Buddy backup
Buddy backup pairs your server with a friend’s. Each server keeps an encrypted backup of the other. Frameleaf Cloud handles pairing and finding the connection, but your photos go straight between the two servers, and neither your buddy nor Frameleaf Cloud can read them.
Hosting your buddy’s backup never adds their photos, albums or people to your library, timeline or search. It’s purely storage. Likewise, your restore screen only ever opens your own backup.
You can use buddy backup and cloud backup at the same time. They encrypt differently: buddy backup encrypts on your server before anything is sent.
What you need
Section titled “What you need”- Both servers running a compatible Frameleaf version and linked to Frameleaf Cloud.
- An active Frameleaf Cloud subscription on both sides, or its grace period, to make new backups. Existing backups stay restorable if a subscription ends.
- A dedicated folder on each server for the other’s backup, outside your photo libraries, import folders and the server’s identity folder. Storage on your buddy’s disk costs nothing extra; transfers through the relay count toward your normal relay allowance.
No port forwarding, DNS or router changes are needed. Direct connections are preferred, and the Frameleaf relay handles the ones that can’t connect directly.
Set it up
Section titled “Set it up”Open Settings, then Backup, then Buddy controls. The Frameleaf Cloud, then Backup entry opens the same place.
- Check the library mounts, configuration coverage and estimated size of the first backup.
- Choose the folder where you’ll store your buddy’s backup and set a hard limit on the space you offer. You don’t have to offer the same amount as your buddy.
- Invite your buddy’s Frameleaf Cloud account. Each of you confirms the other’s account, server and storage agreement.
- Download your recovery kit, then import it again to check it works. Keep it somewhere other than your server. Each server has its own encryption key, and you need the kit to restore if your server is lost.
- Run the encrypted connection check, then start the first backup.
Optionally, you can keep an escrow copy of your recovery kit with Frameleaf Cloud. It’s encrypted on your server with a passphrase, and Frameleaf Cloud never receives the passphrase.
What’s protected
Section titled “What’s protected”Every user’s originals, videos, Live Photo parts, sidecars, edits, project files and metadata, plus external libraries whose drives are connected when the backup runs. Each restore point also includes a verified database dump, Frameleaf settings, user preferences and the configuration files you declared during setup. It’s not a whole operating-system image.
If a required file is missing or changes during capture, that restore point isn’t published as complete, so connect external drives and declared configuration files before a backup runs. Thumbnails and transcoded videos are optional. Your buddy’s backup that you host, temporary transfer files and caches are never included in your own.
Cloud backup keys
Section titled “Cloud backup keys”If you also use Cloud backup with a key stored on your server, that key is included in your encrypted buddy backup and put back when you recover settings or the whole server. A Cloud backup key that’s never saved on the server isn’t included. Your server’s identity and your buddy recovery kit are never included; a recovered server keeps its new identity.
Keep a separate copy of each recovery kit or key, for buddy backup and for Cloud backup.
Your buddy can see how much space you use and when transfers happen, never your file names, albums or photos.
After the first backup, only new and changed files are sent, and metadata-only changes don’t upload originals again. Pausing keeps the progress already confirmed.
Two directions
Section titled “Two directions”- My backup shows your latest complete restore point, and separately, your latest successful restore check.
- Hosting for my buddy shows the space used and reserved. It never shows their file names, albums or photos.
The Command Center’s overview and analytics show both directions next to Cloud backup. Refresh them to see the latest status.
The backup area has five tabs: Status, Cloud Backup, Buddy controls, Recover and How it works.
From the controls you can Pause sending or Pause receiving, Resume, Restart backup (which reuses files already safely stored), and Verify backup, which checks stored content and restores a sample into a temporary folder. Automatic checks rotate through your backup weekly.
Defaults
Section titled “Defaults”| Setting | Default |
|---|---|
| Buddies | One reciprocal buddy per server |
| Schedule | Daily at 02:00, in the sending server’s time zone |
| Speed | 20 Mbit/s each way, with two transfers at a time in each direction |
| Retention | At least 30 days of restore points, plus 12 monthly points and the latest complete one |
| Free-space guard | Stops receiving before free space drops below 10 GiB or 10% of the volume, whichever is larger |
Change the schedule, transfer windows and limits under Hosting & transfer settings. When either side runs out of agreed space or free disk, receiving pauses. Protected restore points are never deleted to make room.
Restore
Section titled “Restore”Unlock with your PIN and choose a dated restore point. Restore a photo or video, a selection or an album; administrators can also restore a whole library, the settings or the entire server. The wizard previews what will change and any conflicts before it starts. By default it fills in what’s missing and keeps your current changes; choosing to replace keeps a rollback copy. Restoring part of a library doesn’t bring back old sharing.
A full server recovery checks the files first, then puts the server into maintenance mode while it restores. Reconnect your original storage mounts and check the versions are compatible before you start. Recovery signs everyone out of the restored server and drops jobs that were in progress. If recovery fails, the server stays in maintenance mode.
Your buddy backup settings after a restore
Section titled “Your buddy backup settings after a restore”A restore point also holds your buddy backup schedule, time zone, transfer windows, limits and pause switches. When you recover settings or a whole server:
- Keep leaves your current buddy backup settings as they are.
- Replace brings back the saved schedule and limits, but keeps the new server’s hosting folder, storage offer, pairing and identity. A direction stays paused if either server’s settings pause it.
Older restore points without these settings can still be recovered.
If your server is gone
Section titled “If your server is gone”- Set up a new Frameleaf server and sign in to Frameleaf Cloud.
- On your Buddy account page, rebind the backup to the new server. This revokes the old server’s identity.
- Import your recovery kit, or unlock your escrow copy, on the new server.
Recover without Frameleaf Cloud
Section titled “Recover without Frameleaf Cloud”Your buddy can export your encrypted backup for you without being able to decrypt it. With your recovery kit you can then recover it offline, with no Cloud connection and no original database, in a Frameleaf environment with the folders mounted:
frameleaf-admin buddy-backup export --vault /vault/VAULT_UUID --output /empty-exportframeleaf-admin buddy-backup recover --vault /empty-export/VAULT_UUID --kit /recovery-kit.json --output /empty-recoveryAdd --snapshot SNAPSHOT_UUID to pick a particular restore point. The output folder must be empty. The result is your verified files plus a manifest.json listing their original paths and details; recovery-complete.json points to the database. Keep the decrypted output private.
Ending a pairing
Section titled “Ending a pairing”Ending a pairing stops new backups and normally leaves a 30-day window to recover; a security block revokes access immediately. Unlinking from Cloud, a Cloud outage or a lapsed subscription never silently deletes the backup stored on your buddy’s disk. After a subscription ends, you can still sign in and recover from your backup, read-only.