Cloud backup
A home server protects you from losing a phone. Cloud backup protects you from losing the server.
- A bucket of your own. Each server backs up to a dedicated storage bucket that’s never shared with another server or anything else.
- Encrypted with your key. The storage provider encrypts every file with a key for your bucket and never keeps the key. Frameleaf Cloud never receives it either.
- Only what changed. After the first run, only new and changed files upload. A photo you have twice is stored once.
- 1 TB included with a Frameleaf Cloud plan.
- Restore anything, from one photo to the whole library, or onto new hardware.
Your photos and every local feature keep working without it.
Turn it on
Section titled “Turn it on”Open the Command Center, then Frameleaf Cloud, then Cloud backup. The same controls are under Settings, then Backup, alongside Buddy backup. Your server must be linked.
Choose where it’s stored
Section titled “Choose where it’s stored”| Storage | What it means |
|---|---|
| Frameleaf-managed | Frameleaf creates the bucket for you. Included with your plan, 1 TB. Frameleaf can see file names and sizes, never their contents |
| Your own bucket | Any S3-compatible provider that supports customer-provided encryption keys (SSE-C). The bucket must be empty and use HTTPS. Needs no plan |
Choose how the key is kept
Section titled “Choose how the key is kept”Every upload, download and check carries a 256-bit key for your bucket. The provider encrypts with it and keeps only a salted fingerprint of it, never the key itself. You choose where the key lives:
| Option | Where the key is kept | After a restart | To restore you need |
|---|---|---|---|
| Generated key, kept on this server | A protected key file on your server. A recovery kit is shown once to save or print | Backups carry on | The key file or the recovery kit |
| Your own key, with a copy on this server | Your browser creates it and you download it. A copy stays on your server and is never sent to Frameleaf Cloud | Backups carry on | Your downloaded key file |
| Your own key, never saved | Your browser creates it and you download it. It’s never stored on the server | Backups pause until someone loads the key | Your key file, always |
You can’t change this choice later without starting a new backup.
Optional key escrow
Section titled “Optional key escrow”With a generated key, you can also keep an encrypted copy of it with Frameleaf. Your server wraps it with a passphrase of at least 12 characters before it’s sent, so Frameleaf can’t read it. It helps if you lose the server but still remember the passphrase. It’s off by default, and the owner can download or delete the escrow copy from the account site.
What’s backed up
Section titled “What’s backed up”- Always: originals with their metadata sidecar files, profile pictures and the database. Locked and trashed photos are included.
- Optional: thumbnails, previews and transcoded videos. They can be made again from the originals.
- Not included: external libraries.
Each run backs up the database first, then the files, then writes a list of everything in that run. An interrupted run resumes where it stopped.
Protection against ransomware
Section titled “Protection against ransomware”Your bucket keeps older versions of every file, and your server’s credentials can’t delete them. An old version is cleaned up 30 days after it’s replaced. The credentials your server uses are short-lived, issued fresh for each run and never stored on the server.
Schedule, retention and checks
Section titled “Schedule, retention and checks”| Setting | Default | You can choose |
|---|---|---|
| Schedule | Every night at 03:00, server time | Every 6 hours, or Sundays at 03:00 |
| Daily runs kept | 7 | 1 to 90 |
| Weekly runs kept | 4 | 0 to 52 |
| Monthly runs kept | 12 | 0 to 120 |
| Spot check | Weekly: a 1/52 sample of files is downloaded and checked, so every file is checked about once a year | |
| Full check | Monthly: every file in a kept run is checked |
Files that are still part of a kept run are never removed. Administrators are notified if a check finds a mismatch, and the owner is emailed if a scheduled backup hasn’t run for 7 days.
Restore
Section titled “Restore”You can restore one photo, an album, a person or the whole library, with its details and albums.
- Choose a run, then what to bring back. Every file is checked against its fingerprint as it’s restored.
- Files can be restored into a review folder for Library Care instead of straight into your library.
- Restoring the database uses the server’s normal maintenance restore. See Backup and restore.
- If your server is gone, a command-line restore puts your library onto new hardware using your bucket and your key file or recovery kit.
Restores keep working when your backup is read-only for any of the reasons below.
When your backup grows
Section titled “When your backup grows”Plans bought on the web: 1 TB is included. Beyond that, storage is added automatically in 1 TB blocks at $9.99 a month each, billed from your peak usage in the period. The owner is emailed when another block is added. Backups never go read-only for being over. A block is counted for any part of a terabyte: 1.01 TB of backups means one extra block. Storage is counted across all your servers’ buckets.
Plans bought in the iPhone or Android app come in fixed sizes. When a backup outgrows its size:
- The owner is asked whether to move up a size. Until they answer, backups carry on.
- If the owner keeps the current plan, backups continue up to its size, and new items wait. You’ll see Backup paused: plan full. Your library is untouched, restores keep working, and backups carry on by themselves once there’s room, after an upgrade or when the plan ends.
Usage is measured every hour, so up to an hour of uploads can go past the limit before the pause. A Family Sharing member whose plan is full sees the same pause, with a prompt to ask the organiser.
Read-only states
Section titled “Read-only states”| When | What happens | Ends when |
|---|---|---|
| Your plan lapses past its grace period | Read-only. Kept for 30 days, then deleted by day 90 | You renew |
| The server is unlinked | Read-only for 30 days, then deleted by day 90 | You link the server again |
| The owner asks to delete the backups | Read-only for 30 days, with a reminder 7 days before; deleted by day 90 | The owner cancels |
| The account is closed | Kept read-only, not deleted | A server is linked again |
| Plan full (app plans only) | New items wait; nothing is deleted | There’s room again |
The account site’s backup page for each server shows storage used, the last run, recent runs, any read-only reason, the escrow download, and a countdown if a deletion is scheduled.