2BrightSparks

Backup Software and Your Privacy: What We Collect, and What We Don't

Backup software is in an unusual position. To do its job it has to be able to read everything you own: your documents, your photographs, your accounts, your correspondence, your business records. You are not installing a game or a text editor. You are handing a program the keys to the whole filing cabinet.

That is a lot of trust to ask for, and we think you are entitled to know exactly what we do with it. This article sets out what SyncBack sends to us, what we store, what we deliberately never ask for, and where you can check any of it for yourself.

TL;DR

Your files never pass through our servers. SyncBack has no account to create, no telemetry, no analytics and no advertising. If you buy a licence we hold your name, your email address and the order details our payment processor passes to us, and the email address exists so that you can recover your own licence if you lose it. We never ask for your postal address, your age, your gender, your occupation or your income, and we have no way of recovering your encryption passwords, by design.

Why the stakes are higher for backup software

Most software can only see the small part of your computer it needs. A photo editor sees photographs. An accounts package sees invoices. Backup software is different, because a backup that skips things is not really a backup. By the time it is configured usefully, it can read your entire user profile and often whole drives.

Two things follow from that. The first is that a backup program which quietly reports on what it finds would be an extraordinarily rich source of information about you: what software you run, what you are working on, what your file names say about your business, when you are at your desk. The second is that if the software routes your data through the vendor, then the vendor is now holding a complete copy of your life, and their security failures become your security failures.

We designed SyncBack so that neither of those is possible. It is not a policy we could quietly reverse next quarter, because the plumbing that would be needed does not exist in the product.

What our software does not do

There is no account to create

You do not sign up to use SyncBackFree. You download it, install it, and it works. There is no registration wall, no email confirmation step, no profile, and no dashboard on our website showing what you have been backing up. SyncBackPro and SyncBackSE are activated with a serial number, which is a licence key and not an identity.

This is worth stating plainly because a lot of software now treats the account as the product. Once there is an account, there is a login history, a device list, a usage record and a support ticket trail, all tied together under one identifier. We never built that, so there is nothing there to leak, subpoena or sell.

There is no telemetry

This applies to all three versions. SyncBackPro, SyncBackSE and SyncBackFree do not collect usage statistics, do not build a profile of how you use them, and do not send anonymised or aggregated behavioural data back to us. We do not know how many profiles you have created, what you have named them, which features you use, what drives you own or what is on them.

There was once a feature called Runtime Intelligence which could send anonymous usage information back to us. It was strictly opt-in, it was never enabled unless you chose it, and even then it collected nothing personal: no serial numbers, no email addresses, no file or folder names, no IP addresses. We removed it entirely in V11.3.35.0 on 1st July 2024, in SyncBackPro, SyncBackSE and SyncBackFree alike. Our original article on Runtime Intelligence is still on the site for reference. We mention it because anyone running a much older release may remember being asked, and we would rather explain it here than have it look like something we had quietly left out.

People sometimes assume this must be a limitation of a small company. It is not. Collecting that data would be easy and it would genuinely be useful to us, which is precisely why we think the decision not to collect it means something. We find out what our users want the same way software companies used to: they tell us, on the forum and through support tickets.

The same applies when something goes wrong. If SyncBack hits an unexpected error, the report is saved to a file on your own computer and nothing is sent automatically. When you are using the program interactively you are shown the report and can choose to send it, and if you do it goes directly from your computer to our support address. During a scheduled or unattended run the report is simply written to disk and nothing is sent at all.

If you do decide to send one, you are entitled to know what is in it, because it is a good deal more than the stack trace. A crash report contains your serial numbers, held encrypted within the report, along with your Upgrade Assurance serial, a session identifier, the path to your temporary folder and how much free space it has, the list of modules loaded into the program, and the stack trace itself. It also carries the standard diagnostic header, which includes your computer name, your Windows user name, the Terminal Services client name if you are using one, the registered owner and organisation held in Windows, and the command line the program was started with, which on a scheduled run names the profile that was running. You see all of this before it goes anywhere, and if you would rather not send it then nothing leaves your machine.

The Technical Support Wizard works the same way: it builds an encrypted archive of logs and settings on your disk and uploads nothing at all. You choose whether to attach it to a support ticket.

There are no advertisements in our software, no nag screens in the paid versions, and no third-party components bundled into the installer. You can read more about that on our No Nasties page.

Your files never pass through our servers

This is the single most important point in this article. SyncBack copies files from a source you choose to a destination you choose. If that destination is an external drive, the data goes to the drive. If it is a network share, it goes to the share. If it is an FTP or SFTP server, it goes to that server.

The same is true of cloud destinations in SyncBackPro. When you back up to Amazon S3, Microsoft Azure, OneDrive, Google Drive, Dropbox, Backblaze B2 or any of the other supported services, you are using your account with your credentials, and the program connects to that service directly from your machine. We are not in the middle. We do not resell storage, we do not proxy the transfer, and we could not read your backups even if we wanted to.

Compare that with a subscription backup service, where the whole design depends on your files living on the provider's infrastructure. Neither model is dishonest, but they ask for very different amounts of trust, and it is worth knowing which one you are buying.

What the update check actually does

We would rather set this out in full than let it look like something we are glossing over, because this is the main occasion on which the program contacts us on its own. There are three others, all of them narrow, and they are listed at the end of this section.

First, when it happens. The check is only made while SyncBack is open in front of you. We never make it during a scheduled run, a command line run, or any other unattended run, so a machine that wakes at 2am purely to run a backup does not contact us on our initiative at all. By default the check happens at most once every 30 days, and you can switch it off entirely in Preferences. Administrators deploying the software across an organisation can also set a different interval, or disable the check, at installation time.

There is one way to make it happen unattended, and it is entirely yours to choose. SyncBack offers profile variables that report the latest available version, and putting one of those into a profile tells the program to look that value up while the profile runs, because reporting it is what you asked for. From V12.1.7.0 onwards this applies only to the variables whose names end in ONLINE, which exist for exactly this purpose; in earlier releases it applies to the version variables generally. If you never use one, it never happens. Either way the request is the same bare download of a text file, carrying nothing about you or your machine.

Second, what it sends. The version check itself requests a small text file from our web server containing the current release number, and compares it locally with the version you have installed. That request carries nothing at all: no query string, no identifiers, nothing about you, your licence or your machine.

Third, the exception, which we would rather you heard from us. If you are running a licensed copy of SyncBackPro or SyncBackSE, the same check also asks whether your Upgrade Assurance is still current, and that request does include your serial number, along with which edition and version you are running. It has to, because there is no other way to answer the question. Nothing else travels with it: no name, no email address, no machine or installation identifier, no hostname, and nothing whatsoever about your profiles or your files. What comes back is your subscription dates and, if you have one, the month and year your payment card expires, which the program displays to you. SyncBackFree never makes this call at all, since it has no serial number.

Like any request to any website, all of the above reveals the IP address it came from, which is simply how the internet works.

The update check never installs anything

If a newer version is available, SyncBack opens your web browser at our download page and stops there. It does not download or install anything by itself, and it never has. Any change to the software on your machine is a decision you make deliberately.

Checking your licence is a separate matter from Upgrade Assurance, and it happens entirely on your own computer. There is no activation server, no licence is registered against your hardware, and no check with us is needed for your copy to work. Installing the program contacts us for nothing, and neither does starting it. If our servers disappeared tomorrow your copy would carry on working exactly as before.

One clarification, since it would otherwise look like a contradiction: when you first enter a serial number the program offers to fetch your Upgrade Assurance details for you, and saying yes sends your serial as described above. That is an offer you can decline, and declining it does not affect your licence. You can enter an offline Upgrade Assurance serial instead.

The three remaining cases are these. If you use SyncBack Touch, the program makes a second version check of the same kind, sending nothing, to tell you whether your Touch device is out of date. If you click the link asking us to email you a link to your Customer Account Portal, that request sends your serial number so we can look up the address to send it to. And if you run an FTP profile in active mode, with the external address either set to be worked out automatically or left blank, the program asks our server what your own public IP address is, sending nothing, because the FTP server needs to be told where to connect back to. Passive mode, which is the default, never does this.

That is the complete list. Everything else SyncBack connects to is a destination you configured yourself.

If you use the AI features

SyncBackPro has optional AI features, available in builds with scripting and switched off unless you set them up. They are worth a word here because they are the one part of the program that can send the contents of your setup somewhere.

You supply your own API key for whichever provider you choose, and the requests go directly from your computer to that provider. A prompt can include profile settings and extracts from your run logs, so that material does go to the provider you selected, and you should treat it the way you would treat anything else you send to an AI service. We are not in the path, we do not proxy it, and we receive nothing from it. If you never turn the feature on, nothing is ever sent.

Encryption with no backdoor

When you encrypt a backup with SyncBack, or encrypt a file with EncryptOnClick, the password is yours alone. We do not hold a copy, there is no master key, there is no recovery service, and there is no escrow arrangement with anyone.

The honest consequence is that if you lose the password, the data is gone, and no amount of contacting support will change that. We are asked to recover forgotten passwords fairly regularly and the answer is always the same. A vendor who could help you in that situation would be a vendor who could also be compelled to help someone else. We would rather disappoint you occasionally than hold a key to your data. Our article on data encryption explains how this works in more detail.

What we hold about you, and why

If you buy a licence, a record is created containing your name and your email address, along with the details of the order itself: which product, which version, the amount, the currency and the invoice reference. Our payment processor also passes across a company name and a country where the checkout collected them, plus the last four digits of the card so that a payment can be matched to an order. We never receive your full card number.

The country is not idle curiosity on our part. Sales tax and VAT obligations depend on where the customer is, so an order cannot lawfully be processed without it. The company name is there because business customers need it printed on their invoice.

The email address is the part that matters, and it is not there so that we can market to you. It is there so that you can get your own licence back. Serial numbers get lost. Hard drives fail, machines are replaced, people change jobs, and the email containing the licence details disappears with the old mailbox. When that happens, the email address is what lets us find your record and send your serial number to the address it was issued to. Without it we would have no way of telling a genuine customer apart from someone who simply knows their name.

It is also how we reach you if something matters: a security issue, a serious bug, a problem with your order. Our mailing list is separate and entirely optional. You opt in, and you can remove yourself at any time without contacting us.

What we deliberately never ask for

We do not want, and do not ask for:

  • Your postal address. On the rare occasion a customer needs one printed on an invoice for their own accounting they give it to us and we add it, but we never request it and we do not need it in order to sell you anything.
  • Your telephone number. Our payment processor shows an optional field for one at checkout and we cannot remove it from their page, but we no longer record it. We stopped storing it in September 2026 and erased the numbers we had.
  • Your age, date of birth, gender, occupation, income or marital status.
  • Your card number. Our payment processor holds that and does not pass it to us.
  • Any tracking identifier that would let us recognise you on somebody else's website.
  • Anything at all about the contents of your computer, the software you run, or the backups you create.

The reasoning is simple. Data you have never collected cannot be stolen from you, cannot be sold by a future owner of the business, cannot be handed over in a legal demand, and cannot be quietly repurposed years later by someone who was not in the room when the promise was made. The safest possible place for your personal information is with you.

The third parties we cannot avoid

We would be overstating our case if we implied that no company but ours is ever involved. A few are, and you should know who they are and why.

  • FastSpring is our webstore and Merchant of Record. They take the payment, hold the card details, and issue the invoice. We chose to pay a specialist to do this rather than handle payment data ourselves, which costs us money and is the right trade.
  • Freshdesk runs our support ticketing. If you open a ticket, whatever you choose to put in it is stored there. That is entirely under your control, and we would gently suggest not pasting anything into a support ticket that you would not want stored.
  • Our forum is public by design. A username and an email address are needed to register, and you decide what appears on your profile.
  • Website analytics. Like most sites, we use analytics to understand which pages are useful. This applies to the website only. It has nothing to do with the software on your machine, and you can block it in your browser without affecting anything you have downloaded or bought.

All of these are named, along with links to their own privacy policies and instructions for removing your data from them, in our Privacy Statement. If any of it changes, that page changes.

What this position costs us

It would be easy to present all of the above as pure virtue, so it is worth being clear that it has a price, and that the price is the reason it is credible.

We have no behavioural data to sell, and no advertising profile to build. We cannot tell an investor how many monthly active users we have or how engaged they are, because we genuinely do not know. We cannot run the kind of targeted campaign that depends on knowing a customer's age and location. When we redesign part of the program we do it based on what users tell us, not on a heat map, which is slower and occasionally means we get it wrong.

Our licences are also a one-time purchase rather than a subscription. Upgrade Assurance exists for customers who want future major versions included, but it is optional, and choosing not to buy it does not stop your software working. Recurring revenue is easier to run a business on. We understand perfectly well why the rest of the industry moved that way.

We have been doing this since 2003 and we are still here, so it evidently works well enough. But it is a choice with real costs attached, not a lucky accident.

How to check any of this for yourself

You should not take a software company's word for what its software does, including ours. A few things you can do:

  • Watch the network. Run SyncBack behind a firewall that logs outbound connections, or use a tool such as Wireshark, and see what it contacts. Apart from the destinations you configured, and the occasional calls listed above, you should see nothing going to us.
  • Block us entirely. Turn off the update check in Preferences, or firewall the program off from the internet altogether. Local and network backups will carry on working normally. Software that depends on calling home cannot pass that test.
  • Read the Privacy Statement. Our Privacy Statement is the binding document, and it is deliberately more detailed than this article. If the two ever appear to disagree, the Privacy Statement is the one that counts, and we would want to know about the discrepancy.
  • Ask us to delete your record. You do not need to cite legislation at us. Ask us and we will remove what we can. In practice a small amount of transaction information has to survive, because tax and accounting rules require us to keep records of sales for a number of years, and that is a legal obligation rather than a preference on our part. Everything beyond that can go. The one thing worth knowing is that deleting your record also removes our ability to recover your serial number for you later, so keep your own copy first.

Conclusion

We are not claiming to be saints, and we are wary of companies that market their own decency. What we can say is narrower and more checkable: your files stay yours, the software does not report on you, there is no account tying your activity together, the customer record we keep is a name, an email address and an order history so that you can recover your own licence, and we have deliberately built ourselves out of any position where we could read your data or unlock your encryption.

Those are testable claims rather than sentiments, which is the point. If you ever find us falling short of one of them, tell us, and we will either fix it or correct the record here.

Further reading: our Privacy Statement, our Terms and Conditions, the No Nasties page, and our article on 100% freeware.

Noted Customers

© 2003-2026 2BrightSparks Pte. Ltd.  | Home | Support | Privacy | Security | Terms | Affiliate Program

Home | Support | Privacy | Security | Terms
© 2003-2026 2BrightSparks Pte. Ltd.

Back to top