The fact that Notion staff technically has unrestricted access to all user and account data legally prevents me from putting the vast majority of my work-related items on there.
On top of that there's so much tracking going on that even Facebook would be jealous.
And that's just the tip of the iceberg. Check out their T&C and Privacy Policy:
Not sure how this is different from something like Dropbox (which stores stuff on S3 iirc). So technically, you can have Dropbox people looking through your stuff, and you can also have Amazon people looking through your stuff. Obviously, if this ever happens without a good reason, employees that do this can get fired and/or sued (and the company itself might also be held liable). Everything is also logged, so there's a paper trail. I skimmed over both the T&C and the Privacy Policy and it doesn't really seem that Notion breaks from this norm.
All of those are blob/file based, when the service provider needs to offer services like search and ways to make deeper inferences between pieces of data it's pretty much impossible to have all the encryption handled client-side.
I'd be interested to see examples/arguments where it works though.
Not sure about DropBox, but AWS has alot of protections around what goes into S3. I have worked with them to address issues that come up in the service, and they couldn't access our data, even when we would have been fine with it. Had to copy it somewhere else for them.
On top of that there's so much tracking going on that even Facebook would be jealous.
And that's just the tip of the iceberg. Check out their T&C and Privacy Policy:
https://www.notion.so/Terms-Conditions-4e1c5dd3e3de45dfa4a8e...
https://www.notion.so/Privacy-Policy-3468d120cf614d4c9014c09...