Back That Data Up

About

Updated: September 13, 2026

Back That Data Up is made by one developer. It is not a startup, there are no investors, and there is no growth team. The app is funded entirely by one-time purchases, which is why it has no subscription, no ads, no analytics, and no reason to collect your data.

Why it exists

I have a background in federal cyber defense, and I wanted a Mac backup where the security decisions were mine to make and mine to inspect: which encryption, which key derivation, whether a physical key is required, what happens when the cloud copy and the local copy disagree. The tools I tried were either local only, subscription based, or held the keys on my behalf. So I built the one I wanted, and then put a proper interface on it so other people could use it too.

The result is one app that does local snapshots and an encrypted Cloud Vault, with every cryptographic primitive coming from Apple's CryptoKit rather than anything written in house. The full design is public: Security design.

What we do not do

  • We run no storage servers. Backups go to drives you own and cloud accounts you already have. We could not read your files even if we wanted to.
  • No telemetry, no analytics SDK, no crash reporting that phones home. The only network calls the app makes are to your chosen cloud provider, to the update feed, and to validate your license.
  • No account is required for local backups.
  • No data is sold, rented, or shared with advertisers. There is nothing to sell.

What happens if this app disappears

Local snapshots are plain files on your drive, browsable in Finder, with unchanged files hardlinked between snapshots. They need no software to read. Cloud Vault data is encrypted with keys only you hold, in a format documented on the security design page, and a recovery bundle stored alongside your files means a fresh Mac plus your recovery key can rebuild the whole vault without anything from the old machine.

What you can verify yourself

  • Security design document: key hierarchy, file format, threat model, and what the app explicitly does not protect against.
  • security.txt: how to report a vulnerability and what we commit to.
  • Release notes for every version.
  • Refund policy, and purchases handled by Paddle as merchant of record, so you keep the normal consumer protections and we never see your card details.
  • Apple's APFS snapshot entitlement. Crash-consistent backups rely on com.apple.developer.vfs.snapshot, a capability Apple does not hand out by default. Developers have to request it and explain how it will be used, and Apple grants it narrowly to backup apps. Back That Data Up was granted it in August 2026. Apple's conditions are enforced in code: snapshots are never created on system volumes, every snapshot is named so it can be traced to this app, and the app never deletes a snapshot it did not create. Details in the security design.

Publisher

Weitzman Creations LTD
1399 New Scotland Rd #72
Slingerlands, NY 12159
United States

Email: [email protected]
Security reports: [email protected]
Merchant of record for purchases: Paddle.com Market Ltd, United Kingdom.
Governing law: State of New York, United States. See the Terms and Privacy Policy.

Contact

A real person reads every email. Support requests are usually answered within one business day.