Dropbox being a YC company means absolutely zero other than that YC liked their idea and supported them. That doesn't give me any assurance that they won't make a mistake or that an employee won't sell my data.
In fact, Dropbox, despite being a YC company, already slipped up majorly once to the point that every account was completely passwordless. You could just type in random emails at the web login and view some stranger's files. Story here: http://techcrunch.com/2011/06/20/dropbox-security-bug-made-p...
On the other hand, AES has yet to slip up. My AES encrypted data will take a significant fraction of the life of the universe to crack and, YC or no, a single programmer error won't break it.
The only protection against that is that the cloud storage provider doesn't have the encryption keys.
There are other reasons as well: potential vulnerabilities in their software, malicious/crazy/corrupted employees, etc. Healthy need-to-know rule is enough to decide that if there's no reason your cloud provider should have access to your data, he shouldn't have it.