Backups and sync: the copy you did not decide to make
Almost every modern device makes copies of itself somewhere else, automatically, as a feature. The copies are the point of the feature, and they are also the quietest thing in this section.
The backup provider · The account holder · Anyone who signs into the account
Break the sentence into its parts, because each part carries weight. A backup is a copy you did not consciously make. It is held by a party you did not choose, usually whoever made the device. It sits in a jurisdiction you did not pick, wherever that company keeps its storage. And it is attached to an account, which means an identity that can be asked about.
None of that is sinister. Backups exist because people lose phones and drop laptops, and the feature is genuinely useful. It is also the single largest difference between a machine that holds a record and a record that has left the machine.
What a backup ends up holding
Automatic phone backups
Phones commonly back themselves up whenever they are charging and on wifi, which is nightly for most people. Depending on the platform and the settings, that backup can include app data, message databases, call history, settings and photographs. It is designed to be complete enough to restore a phone from nothing.
Desktop sync folders
A synced folder is a folder that is also somewhere else. Anything placed in it is uploaded within seconds. The trap is that these folders are frequently the default location for the desktop, the documents folder and the downloads folder, which means the default place a browser saves a file may be a synced place. Most people know they use a sync service. Far fewer can say which local folders are inside it.
Browser profile sync
Ordinary browsers offer to sync history, bookmarks, open tabs, saved passwords and autofill entries to an account, so a new machine feels like the old one. Tor Browser does not. But most people run more than one browser, and an address typed into the wrong window is an address in a synced profile. The mistake is not the syncing, it is the window.
Message app backups
This one surprises people the most. An application can encrypt messages in transit perfectly well and still write a backup of the message database to a general purpose cloud account, where the protection is whatever that account provides. Whether that backup is separately encrypted varies by application and by setting. The end to end promise covers the wire, not the archive.
Photo libraries
Photo libraries upload continuously and keep deleted items in a recovery area for a period, by design, because people delete things by accident. A screenshot is a photograph as far as a library is concerned. See screenshots and photos for what those files carry with them.
What a backup does not hold
It does not hold what was never on the device. A page you looked at and did not save is not in a backup, because a backup copies files rather than sessions. That is the main reason the distinction on what lands on the disk matters: incidental system scratch is generally not what backup software targets, and deliberately saved files are exactly what it targets.
It does not hold your browsing over Tor. No backup product reconstructs which sites a browser visited when the browser did not record it. What ends up in the backup is artefacts: images, downloads, notes, message archives. A synced clipboard is the odd exception, and that lives on the clipboard.
And a provider does not, in the ordinary course of things, read your files for interest. The relationship is a storage relationship. The point is not that somebody is looking, it is that the copy sits in a place governed by an account, terms of service and a legal system, and those are the mechanisms through which anybody ever looks.
The lag that catches people
Sync is fast and deletion propagation is slow, and the asymmetry is deliberate. Uploading immediately is a feature. Deleting immediately everywhere is a hazard, because most deletions are mistakes. So providers keep versions and a recycle area, for a stated period.
The practical result: the window in which a file exists only on your machine is measured in seconds. The window in which it exists only in the remote copy, after you removed it locally, can be weeks.
What changes the answer
5 things change how much this action gives away. None of them takes it to zero, and none of them is a promise.
- Know which local folders are syncedThis is a fact you can establish in a minute and most people never have. Once you know, you know whether saving a file is a local act or a remote one. Knowing does not remove anything already uploaded.
- Do not save into a synced folder by accidentBrowsers have a default download location and it is often a synced one, as files you downloaded sets out. Choosing a different destination is a boring decision with a large effect. It has no effect on files already there.
- Treat a message backup as a separate question from the messageHow an application protects messages while they travel and how it stores an archive are two different designs with two different answers. Reading what an app says about backups is the only way to know which you have. This does not alter messages already archived.
- Remember the recovery areaPhoto libraries and file services keep deleted items for a period before they go. Emptying that area is part of a deletion, not an extra. It still says nothing about backups held under a different account or on a different device.
- Fewer durable files means fewer copiesEvery mechanism on this page acts on files. A record you decided not to create is a record that has nothing to copy. That is the only reducer here that works on all five mechanisms at once.
What this card is not
This card describes how consumer backup and sync features behave in general. It does not describe any named service and makes no claim about what any specific provider stores or retains.
Questions that come up
If my messages are end to end encrypted, is the backup encrypted too?
Not necessarily, and they are separate questions. Encryption in transit protects the message while it moves between devices. A backup is a copy of the local database written somewhere else, and whether that copy is separately encrypted depends on the application and on a setting.
Does deleting a file locally delete it from the backup?
Sometimes, eventually, and usually not straight away. Sync services typically keep deleted items in a recovery area for a period and may keep previous versions as well. A local delete should be read as one copy removed, not as the file being gone.