Security & sync

Continue on another computer.

When uploads are allowed, closing an account encrypts its data locally before backup. Restore existing data on another device; conflicting edits are not automatically overwritten or merged.

Each account is encrypted separately

A problem with one account does not directly expose the others.

Encrypted before upload

When an account closes, data is encrypted on the device before upload and restored by a signed-in client.

Recovery after mistakes

Deleting an account keeps a recovery path for a period of time instead of immediately losing the data.

Prevent two computers from overwriting each other

Multiple devices can run an account. Uploads reject conflicting old versions and preserve local changes.

How backups work

  1. 01

    Check for newer data

  2. 02

    Download a backup when needed

  3. 03

    Restore and open the account

  4. 04

    Back up again when it closes

Data lifecycle

Understand local data and recovery in four stages.

Sync is not one vague cloud switch. Device upload policy, encryption timing, runtime ownership, deletion, and recovery each have a separate boundary.

The browser runs on the current device first.

Every account uses its own data directory. Proxy testing, exit-timezone checks, and AI connections run in the client rather than being performed by the website.

  • Cookies, site data, and extensions stay with the account
  • The real proxy exit is checked before each launch
  • Closing MaskPilot stops its local AI connection

Missing settings never enable upload by accident.

“Do not sync account data” belongs to the current device. While enabled, local changes are not uploaded, but an existing remote backup can still be read when the device has no usable data. Upload resumes only after you turn this setting off.

  • The setting does not follow the account to another device
  • Local data and pending changes remain available while upload is blocked
  • Confirm which copy should continue before allowing upload again
Read about the device sync setting

When upload is allowed, encryption happens locally after close.

The client prepares and encrypts account data before uploading an encrypted package. Accounts are encrypted separately, and the service keeps the key needed to restore one on another device.

  • Encryption completes before upload
  • Every account has a separate encryption boundary
  • The service does not claim it can never decrypt data

Version checks protect cloud data; recovery records handle mistakes.

Multiple devices can run the same account; conflicting uploads are not automatically merged. Deleting its active record keeps a recovery snapshot and existing cloud-data reference, but no fixed retention period is promised and local changes that were never synced are not uploaded later.

  • Only the account owner can restore it
  • Recovery stops when the previous proxy is now in use elsewhere
  • Recheck plan capacity, proxies, extensions, and member assignments after restore
Read the recovery guide

Confirm the data boundary first

Check local data before changing sync settings.

Use a test account to complete one normal close and recovery check before allowing a device to upload production account data.