Just curious, are you storing the keys? Or at the very least the login info from which you could regenerate the keys? If so, there's no reason a government couldn't ask for you to hand the info over, so even though this is a step more complex that Dropbox, it doesn't add too much security.
Now, if users provide their own key and it's never transmitted, that would be secure, but obviously the data would be un-decryptable if the key is lost.