Where does your data actually live?
Your photos, files and messages are somewhere. Three questions decide how much say you have — and most people get the same answer to all three.
There is nothing wrong with using services other people run. Almost everybody does, most of it works well, and the alternative takes effort.
But it is worth knowing what the arrangement actually is, because it is rarely described plainly. You are not buying storage. You are placing your things in somebody else’s building, under terms they wrote and can rewrite, in a country you probably never checked.
The three questions
Strip away the marketing and everything comes down to these.
Where does it live? Physically. Which country, under whose laws. This is not a technicality — it determines who can compel access to it, and what rights you have if something goes wrong. Most services will tell you if you go looking. Most people never look.
Who can reach it? Not just “is it encrypted”, but who holds the key, which staff can open a support ticket and see your files, and which other companies have been handed a copy as part of running the service.
Who decides what happens next? Pricing, storage limits, what is allowed, whether the product exists in two years. If the answer is “somebody else”, then every one of those can change while you are asleep.
the usual arrangement
Where does it live?
Their buildings, in whichever countries they have chosen.
Who can reach it?
Their staff, their systems, and whoever else they have handed a copy to.
Who sets the rules?
They do — and they can change them while you are asleep.
running it yourself
Where does it live?
A machine you chose, in a country you chose.
Who can reach it?
The people you deliberately granted access to. Nobody else has standing.
Who sets the rules?
You do — and they do not change overnight.
What “taking custody” actually means
It is not a rebellion and it is not about distrusting everybody. It is the straightforward conclusion of taking those three questions seriously.
Your machine. Your country. Your access rules. That is the whole idea, and everything else is detail.
The important word is custody, not secrecy. This is not about having something to hide. It is about being the person who decides — the same instinct that has you keep your passport in a drawer at home rather than in a friend’s loft, however trustworthy the friend.
What you actually get
A physical location you chose. Not a region name in a settings page, but a known building in a known country under known law. For a UK household that usually means keeping things in the UK, which is a decision you can only make if you are the one placing them.
Access that is granted rather than assumed. Every person who can open a thing is somebody you deliberately let in. Nobody has standing access because of a job title at a company you have never dealt with.
Rules that stop changing without you. The service you set up this year is the service you have next year. Nobody reprices it, adds a tier, decides your file type is no longer supported, or quietly starts using your content for something you would not have agreed to.
An exit that always exists. Because the files are already yours, in ordinary formats, on hardware you control. There is no export process to complete before a deadline. Leaving is just… not a thing that has to happen.
What it costs
Being honest about this matters more than the pitch.
You become the person who fixes it. Nobody else notices when a disk fails. Nobody else is on call. If a thing breaks on a Sunday, it is broken until you deal with it.
Backups become your job, and it is the job people skip. A copy on the same machine is not a backup. A copy in the same building is not really a backup either.
Some polish disappears. Big providers have enormous teams making things smooth. Self-hosted equivalents are often excellent and occasionally rough.
You cannot outsource the decisions. Where things live, who gets access, how long you keep them — all yours now. That is the entire point, and it is also work.
Not all or nothing
The version of this that actually sticks is not “delete every account and run everything yourself”. It is deciding, thing by thing, which side of the line each belongs on.
Family photos, personal documents, the password vault, anything you would find genuinely upsetting to lose or to have read — those are worth custody.
The video call app your work uses, the map on your phone, the thing you use twice a year — probably not worth the trouble.
Start with what you would hate to lose. That is almost always photos, and it is a good first move because the value is obvious the moment it works.
If you want to see what the self-hosted versions of these things look like in practice, the applications we run is a reasonable tour of the categories — photos, passwords, files, notes, bookmarks. All of them are open-source projects anybody can run.
The question worth sitting with
Not “is my data safe” — that is unanswerable and mostly a marketing question.
Ask instead: if this company changed its mind tomorrow, what could it do to me, and what could I do about it?
If the honest answer is “quite a lot” and “very little”, that is the gap. Custody is how you close it.