Skip to content
Frameleaf
    • Library & timelineEvery photo and video, in order
    • Search & AIFind anything by describing it
    • People & petsFaces recognised on your server
    • Memories & placesRediscover moments and maps
    • SharingPartners, spaces and links
    • Photo editorNon-destructive, with versions
    • StudioA full video editor, built in
    • For photographersIngest, proof, edit and deliver
    • Library careDuplicates, repairs and trash
    • PrivacyLocked content and what stays home
  • Demo
    • iPhone & iPadNative, written in Swift
    • AndroidNative, written in Kotlin
    • Web appThe full library in any browser
    • NAS appsUnraid, Synology and TrueNAS
    • Frameleaf CloudOptional services for your server
    • Remote accessReach home without open ports
    • Cloud backupEncrypted off-site copies
    • Buddy backupBack up to a friend's server
    • Cloud GPUHeavy AI jobs, paid by use
    • Sign inManage and open your servers
  • Pricing
  • Docs
  • Sign in to Frameleaf Cloud
  • Get Frameleaf
Sign inGet Frameleaf
Legal and policiesFrameleaf Cloud services

Encrypted Backup and Restoration Agreement

Last updated October 3, 2026

On this page
  1. 1. Backup destinations and service boundary
  2. 2. Backup scope and completion
  3. 3. Enrollment and customer responsibilities
  4. 4. Cloud Backup encryption and keys
  5. 5. Scheduling, integrity and recovery-point history
  6. 6. Managed storage accounting and billing
  7. 7. Restoration and export
  8. 8. Managed backup suspension and deletion
  9. 9. Buddy Backup
  10. 10. Service standard and contact

This Agreement supplements the Frameleaf Master Terms for backup and restoration features. Frameleaf, Inc. is the supplier of the commercial Services. The selected backup destination determines which provisions apply.

1. Backup destinations and service boundary

Managed Cloud Backup uses a dedicated storage bucket provisioned by Frameleaf Cloud for a linked Frameleaf Library server. Frameleaf manages the storage account, access credentials, usage accounting and managed deletion process. You do not receive your own account with the storage supplier through this service.

Customer-provided storage uses a compatible S3 storage bucket that you arrange and administer. You supply the storage credentials and pay that provider under your own agreement. The Library’s backup tools can use that destination without a managed Cloud Backup subscription. Frameleaf does not administer its billing, provider lifecycle rules, retention locks or final deletion.

Buddy Backup, where enabled, stores recovery material on another paired, customer-operated Frameleaf Library server. Cloud supplies coordination and authorized connection services. The peer supplies the disk space, power, network and availability. Managed Cloud Backup storage allowances and deletion deadlines do not apply to that peer’s disks.

None of these destinations is a hosted operational Library, an always-on gallery, or an automatic replacement server. You or your administrator operate the Library, its database and primary media. Restoration requires an appropriate target, compatible software, retained recovery material and the necessary keys.

2. Backup scope and completion

A Recovery Point is a completed backup state with the manifest and dependencies needed for its supported restore method. A selected, queued, hashed or partially transferred file is not a completed recovery copy.

The Library’s Cloud Backup agent captures a database dump, supported original media, sidecars and profile images, and writes a manifest describing the run. Thumbnails and encoded video derivatives are optional and are excluded by default. Files are stored by content hash so that unchanged identical file content need not be uploaded again. Database and manifest data can include albums, people information, ownership and other Library metadata. A full backup can include media marked locked in the Library interface; that label does not exclude it from an administrator-operated backup.

The backup does not include every file on the host, operating-system configuration, an entire container or virtual machine, or media that has not reached a supported source. Inclusion depends on the configured scope, recorded Library assets and readable source files. External mounts, edited derivatives, companion files and application-specific metadata must be checked against the selected backup and restore scope. Regenerable previews are not substitutes for original media.

A database-only restore does not restore missing original files. A media-only restore does not rebuild all database relationships. A completed upload does not prove that every source image was valid, that every third-party edit is reproducible, or that a clean-target Library restoration has been tested.

3. Enrollment and customer responsibilities

Before activation, check the destination, schedule, scope, key mode, retention settings, storage billing basis and restore requirements shown in the setup. Use a dedicated compatible bucket for customer-provided storage; a bucket claimed by another Library or containing unrelated data is refused by the setup process.

Maintain a supported server, adequate staging and destination space, readable source files, a reliable connection and current contact information. Backups cannot run while the source is unavailable, credentials are invalid, required keys are unloaded or a relevant service restriction prevents writes. Review completed status and failure notices before deleting originals.

Keep independent copies of irreplaceable data and test restoration periodically, particularly after changing storage, software or keys. These precautions do not excuse Frameleaf from its own contractual duties.

4. Cloud Backup encryption and keys

4.1 Storage-provider encryption

Managed Cloud Backup and the supported customer-provided S3 destination use server-side encryption with customer-provided keys (SSE-C). The Library supplies its 256-bit encryption key over HTTPS to the storage endpoint for content upload, download and related content operations. The storage system performs encryption and decryption. This is encryption at rest and in transit; it is not client-side encryption that conceals plaintext and the usable key from the storage processor during those operations.

The Frameleaf Cloud account and coordination services do not receive the usable bucket key in the ordinary backup protocol. They manage credentials, list object identifiers and sizes, and receive run and usage information. Access credentials and the encryption key are separate: possessing storage credentials alone is insufficient to decrypt an SSE-C object without its key.

4.2 Key modes

The Library offers these key arrangements:

  • Server-generated: the Library generates the key, saves a copy on the server and provides recovery material for you to keep separately.
  • Your key, stored on the server: you supply the key and the Library saves a local copy for automatic operation.
  • Your key, memory only: the Library does not persist the key through this mode. You must unlock it again after restart; jobs wait while the key is unavailable.

A server or device administrator with access to a stored or loaded key may be able to use it. Filesystem permissions, device security and your control of authorized administrators matter in every mode.

4.3 Optional escrow

For the server-generated key mode, you may separately enable passphrase-protected escrow. The Library wraps the key before sending the encrypted envelope to Cloud. Restoration requires the necessary passphrase or another usable recovery copy. Escrow is not a staff-held plaintext recovery key, is not automatically enabled, and does not allow an ordinary Cloud password reset to reconstruct a lost backup key. It is not offered for the two customer-generated key modes.

If every usable key and necessary recovery secret is lost, stored objects may be permanently unreadable. Keep the recovery kit outside the server and outside the backup it unlocks. Do not email usable keys or passphrases to support.

4.4 Metadata and permissions

Cloud and the storage processor can see information such as account and server identifiers, bucket and object names, content-hash object identifiers, sizes, timestamps, status and traffic amounts. Database dumps and manifest contents receive the destination’s SSE-C protection. That protection does not hide all metadata or remove the storage processor’s role in content operations.

Backup enrollment is not authorization for Cloud AI analysis. No unrelated AI job may obtain the bucket key or treat backup access as consent to analyze the collection.

5. Scheduling, integrity and recovery-point history

Schedules run when their dependencies are available. The first backup or a large change can take substantial time. There is no guaranteed recovery-point age, transfer rate or restoration deadline unless a signed Order expressly states one.

The default Library retention selection keeps the newest completed manifest plus the newest available point from each of seven daily, four weekly and twelve monthly periods. These selections overlap; they do not promise 23 distinct copies or a backup on a day when none completed. The administrator can change supported retention settings. Pruning removes other manifests and objects no retained manifest needs. The newest manifest is kept by the retention calculation even if it is old.

Managed storage also retains noncurrent object versions for 30 days after they become noncurrent. This provider-version history is separate from the Library’s manifest selection and is not a promise that every historical version is a complete independently restorable Library. Routine cleanup can remove expired versions. Ordinary source-side credentials cannot delete individual object versions or change the managed bucket’s versioning policy, but Frameleaf’s authorized storage administration can perform lifecycle deletion. This is not immutable storage or a guarantee against ransomware.

Source deletion or exclusion affects later captures and pruning. It does not necessarily remove previously stored copies immediately. A later backup can contain an already damaged or encrypted source file. Recovery depends on a suitable earlier point remaining available.

Integrity verification distinguishes sampled content checks from presence checks. A checksum can detect changed bytes; it cannot establish that the original photograph was uncorrupted or that your recovery key is still available. Keep recovery dependencies and test the intended restore procedure.

6. Managed storage accounting and billing

One terabyte (TB) is 1,000,000,000,000 bytes. Managed usage is measured across the account’s managed buckets. Current object bytes count toward the allowance, including current manifests and database dumps. Noncurrent object versions are measured separately; they are not added to the current-byte storage-block calculation. Internal infrastructure replicas are not separately counted as customer storage.

For a direct-billed plan with automatic storage expansion, the included allowance and price per additional whole 1 TB block are disclosed at purchase. Additional blocks are calculated from the peak measured current-byte usage during the storage billing period, rounded up above the included allowance. Usage below the peak later in that period does not reduce that period’s peak charge. This is not time-weighted billing. Accepting that plan authorizes its disclosed storage expansion; an alert is a notice of usage, not a new spending approval. New writes are not stopped merely because the included allowance is exceeded under that arrangement.

App Store and Google Play plans use their purchased storage tier rather than direct-billing overage charges. At the applicable capacity limit, new managed backup writes can become read-only until usage or entitlement is resolved. Existing data is not purged merely because the tier is full. The account identifies its billing channel, allowance and any required tier change.

The Order controls the actual prices, taxes and included capacity. No supplier minimum, deleted-storage fee or restore fee becomes your obligation without an accepted disclosure. Customer-provided storage and peer storage have their own capacity and cost arrangements.

7. Restoration and export

Supported Cloud Backup restoration uses the retained manifest, required objects and database dump, the bucket key, authorized storage access and a compatible target. Available scopes include files, database or Library recovery; a particular scope may require additional preparation or an offline command. Restoring into a live database or replacing existing files can be destructive. Follow the identified prerequisites and verify results before discarding another copy.

Managed access normally requires a linked, authorized server and a usable Cloud account. Unlinking revokes issued storage access credentials. A bucket being retained during a hold does not mean that the unlinked server can still read it. Relinking, account recovery or support assistance may be necessary before a supported restore can proceed. Support cannot recreate a missing encryption key.

Ordinary supported online retrieval has no separate Frameleaf restore charge unless your accepted Order expressly states one. Custom migration, physical media, forensic work and bespoke engineering require a separate agreement. A large ordinary disaster restore is not abuse merely because it is large, but transfer time still depends on capacity, network conditions and the target.

8. Managed backup suspension and deletion

An ordinary owner unlink, backup deletion request, account erasure or lapse of the backup entitlement starts a 30-day deletion hold. The recorded hold date, rather than a generic subscription cancellation date, controls. The managed bucket is placed in a read-only or frozen state, as applicable. After the hold, deletion can begin; bucket contents, versions, access user and associated escrow are scheduled for removal no later than 90 days from the original trigger, subject to a lawful preservation exception.

The service records the hold and sends the available account notice and a reminder seven days before the hold ends. Account erasure can remove the ordinary contact and sign-in route; export and recovery should be arranged before erasure. A 90-day final-removal deadline is not a promise of access between days 30 and 90. Routine version cleanup remains distinct from whole-bucket deletion; the hold does not promise that every expired historical version remains available.

A held owner-requested deletion can be canceled through the authorized controls before purge begins. An unlink-triggered hold can end on relinking, and an entitlement-lapse hold can end on renewal, subject to account and server eligibility. Relinking or renewal does not silently cancel an explicit deletion request. Once purge begins, it cannot be canceled through the ordinary controls and recovery is not promised.

Closing a Cloud account through the closure control is different: existing backup storage is frozen without scheduling whole-bucket deletion solely because of that closure. Account or server suspension can likewise freeze access pending resolution. The Security Schedule describes these states and rights requests. They are not substitutes for an independently usable recovery copy.

There is no automatic extension of a deletion deadline merely because a restore or support ticket is open. Contact support before the hold expires if recovery is blocked. Any agreed preservation extension must be recorded. Frameleaf remains responsible for a failure to provide an expressly contracted recovery opportunity and for applicable legal remedies.

9. Buddy Backup

Buddy Backup requires compatible enabled Frameleaf servers, an authorized pairing, available peer capacity and a usable recovery kit. The source encrypts blocks and recovery metadata before sending them to the peer. The peer stores ciphertext; the ordinary Cloud coordination protocol receives pairing, identity, authorization and operational information rather than plaintext media, plaintext manifests or usable vault keys. Optional escrow stores a passphrase-wrapped recovery envelope.

The peer operator controls the physical storage and can take the server offline or delete or lose its stored data. Encryption protects confidentiality; it does not compel that operator to retain or deliver data. Pairing terms, quota, recorded recovery access and peer availability govern the practical recovery opportunity. Cloud cancellation or revocation can affect coordination and relay access even when peer data remains on disk. Managed Cloud Backup’s 30-day hold and 90-day purge deadlines do not bind an independent peer.

A snapshot is recoverable only to the extent its encrypted blocks, manifest, keys and required application state remain intact. A pairing, successful connection or partial upload does not establish a completed snapshot. Keep recovery material independently and test recovery before relying on the peer. Do not offer peer capacity you are not authorized to use or store another person’s data outside the agreed arrangement.

10. Service standard and contact

Frameleaf will exercise reasonable skill and care in supplying its managed storage and coordination services and honor the express safeguards in the Agreement. No provider durability figure, encryption label or status indicator is a guarantee against every loss, corruption, key failure or outage. Frameleaf remains responsible for its chosen managed suppliers and its own failures; independent customer storage and peer operators remain responsible for their own systems.

The Master Terms govern correction, termination, refunds and liability, including the elevated cap for specified backup and security breaches. Contact [email protected] or frameleaf.app for backup, recovery, security or deletion assistance. Postal correspondence: Frameleaf, Inc., 14 Wall Street, Suite 2000, New York, NY 10005, United States.

Telephone: +1 (332) 287-1911.

More in Frameleaf Cloud services

  • Cloud Connectivity and Relay ScheduleRemote access and the relay, network and administrator responsibilities, encryption and sharing.
  • AI, GPU Processing and AI Credits TermsCloud AI processing, separate authorisation, outputs, no training on your content, credits and spending limits.

All legal documents

Frameleaf

A photo and video library for home servers. The Frameleaf Library community edition is open source under AGPLv3.

GitHub

Features

  • Library & timeline
  • Search & AI
  • People & pets
  • Memories & places
  • Sharing
  • Photo editor
  • Studio
  • For photographers
  • Library care
  • Privacy

Apps

  • iPhone & iPad
  • Android
  • Web app
  • NAS apps

Cloud

  • Frameleaf Cloud
  • Remote access
  • Cloud backup
  • Buddy backup
  • Cloud GPU
  • Pricing
  • Sign in to Frameleaf Cloud
  • Status

Get started

  • Get Frameleaf
  • Try the demo
  • Switch to Frameleaf
  • Install guide
  • Documentation
  • FAQ
  • Open source
  • Photo credits

Legal & policies

  • All legal documents
  • Terms of Service
  • Privacy Notice
  • Acceptable Use
  • Refund Policy
  • Security Policy
  • Cookies
© 2026 Frameleaf. Frameleaf Library community edition licensed under AGPLv3.