Nothing. And since it's uploaded, I've agreed that it's OK for them to scan and report on them.
The key point I'm trying to make is that where the data is located matters for whether Apple (or Microsoft or Redhat or whichever company) has the ability or right to read and report on that data.
> at least you are protected from future policy changes if your files in the cloud are encrypted.
If, and only if, that data is never synced back to your phone (which Apples does currently).