How does Nextcloud weigh up against QNAP/Synology/Drobo with regards to privacy?

Here are QNAP’s official responses from Jerome Wong:

"Hi,

1.are my login credentials to my NAS stored by QNAP?
–Login credentials are not stored by QNAP.

2.If so, do they ever access the contents of my NAS? The PP states that they can look through data I “publish”, but that sounds more like stuff outside of the confines of my NAS through other QNAP channels / services.

–QNAP does not have access to your content. If you are using myQNAPcloud, you do have the option of publishing your content. However that is up to the user’s control.

3.are my encryption keys to my storage ever stored by QNAP? If so, how are they stored? in plaintext? Encrypted? If encrypted, in what way? Can I opt out of this if so?

–QNAP does not store your encryption keys. It is stored only on your NAS. They are stored like a hash in Linux.

4.I tried to stay away from the use of a trendy word like ‘backdoor’ on my google searches, but this super old link definitely got me nervous, does QNAP in fact have a way to get into my device, or is it zero knowledge with regards to my encryption keys? https://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt

–This old link was referring to a security vulnerability we had in the past. That issue has long been resolved and we keep updating our security.

5.does my data within my NAS fall into the category of information that can be shared with a 3rd party? Be it an advertiser, a partner of QNAP, a law enforcement agency, etc?

–Sharing your data with a 3rd party falls in the hands of the user.

If you have any other questions, please let me know."