Three tools turn a server you control into a Google Drive or Dropbox alternative, and each one puts its weight somewhere else. Nextcloud is a platform: calendars, contacts and hundreds of apps sit next to your files, and encryption is opt-in. Seafile is built around block-level sync, with libraries you can lock with a password but whose file names the server can still read. Hoodik encrypts everything in the browser, file names included, yet has no desktop sync client, and its CC BY-NC 4.0 licence bars commercial use without the author's consent, so it doesn't qualify as open source.
Platform, sync tool or encrypted vault
Nextcloud's README puts contacts and calendars on the same footing as files and leaves the rest to apps: mail, video calls, or External Storage Support, which mounts SMB/CIFS, SFTP, WebDAV and FTP shares or S3 buckets into the file tree. The Federation app links shares across separate Nextcloud servers. Official desktop clients sync files on Windows, macOS and Linux, alongside iOS and Android apps.
Seafile organises files into libraries that each sync on their own. Its client splits every file into variable-size blocks based on the content, about 8 MB on average according to the docs, and uploads only the blocks that changed; an interrupted transfer picks up where it stopped. SeaDrive mounts libraries as a drive that downloads files only when you open them. Seafile has no calendar or address book, but it edits documents in the browser through SeaDoc, a wiki, and OnlyOffice or Collabora Online integration.
Hoodik is closer to a vault: a web interface plus iPhone, Android and Mac apps that back up photos and keep files offline, but no client that keeps a folder on your computer in sync. Windows and Linux apps are planned, the maintainer wrote on 27 July 2026, but the notes editor relies on a webview that doesn't run on those systems. WebDAV has been requested since March 2024 with no reply from the maintainer. Hoodik's own comparison pages point readers elsewhere when it fits: the one on Seafile recommends Seafile to anyone who needs a sync client, and the one on Nextcloud sends people who want a full productivity suite, with calendar, contacts and office tools, to Nextcloud.
Server-side or end-to-end encryption: what the admin can read
Nextcloud offers two kinds of encryption, and they can't be combined. Server-side encryption protects files at rest, external storage included, but the docs say plainly that it doesn't protect against a compromised server or a malicious administrator: file names and folder structure stay readable, and in the default master-key mode the admin can decrypt files. End-to-end encryption is a separate app, and it requires server-side encryption to be turned off first. It is enabled folder by folder from the official clients, and the desktop client won't encrypt the root of a sync or a folder that already holds files. The web interface can only view and download those files.
Seafile encrypts per library, with AES-256 and a password for each library. Its documentation lists what stays in the clear: folder and file names, file sizes and the edit history. Only the desktop client encrypts on the device. In the browser, the server receives the password and decrypts on its side, and the iOS and Android apps have also sent the password to the server since version 3.0.0. A library created on the web passes its keys through the server, and encryption doesn't guarantee integrity: an admin can partially alter a file without the client noticing. Libraries created before version 12 derive their key with PBKDF2-SHA256 at 1,000 iterations, which the docs call "far from secure"; Argon2id is only offered for new libraries.
Hoodik encrypts each file on the device before upload, chunk by chunk with AEGIS-128L by default, and encrypts the file name with the file key. The password never leaves the device: login runs over OPAQUE, and private keys are stored encrypted under a key that only the password can derive. Search only covers file names and note text, which the browser turns into HMAC tags, so the server matches tags it can't read back. A public link carries its key after the # in the URL, and that key never reaches the server.
Neither the password of an encrypted Seafile library nor the mnemonic behind Nextcloud's end-to-end encryption can be recovered by the administrator: lose it, and the files stay unreadable. Hoodik leaves one way back, the private key, which its README asks you to store somewhere safe; without it, a forgotten password means the files are gone.
What each tool needs to run
Read from the repositories and documentation on 7 October 2026.
| Tool | Licence | What you run | Clients | Encryption | Latest release |
|---|---|---|---|---|---|
| Nextcloud | AGPL-3.0-or-later | PHP 8.3 to 8.5, Apache or nginx, MariaDB, MySQL or PostgreSQL; APCu and Redis advised | desktop on Windows, macOS and Linux; iOS, Android | opt-in, server-side or end-to-end per folder | 35.0.1, 24 Sep 2026 |
| Seafile, Community Edition | AGPL-3.0 for the server, Apache-2.0 for the web UI | Seafile, MariaDB, Redis and Caddy containers; 2 GB of RAM, 2 cores | desktop, SeaDrive virtual drive, iOS, Android | opt-in, per library; names and sizes in the clear | 13.0.28, 18 Sep 2026 |
| Hoodik | CC BY-NC 4.0, non-commercial | one container, SQLite or PostgreSQL; about 20 MB of RAM at idle | web, iPhone, Android, Mac; no desktop sync client | end-to-end for every file, names included | 2.5.5, 22 Sep 2026 |
Nextcloud sets a floor of 128 MB of RAM per PHP process and recommends 512 MB. SQLite is only advised for testing and very small instances. Nextcloud All-in-One, the official install method, ships the whole stack as Docker containers with PostgreSQL and Redis, free for up to 100 users. Seafile has installed its Community Edition only as containers since 13.0, through Docker Compose or Kubernetes, on x86 or ARM64, and dropped SQLite in 11.0; its docs ask for 2 GB of RAM, 2 cores and 10 GB of disk, with 50 GB advised. Hoodik fits in a single container that idles at about 20 MB of RAM according to its setup guide, on amd64, arm64 or armv6/v7. Two of its settings have to be right before you store anything: SQLite and PostgreSQL aren't interchangeable once data has been written, and without a fixed JWT_SECRET, every restart invalidates all sessions.
Seafile doesn't store files as files: on the server, a library is a chain of commits, objects and blocks, deduplicated from one version to the next. Browsing the data directory gives you no documents back. seaf-fsck.sh --export rebuilds libraries into a regular file system, except encrypted ones, and deleting a file frees no space until seaf-gc.sh runs. A backup covers three databases, ccnet_db, seafile_db and seahub_db, plus the data directory. Hoodik only holds encrypted chunks, on local disk or on S3-compatible storage; since v2.5.0, clients can send them straight to the bucket through signed URLs, provided you have HTTPS, a public certificate and a CORS rule. In Seafile, S3 storage is a Pro-only feature.
Where the projects stand
Nextcloud ships a major version every four months, and its repository wiki gives each one a year of monthly maintenance releases, security fixes included, and nothing after that. Nextcloud 35 came out on 15 September 2026 and reaches end of life in September 2027. Several branches therefore get fixes at the same time: 32.0.15, 33.0.9 and 34.0.4 all shipped on 10 September 2026.
Seafile releases one major version a year: 11.0 went stable in November 2023, 12.0 in January 2025 and 13.0 in October 2025. The Community Edition got nine 13.0 bugfix releases between February and September 2026. Version 14.0 only exists as -testing images, since May 2026 for Pro, and the docs still list 13.0 as current; Pro also still maintains 12.0.
Hoodik rests on one maintainer, Tibor Hudik, who wrote 225 of the 231 commits on the main branch of a repository opened in January 2023. Fifteen releases shipped between 1 July and 22 September 2026. Version 2.0.0, on 17 July, replaced RSA-2048 with a hybrid X25519 and ML-KEM-768 scheme, and older accounts migrate on their next login. Hoodik has neither OpenID Connect nor LDAP: the first, requested since 2023, is targeted for the end of 2026, with no commitment from the maintainer.
Licences and paid editions
Nextcloud is under AGPL-3.0-or-later, and contributing doesn't require signing a CLA. Nextcloud Enterprise starts at 100 users and buys a longer support window: the Standard plan keeps the one-year cycle, while Premium and Ultimate stretch it to five years or more. The subscription adds early security patches, support from Nextcloud's own engineers, custom branding down to the desktop clients, and Microsoft integrations. All-in-One points to it past 100 users, and running Nextcloud on an Oracle database requires a subscription.
Seafile's Community Edition mixes licences: AGPL-3.0 for the server core, without the "or later" clause, Apache-2.0 for the Seahub web interface and GPL-2.0 for the desktop client. The Pro edition is proprietary: its source code is provided for security audits, and derivative works are forbidden. It runs without a licence file for up to three users; from 10 to 249 users, the annual subscription costs 48 dollars per user. The docs keep full-text search, sub-folder permissions, audit logs, S3 storage, clustering, virus scanning, SAML 2.0 and LDAP group sync for Pro. Community keeps TOTP two-factor authentication, sign-in through LDAP or Active Directory, and WebDAV.
Hoodik is released under CC BY-NC 4.0: personal and non-commercial use is free, and a commercial licence has to be negotiated with the author. That restriction puts it outside the Open Source Definition, whose sixth criterion forbids a licence from ruling out any field of endeavour, business use included. The CLA that contributors sign lets Tibor Hudik and his company, Hudik d.o.o., redistribute their code under other terms. Hoodik Cloud, the hosted version run by the publisher, costs €9 a month for 100 GB or €19 for 500 GB, in an EU or US region, and an instance can be exported at any time as a self-hostable copy.
