What matters is not whether the scan is online but where it sits. In a safe with zero-knowledge encryption, access belongs to you and to the people you authorise. A scan in your mailbox, on an ordinary cloud drive or in your phone's gallery is readable by anyone who takes over that account.
Why a scan of an ID card in particular is worth stealing
The scan holds everything needed to impersonate someone: given names, surname, PESEL number, the document’s series and number, its expiry date and the photograph. A leak of the PESEL number alone is an inconvenience. A leak of the document’s image can be the basis for remote identity verification.
Where a scan should not sit
- Your mailbox. A scan sent to an office or an insurer stays in the sent folder for years. Taking over the mailbox gives access to all of it at once.
- Your phone’s gallery. A photo of the ID syncs to the cloud along with holiday pictures and ends up in a backup you have forgotten about.
- An ordinary cloud drive. Files are encrypted on the server, but the provider holds the keys. That is enough against an outsider; it is not enough against the provider, or against a compromised account.
What zero-knowledge encryption changes
The file is encrypted before it leaves your device, and the key stays on your side. The operator stores an encrypted string of bytes and has no technical means of reading it. If the database is stolen, the attacker gets exactly what the operator has, which is nothing useful.
And what about sending a scan
Since the institution needs it anyway, limit what can be limited: send it only where the legal basis is clear, use the channel the institution indicates rather than plain e-mail, and delete the file from your sent folder once the matter closes. The copy that stays with you belongs back in the safe, not on the desktop.
Put your most important documents in one secure place
Sejf Życia is an encrypted space for documents, access details and instructions for loved ones. Only you decide who gets access, and when.