d be really upset to lose or to have a stranger read: those are worth taking custody of.

The video-call app your work makes you use, the map on your phone, the tool you open twice a year: probably not worth the bother.

Start with what you’d hate to lose. For most people that’s photos. They’re a good first step, because once it works the value is obvious.

If you want to see what self-hosted versions look like in practice, the apps we run cover the main types: photos, passwords, files, notes, bookmarks. Every one of them is an open-source project that anybody can run.

The question to think about

Not “is my data safe?”. Nobody can answer that one, and it’s mostly a marketing question anyway.

Ask instead: if this company changed its mind tomorrow, what could it do to me, and what could I do about it?

If the honest answers are “quite a lot” and “very little”, that gap is what this is all about. Taking custody is how you close it.

Written by

Gee

We run itzgee.com, a private cloud in daily use, on servers run by us. How it works has the full picture.