Each account is encrypted separately
A problem with one account does not directly expose the others.
Security & sync
When uploads are allowed, closing an account encrypts its data locally before backup. Restore existing data on another device; conflicting edits are not automatically overwritten or merged.
A problem with one account does not directly expose the others.
When an account closes, data is encrypted on the device before upload and restored by a signed-in client.
Deleting an account keeps a recovery path for a period of time instead of immediately losing the data.
Multiple devices can run an account. Uploads reject conflicting old versions and preserve local changes.
How backups work
Check for newer data
Download a backup when needed
Restore and open the account
Back up again when it closes
Data lifecycle
Sync is not one vague cloud switch. Device upload policy, encryption timing, runtime ownership, deletion, and recovery each have a separate boundary.
Every account uses its own data directory. Proxy testing, exit-timezone checks, and AI connections run in the client rather than being performed by the website.
“Do not sync account data” belongs to the current device. While enabled, local changes are not uploaded, but an existing remote backup can still be read when the device has no usable data. Upload resumes only after you turn this setting off.
The client prepares and encrypts account data before uploading an encrypted package. Accounts are encrypted separately, and the service keeps the key needed to restore one on another device.
Multiple devices can run the same account; conflicting uploads are not automatically merged. Deleting its active record keeps a recovery snapshot and existing cloud-data reference, but no fixed retention period is promised and local changes that were never synced are not uploaded later.
Confirm the data boundary first
Use a test account to complete one normal close and recovery check before allowing a device to upload production account data.