Backups and the recovery passphrase
What's backed up, how the two passphrases work, and the honest tradeoff behind a promise we take seriously.
Everything Singer Intelligent Homes backs up is encrypted inside your home before it leaves. We hold the locked box; you hold the only key. We can hand it back — we can never open it.
This is what makes backups key-blind: we store ciphertext, never the key that decrypts it. That’s not a marketing line we’re hedging on — the tradeoff behind it is real, and this guide covers both sides of it: what’s protected, what the two passphrases are for, and what happens if the recovery one is ever lost.
What’s backed up
Nightly snapshots cover your whole home: the inventory, spaces, devices, and Charyl’s own records, plus every photo and document you’ve stored. All of it is encrypted before it ever leaves your house.
| What | What we can see |
|---|---|
| Your database (inventory, spaces, devices, Charyl’s own records) | Only the encrypted bytes |
| Photos and documents you’ve stored | Only the encrypted bytes |
| The file list and hashes | Encrypted — even file names can say more than you’d want |
| Your home’s id, backup size, and timestamps | Plain — needed to bill and retain backups correctly |
The schedule
Nightly, at 02:00 your home’s local time, by default. If your home stays offline for more than about a day and a half, you’ll get an alert email — no content, just that a backup was missed — and a catch-up run happens automatically as soon as you’re back online. Backups require your home to be paired with Charyl Cloud; see Connect your home to Charyl Cloud.
Two passphrases, two jobs
- Your daily passphrase decrypts the encryption key during normal, day-to-day operation. You set it once, when you turn backups on, and your box uses it automatically after that.
- Your recovery passphrase is different. It’s used only to recover a home onto a brand-new machine, and it’s the one you write down and keep somewhere safe — not the one you type every day.
The tradeoff, stated plainly
“We can’t read it” and “we can rescue it without you” can’t both be true — we chose the one that protects you.
If you lose both your recovery passphrase and the machine your home runs on, there is no way for anyone, including us, to get your data back. You confirm you understand exactly that before backups turn on. It’s the honest cost of a backup we genuinely cannot read.
Most losses are recoverable
In practice, the passphrase is the part people lose — the machine usually isn’t gone too. As long as your box is still alive, it can reset your recovery passphrase to a new one without needing the old one at all, because the piece that makes that possible lives on the box itself, not with us. That makes a lost passphrase a recoverable mistake, not a permanent one, for most real situations.
Two things help you avoid needing that at all: a printable recovery kit — generated on your own box, never sent to us — that’s worth keeping with your other important documents, and an occasional reminder to make sure you still have your passphrase somewhere safe.
What we chose not to build
Splitting your recovery passphrase among trusted contacts, or offering to hold a recovery option ourselves, would both make a lost passphrase easier to survive — and both would quietly weaken the “we cannot read it” promise. We’ve deliberately held off on either until there’s real-world experience with the prevention side to show it’s actually needed.
Two ways to restore, and they’re not the same thing
| Rolling back on this box | Recovering onto a new machine | |
|---|---|---|
| Needs your recovery passphrase? | No — the box still holds its own keys | Yes |
| What it’s for | Undoing a mistake, or a bad update, on the box you’re already on | A dead machine, a theft, or a genuinely fresh start |
| What happens | You pick a backup from a list; the box restarts into a restore, then comes back up on your data | You enter your recovery passphrase; a new box fetches your encrypted backup, unwraps the key, and restores onto it |
Related