NextCloud

nextcloud.com
NextCloud

Feature-rich productivity platform, that can be used to backup and selectively sync encrypted files and folders between 1 or more clients. A key benefit the wide range of plug-ins in the NextCloud App Store, maintained by the community. NextCloud was a hard fork off OwnCloud.

Open Source

NextCloud Privacy Policy

Privacy Policy Summary

  • The terms for this service are translated into different languages
  • Only necessary user logs are kept by the service to ensure quality
  • User logs are deleted after a finite period of time
  • The service provides details about what kinds of personal information they collect
  • The service provides information about how they collect personal data
  • The service provides information about how they intend to use your personal data
  • IP addresses of website visitors are not tracked
  • The forum of this service is only available to users over 10 years of age
  • Users can access most of the pages on the service's website without revealing any personal information
  • This service respects your browser's Do Not Track (DNT) headers
  • This service tracks which web page referred you to it
  • The service does not share user information with third parties
  • Third parties are involved in operating the service
  • The service does not use third-party analytics or tracking platforms
  • Tracking cookies refused will not limit your ability to use the service
  • This service gives your personal data to third parties involved in its operation
  • The services will notify users if personal data has been affected by data breaches
  • This service reserves the right to disclose your personal information without notifying you
  • The service may change its terms at any time, but the user will receive notification of the changes.
  • Users who have been permanently banned from this service are not allowed to re-register under a new account
  • Prohibits political discussions or campaigning
  • You have the right to leave this service at any time
  • You are responsible for maintaining the security of your account and for the activities on your account
  • Content is published under a free license instead of a bilateral one
  • Users agree not to use the service for illegal purposes
  • Spidering, crawling, or accessing the site through any automated means is not allowed
  • Users can scrape the site, as long as it doesn't impact the server too much
  • Features of the website are made available under a free software license
  • The service informs you that its privacy policy does not apply to third party websites
  • There is a date of the last update of the agreements
  • You are warned of the potential consequences related to third-party access
  • Third parties used by the service are bound by confidentiality obligations
  • A complaint mechanism is provided for the handling of personal data
  • Your personal data is aggregated into statistics
  • You can opt out of promotional communications
  • Your personal data is not sold
  • The user is informed about security practices

Score

B

Documents

  • Privacy
    Created 13 Sept 18, Last modified 5 years ago

About the Data

This data is kindly provided by tosdr.org. Read full report at: #707

NextCloud Source Code

Author

nextcloud

Description

☁️ Nextcloud server, a safe home for all your data

#cloud#collaboration#decentralized#design#distributed#enterprise#federation#file-sharing#free-software#hacktoberfest#javascript#nextcloud#open-source#opensource#owncloud#php#self-hosting#sharing#usability#ux

Homepage

https://nextcloud.com

License

AGPL-3.0

Created

02 Jun 16

Last Updated

12 Jul 26

Latest version

v34.0.1

Primary Language

PHP

Size

6,752,116 KB

Stars

36,109

Forks

5,072

Watchers

36,109

Language Usage

Language Usage

Star History

Star History

Top Contributors

Recent Commits

  • Andy Scherzinger (12 Jul 26)

    Merge pull request #61988 from nextcloud/dependabot/npm_and_yarn/vitest-bf40b4329c chore(deps-dev): bump the vitest group across 2 directories with 2 updates

  • dependabot[bot] (11 Jul 26)

    chore(deps-dev): bump the vitest group across 2 directories with 2 updates Bumps the vitest group with 1 update in the / directory: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8). Bumps the vitest group with 1 update in the /build/frontend-legacy directory: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8). Updates `@vitest/coverage-v8` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8) Updates `vitest` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest) Updates `@vitest/coverage-v8` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8) Updates `vitest` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest) --- updated-dependencies: - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vitest - dependency-name: vitest dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vitest - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vitest - dependency-name: vitest dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vitest ... Signed-off-by: dependabot[bot] <[email protected]>

  • Nextcloud bot (12 Jul 26)

    fix(l10n): Update translations from Transifex Signed-off-by: Nextcloud bot <[email protected]>

  • Andy Scherzinger (11 Jul 26)

    Merge pull request #61990 from nextcloud/dependabot/npm_and_yarn/build/frontend-legacy/query-string-9.4.1 chore(deps): bump query-string from 9.3.1 to 9.4.1 in /build/frontend-legacy

  • nextcloud-command (11 Jul 26)

    chore(assets): Recompile assets Signed-off-by: nextcloud-command <[email protected]>

  • dependabot[bot] (11 Jul 26)

    chore(deps): bump query-string in /build/frontend-legacy Bumps [query-string](https://github.com/sindresorhus/query-string) from 9.3.1 to 9.4.1. - [Release notes](https://github.com/sindresorhus/query-string/releases) - [Commits](https://github.com/sindresorhus/query-string/compare/v9.3.1...v9.4.1) --- updated-dependencies: - dependency-name: query-string dependency-version: 9.4.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>

  • Andy Scherzinger (11 Jul 26)

    Merge pull request #61989 from nextcloud/dependabot/npm_and_yarn/p-queue-9.3.1 chore(deps): bump p-queue from 9.3.0 to 9.3.1

  • nextcloud-command (11 Jul 26)

    chore(assets): Recompile assets Signed-off-by: nextcloud-command <[email protected]>

  • dependabot[bot] (11 Jul 26)

    chore(deps): bump p-queue from 9.3.0 to 9.3.1 Bumps [p-queue](https://github.com/sindresorhus/p-queue) from 9.3.0 to 9.3.1. - [Release notes](https://github.com/sindresorhus/p-queue/releases) - [Commits](https://github.com/sindresorhus/p-queue/compare/v9.3.0...v9.3.1) --- updated-dependencies: - dependency-name: p-queue dependency-version: 9.3.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>

  • Andy Scherzinger (11 Jul 26)

    Merge pull request #62025 from nextcloud/dependabot/npm_and_yarn/build/frontend-legacy/ws-8.21.0 chore(deps-dev): bump ws from 8.18.3 to 8.21.0 in /build/frontend-legacy

  • github-actions[bot] (11 Jul 26)

    Merge pull request #61986 from nextcloud/dependabot/composer/vendor-bin/rector/rector/rector-2.5.5 chore(deps-dev): bump rector/rector from 2.5.2 to 2.5.5 in /vendor-bin/rector

  • dependabot[bot] (11 Jul 26)

    chore(deps-dev): bump ws from 8.18.3 to 8.21.0 in /build/frontend-legacy Bumps [ws](https://github.com/websockets/ws) from 8.18.3 to 8.21.0. - [Release notes](https://github.com/websockets/ws/releases) - [Commits](https://github.com/websockets/ws/compare/8.18.3...8.21.0) --- updated-dependencies: - dependency-name: ws dependency-version: 8.21.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]>

  • Andy Scherzinger (11 Jul 26)

    Merge pull request #61991 from nextcloud/dependabot/npm_and_yarn/build/frontend-legacy/sass-1.101.0 chore(deps-dev): bump sass from 1.100.0 to 1.101.0 in /build/frontend-legacy

  • Andy Scherzinger (11 Jul 26)

    Merge pull request #62019 from nextcloud/automated/noid/master-update-code-signing-crl [master] fix(security): Update code signing revocation list

  • nextcloud-command (11 Jul 26)

    fix(security): Update code signing revocation list Signed-off-by: GitHub <[email protected]>

  • dependabot[bot] (11 Jul 26)

    chore(deps-dev): bump sass in /build/frontend-legacy Bumps [sass](https://github.com/sass/dart-sass) from 1.100.0 to 1.101.0. - [Release notes](https://github.com/sass/dart-sass/releases) - [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md) - [Commits](https://github.com/sass/dart-sass/compare/1.100.0...1.101.0) --- updated-dependencies: - dependency-name: sass dependency-version: 1.101.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>

  • dependabot[bot] (11 Jul 26)

    chore(deps-dev): bump rector/rector in /vendor-bin/rector Bumps [rector/rector](https://github.com/rectorphp/rector) from 2.5.2 to 2.5.5. - [Release notes](https://github.com/rectorphp/rector/releases) - [Commits](https://github.com/rectorphp/rector/compare/2.5.2...2.5.5) --- updated-dependencies: - dependency-name: rector/rector dependency-version: 2.5.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>

  • Nextcloud bot (11 Jul 26)

    fix(l10n): Update translations from Transifex Signed-off-by: Nextcloud bot <[email protected]>

  • Benjamin Gaussorgues (10 Jul 26)

    Merge pull request #61944 from nextcloud/chore/cleanup-login-tokens feat(login): clean remember me tokens

  • Christoph Wurst (10 Jul 26)

    Merge pull request #59539 from nextcloud/fix/noid/s3-mtime-debug fix(files_external): S3 folder mtime updated on every read-only access

  • Benjamin Gaussorgues (10 Jul 26)

    Merge pull request #61917 from nextcloud/bug/noid/catch-exception fix: Catch expected NotFoundException

  • Carl Schwan (10 Jul 26)

    Merge pull request #61941 from nextcloud/feat/search-loading-controller feat(core): add unified search loading controller

  • Nextcloud bot (10 Jul 26)

    fix(l10n): Update translations from Transifex Signed-off-by: Nextcloud bot <[email protected]>

  • Kate (09 Jul 26)

    Merge pull request #61938 from nextcloud/refactor/interaction/allow-multiple-resources-and-receivers refactor(Interaction): Allow multiple resources and receivers in a single event

  • Daniel (09 Jul 26)

    Merge pull request #56533 from nextcloud/bug/56532/display-in-users-list Show group display name when the group object is not loaded yet

  • Maksim Sukharev (22 May 26)

    fix(AmazonS3): handle missing LastModified and ETag in S3 responses Add null-safety checks to handle S3 responses that don't include LastModified and ETag fields. This prevents 'Undefined array key' warnings and deprecation notices when processing directory metadata or incomplete S3 responses. - objectToMetaData(): Check if LastModified/ETag exist before accessing - getMetaData(): Check if LastModified exists before using in strtotime() Fixes test failures in testStat where hasUpdated('/', time) would fail when encountering S3 objects without complete metadata. Assisted-by: ClaudeCode:claude-sonnet-4-6 Signed-off-by: Maksim Sukharev <[email protected]>

  • Maksim Sukharev (22 May 26)

    fix(View#getCacheEntry): skip propagation when storage metadata is unchanged Storage backends like AmazonS3 whose hasUpdated() always returns true (S3 has no cheap global change-detection mechanism) caused propagateChange() to be called on every watcher->update() after a folder was browsed, even when the underlying storage_mtime and etag were identical to the cached values. Before the fix, getCacheEntry() would call watcher->update() and then unconditionally call propagateChange() whenever the watcher reported a change. For S3 directories this meant every read bumped the parent mtime chain. After the fix, getCacheEntry() snapshots the cache entry before watcher->update() and compares it with the entry after. propagateChange() is only invoked when at least one metadata field (mtime, storage_mtime, size, or etag) actually changed. Assisted-by: ClaudeCode:claude-sonnet-4-6 Signed-off-by: Maksim Sukharev <[email protected]>

  • Maksim Sukharev (22 May 26)

    fix(AmazonS3#getMetaData): preserve storage_mtime after parent clobbers it Common::getMetaData (Common.php:667) always sets storage_mtime = mtime before returning. For S3 virtual directories this is wrong: mtime can be bumped by child propagation while storage_mtime should remain the actual last S3 change. When the scanner later calls getMetaData() it compares data['storage_mtime'] against cacheData['storage_mtime']. If they differ it writes the value back, triggering View::getCacheEntry to fire propagateChange on every read even when nothing on S3 changed. Override getMetaData() to restore storage_mtime from the live cache entry (or, for non-root directories not yet in the cache, from the S3 directory marker LastModified header) after the parent call. Assisted-by: ClaudeCode:claude-sonnet-4-6 Signed-off-by: Maksim Sukharev <[email protected]>

  • Maksim Sukharev (22 May 26)

    fix(AmazonS3#getDirectoryMetaData): map root path to filecache key normalizePath('') returns '.' for S3 object keys, but the filecache stores the storage root under the key ''. getDirectoryMetaData() was calling getCache()->get('.') which looks up by md5('.'), never matching the root entry stored at md5(''). The cache miss caused getDirectoryMetaData to return synthetic data with time() as mtime/storage_mtime and uniqid() as etag on every call. The scanner then saw a storage_mtime mismatch and wrote the fabricated timestamps back to the cache on every occ files:scan run, regardless of whether any S3 content had changed. Introduce getCachePath() to translate the normalized root path '.' back to '' before any filecache lookup. Assisted-by: ClaudeCode:claude-sonnet-4-6 Signed-off-by: Maksim Sukharev <[email protected]>

  • Peter Ringelmann (09 Jul 26)

    refactor(core): use async/await in unified search controller Signed-off-by: Peter Ringelmann <[email protected]>

NextCloud Security

6.3/10

Repo Security Summary

Updated 29 Jun 26

  • Maintained 10/10
  • Code-Review 7/10
  • Security-Policy 10/10
  • CII-Best-Practices 5/10
  • Dangerous-Workflow 0/10
  • Packaging N/A
  • License 10/10
  • Signed-Releases N/A
  • Token-Permissions 8/10
  • Branch-Protection 4/10
  • Binary-Artifacts 10/10
  • Pinned-Dependencies 8/10
  • SAST 7/10
  • Fuzzing 0/10

NextCloud Website

Website

Nextcloud - Open source content collaboration platform

The most popular open source content collaboration platform for tens of millions of users at thousands of organizations across the globe

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address 85.10.195.17
  • Hostname nextcloud.com
  • Location Nuremberg, Bayern, Germany, EU
  • ISP Hetzner Online GmbH
  • ASN AS24940

Associated Countries

  • DE DE
  • AT AT

Safety Score

Website marked as safe

100%

Blacklist Check

nextcloud.com was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

NextCloud Docker

Container Info

Nextcloud is an open source, self-hosted file sync and communication app platform. Access and sync your files, contacts, calendars and communicate and collaborate across your devices. You decide what happens with your data, where it is and who can access it!

#Cloud#Productivity#Tools#Other#Web linuxserver/nextcloud:latest

Run Command

docker run -d \
  -p 443/tcp \
  -e PUID=${PUID} \
  -e PGID=${PGID} \
  -e TZ=${TZ} \
  -v /config \
  -v /data \
  linuxserver/nextcloud:latest

Compose File

version: 3.8
services:
  nextcloud-container:
    image: "linuxserver/nextcloud:latest"
    ports:
      - 443/tcp
    environment:
      PUID: 1000
      PGID: 1000
      TZ: America/Chicago
    volumes:
      - /config
      - /data

Environment Variables

  • Var Name Default
  • PUID 1000
  • PGID 1000
  • TZ America/Chicago

Port List

  • 443/tcp

Volume Mounting

  • /config
  • /data

NextCloud Reviews

More Backup and Sync

  • Modern and simpler alternative to Nextcloud/ownCloud crafted with TypeScript. Unifies file management, sync, sharing, notes, RSS, expenses, calendars, contacts, and photos, with MFA, WebDAV, CalDAV, CardDAV, SSO, and more.

  • SeaFile

    SeaFile

    seafile.com

    An open source cloud storage and sync solution. Files are grouped into Libraries, which can be individually encrypted, shared of synced. Docker image available for easy deployment, and native clients for Windows, Mac, Linux, Android and iOS.

  • Syncthing

    Syncthing

    syncthing.net

    Continuous file synchronization between 2 or more clients. It is simple, yet powerful, and fully-encrypted and private. Syncthing can be deployed with Docker, and there are native clients for Windows, Mac, Linux, BSD and Android.

About the Data: NextCloud

Change History

API

You can access NextCloud's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/nextcloud

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share NextCloud

Help your friends compare Backup and Sync, and pick privacy-respecting software and services.
Share NextCloud and Awesome Privacy with your network!

View Backup and Sync (4)