Nextcloud

Nextcloud

What is it?

Nextcloud is a self-hosted file server written in PHP. Files live on your server, sync to laptops and phones through the official clients, and can be shared by link or with other accounts. The nextcloud/server repository holds the core and the Files app; calendar, contacts, mail and video calls are separate apps, installed from an app store that lists several hundred of them. The code is licensed AGPL-3.0-or-later, and contributing doesn't require signing a CLA.

A comparison of self-hosted cloud storage options sets Nextcloud against the other tools on what each takes to run and what its encryption leaves readable.

Why is it interesting?

  • Clients for every device: desktop sync on Windows, macOS and Linux, plus iOS and Android apps
  • Contacts and calendars in sync: the Calendar and Contacts apps keep them in step across devices, next to your files
  • Existing storage, mounted in: the External Storage Support app brings SMB/CIFS, SFTP, WebDAV and FTP shares, or Amazon S3 and OpenStack buckets, into the file tree
  • Sharing across instances: the Federation app links shares between separate Nextcloud servers; an account on another instance is addressed with a federated ID like user@server
  • Version history: older versions are thinned out (one a day for the first month, one a week after that), capped at half of the user's free space
  • Security tooling: two-factor authentication and a HackerOne bug bounty

Good to know

A platform rather than a sync tool. The README puts contacts and calendars on the same footing as files and hands everything else to apps. Seafile is built around libraries that sync independently, each of which can be locked with its own password; Hoodik encrypts everything in the browser, so its server never handles plaintext. In Nextcloud, encryption is opt-in and comes in two flavours that can't be combined.

Server-side encryption doesn't keep the admin out. The documentation says so plainly: it protects files at rest, external storage included, but not against a compromised server or a malicious administrator. File names and folder structure stay readable, and in the default master-key mode the admin can decrypt files. Encrypted files take up about 1% more space.

End-to-end encryption comes with hard limits. The End-to-End Encryption app requires the server-side encryption app to be disabled first. Encryption is then switched on folder by folder from the official clients, and the desktop client won't encrypt the root of a sync or a folder that already holds files. The web interface can only view and download those files, calendars stay out of scope, and a lost mnemonic means lost data: the administrator has no way to recover it.

What you need to run it. Nextcloud 35 requires PHP 8.3, 8.4 or 8.5, Apache or nginx with php-fpm, and MariaDB, MySQL or PostgreSQL. SQLite is recommended only for testing and very small instances, and Oracle needs an Enterprise subscription. The docs set a floor of 128 MB of RAM per PHP process and recommend 512 MB. A memory cache is optional, but for an organization on a single server the docs suggest APCu locally plus Redis for distributed caching and file locking. Nextcloud All-in-One, the official install method, ships the whole stack as Docker containers with PostgreSQL and Redis, free for up to 100 users; past that, it points to Nextcloud Enterprise.

A major release every four months, one year of fixes. The repository wiki sets the policy: each major version gets monthly maintenance releases for a year, then no further fixes, security included. Nextcloud 35 (Hub 26 Summer) shipped in September 2026 and reaches end of life in September 2027; 35.0.1 followed on September 24.

Nextcloud Enterprise buys a longer support window. Subscriptions start at 100 users. The Standard plan keeps the one-year cycle, while Premium and Ultimate extend it to five years or more. The Enterprise page also lists early security patches, support from Nextcloud's own engineers, custom branding down to the desktop clients, and Microsoft integrations (Outlook, Exchange, Teams, SharePoint).

SOURCES

REPOhttps://github.com/nextcloud/server
SITEhttps://nextcloud.com
LICENSEAGPL-3.0-or-later