End-to-end encryption protects content so that its intended endpoints hold the decryption capability rather than an intermediary service that transports or stores it.
Ask who holds the keys
A service can encrypt traffic and stored files while still holding keys that let it read the contents. End-to-end encryption makes a different claim about where decryption is possible. To assess that claim, identify the endpoints, recovery mechanism, sharing rules, and data categories covered.
Apple's iCloud security overview distinguishes standard protection from Advanced Data Protection and explains exceptions for some sharing modes and metadata. A cloud account being described as encrypted does not mean every category has the same protection.
What endpoints can still expose
A legitimate endpoint displays plaintext. Malware, screen recording, a person watching the screen, or an authorized recipient can capture that content. End-to-end encryption does not make a recipient forget a document already read or downloaded.
A useful comparison therefore asks two questions: can the storage provider decrypt this content, and who else can access an unlocked endpoint? Neither answer replaces the other.
NullVault's relevant boundaries
Local vault encryption and encrypted backup are separate capabilities. NullVault describes its cloud features by platform, including recovery and controlled sharing. Consult encrypted backup and secure sharing instead of treating every platform feature as identical.
For ordinary photo-library use, read whether iCloud Photos is end-to-end encrypted. For storage decisions, compare a local vault with cloud photo storage.