Dropbox is the weak link, as your encrypted datafile is likely accessible to a determined 3rd party.
If an attacker is able to find my storage repo, identify my database file, discover what type of encryption I'm using, and figure out the key to decrypt it, then you know what, they've earned my credentials :)