The detail
Backup, recovery, and leaving.
The short version is on the data page. This is the long version, for the people whose job is to ask — what we can restore, how fast, and what happens to your workspace if you close your account.
And if you need us.
Some things still need a person. Here is what happens, and roughly how long it should take. These are targets we work to — not contractual guarantees.
Getting specific data back
Tell us what was lost and roughly when. We rewind a copy of the database to that moment, pull out what you need, and put it back. Our target is within a day of a confirmed request.
Rolling the whole workspace back
A full restore of your workspace to an earlier point is possible. We only do it with your written authorisation, because it discards everything entered since.
A major hosting outage
If our primary region fails, we restore the database from the copies held in a second region and rebuild there. Our target is eight hours to be back online once the database is restored; the most recent cross-region copy can be up to a week old.
The detail, for the people who ask for it.
Every number here comes from our Backup & Disaster Recovery Policy. It is an internal document, and we share it with customers and prospects on request — ask us for a copy.
Continuous backup, one-year horizon
We can rewind your data to any five-minute point in the last two weeks. Beyond that we keep discrete restore points on a rolling schedule: daily for two weeks, weekly for two months, monthly for a year.
Copies in a second region
Weekly and monthly database restore points are copied to a second geographic region, encrypted with a separate key.
Uploaded files keep their old versions
Overwrite or delete a file and the stored copy is kept as a previous version for 30 days, so we can put it back.
Backups are locked against early deletion
Our backup vaults are locked: a restore point cannot be removed before its retention expires. Lifting that lock takes a separate, privileged action, and every such action is logged.
Restore testing on a six-month cadence
Our policy commits us to restoring a real snapshot into an isolated environment every six months and recording the result, pass or fail. The first test under the current policy is due by September 2026 — we will not claim a passing result before there is a dated one.
On the roadmap
S3 cross-region replication for uploaded files is on the backlog — we don't claim it yet.
Your data is yours to take.
Leaving is a supported path, not a negotiation. The steps below are what our Data Retention & Deletion Policy commits us to — ask us for a copy.
Export before anything is torn down
While your account is open you can export at any time from Admin settings, without telling us. When you close it, we agree the final export with you first; the workspace is then held for 30 days before it is purged.
Then we delete it
An automated cascade removes your records, your uploaded files, your connected-integration tokens, and your API keys.
And we put it in writing
You get a written confirmation naming exactly what was removed: the workspace, how many rows, how many bytes of files.
Backups age out on their own schedule
Copies inside our encrypted backups expire on the retention schedule above, not on the day you leave. That is inherent to having backups at all — we would rather tell you than let you assume otherwise.
