Skip to content

Cloud backup

A home server protects you from losing a phone. Cloud backup protects you from losing the server.

  • A bucket of your own. Each server backs up to a dedicated storage bucket that’s never shared with another server or anything else.
  • Encrypted with your key. The storage provider encrypts every file with a key for your bucket and never keeps the key. Frameleaf Cloud never receives it either.
  • Only what changed. After the first run, only new and changed files upload. A photo you have twice is stored once.
  • 1 TB included with a Frameleaf Cloud plan.
  • Restore anything, from one photo to the whole library, or onto new hardware.

Your photos and every local feature keep working without it.

Open the Command Center, then Frameleaf Cloud, then Cloud backup. The same controls are under Settings, then Backup, alongside Buddy backup. Your server must be linked.

Storage What it means
Frameleaf-managed Frameleaf creates the bucket for you. Included with your plan, 1 TB. Frameleaf can see file names and sizes, never their contents
Your own bucket Any S3-compatible provider that supports customer-provided encryption keys (SSE-C). The bucket must be empty and use HTTPS. Needs no plan

Every upload, download and check carries a 256-bit key for your bucket. The provider encrypts with it and keeps only a salted fingerprint of it, never the key itself. You choose where the key lives:

Option Where the key is kept After a restart To restore you need
Generated key, kept on this server A protected key file on your server. A recovery kit is shown once to save or print Backups carry on The key file or the recovery kit
Your own key, with a copy on this server Your browser creates it and you download it. A copy stays on your server and is never sent to Frameleaf Cloud Backups carry on Your downloaded key file
Your own key, never saved Your browser creates it and you download it. It’s never stored on the server Backups pause until someone loads the key Your key file, always

You can’t change this choice later without starting a new backup.

With a generated key, you can also keep an encrypted copy of it with Frameleaf. Your server wraps it with a passphrase of at least 12 characters before it’s sent, so Frameleaf can’t read it. It helps if you lose the server but still remember the passphrase. It’s off by default, and the owner can download or delete the escrow copy from the account site.

  • Always: originals with their metadata sidecar files, profile pictures and the database. Locked and trashed photos are included.
  • Optional: thumbnails, previews and transcoded videos. They can be made again from the originals.
  • Not included: external libraries.

Each run backs up the database first, then the files, then writes a list of everything in that run. An interrupted run resumes where it stopped.

Your bucket keeps older versions of every file, and your server’s credentials can’t delete them. An old version is cleaned up 30 days after it’s replaced. The credentials your server uses are short-lived, issued fresh for each run and never stored on the server.

Setting Default You can choose
Schedule Every night at 03:00, server time Every 6 hours, or Sundays at 03:00
Daily runs kept 7 1 to 90
Weekly runs kept 4 0 to 52
Monthly runs kept 12 0 to 120
Spot check Weekly: a 1/52 sample of files is downloaded and checked, so every file is checked about once a year
Full check Monthly: every file in a kept run is checked

Files that are still part of a kept run are never removed. Administrators are notified if a check finds a mismatch, and the owner is emailed if a scheduled backup hasn’t run for 7 days.

You can restore one photo, an album, a person or the whole library, with its details and albums.

  • Choose a run, then what to bring back. Every file is checked against its fingerprint as it’s restored.
  • Files can be restored into a review folder for Library Care instead of straight into your library.
  • Restoring the database uses the server’s normal maintenance restore. See Backup and restore.
  • If your server is gone, a command-line restore puts your library onto new hardware using your bucket and your key file or recovery kit.

Restores keep working when your backup is read-only for any of the reasons below.

Plans bought on the web: 1 TB is included. Beyond that, storage is added automatically in 1 TB blocks at $9.99 a month each, billed from your peak usage in the period. The owner is emailed when another block is added. Backups never go read-only for being over. A block is counted for any part of a terabyte: 1.01 TB of backups means one extra block. Storage is counted across all your servers’ buckets.

Plans bought in the iPhone or Android app come in fixed sizes. When a backup outgrows its size:

  1. The owner is asked whether to move up a size. Until they answer, backups carry on.
  2. If the owner keeps the current plan, backups continue up to its size, and new items wait. You’ll see Backup paused: plan full. Your library is untouched, restores keep working, and backups carry on by themselves once there’s room, after an upgrade or when the plan ends.

Usage is measured every hour, so up to an hour of uploads can go past the limit before the pause. A Family Sharing member whose plan is full sees the same pause, with a prompt to ask the organiser.

When What happens Ends when
Your plan lapses past its grace period Read-only. Kept for 30 days, then deleted by day 90 You renew
The server is unlinked Read-only for 30 days, then deleted by day 90 You link the server again
The owner asks to delete the backups Read-only for 30 days, with a reminder 7 days before; deleted by day 90 The owner cancels
The account is closed Kept read-only, not deleted A server is linked again
Plan full (app plans only) New items wait; nothing is deleted There’s room again

The account site’s backup page for each server shows storage used, the last run, recent runs, any read-only reason, the escrow download, and a countdown if a deletion is scheduled.