--- title: Backup and restore description: How your calendar can survive a lost phone without a Calendite account, what the backup actually contains, and why the password is never stored. order: 15 --- # Backup and restore Calendite has no account, so there is no server holding a copy of your calendar for you. That leaves an obvious question: what happens when the phone goes in the river? The answer is a **sealed backup** carried by the phone's own backup system. Calendite writes an encrypted bundle and hands it to Android; Android puts it wherever it puts backups, which for most phones means your Google account. Nobody along that path can read it. > **Android only for now.** --- ## Choosing a mode The last step of the [setup wizard](/docs/getting-started.html) — *Protect Your Backups* — asks once, and More → **Backup & restore** changes it at any time. | Mode | What it means | |---|---| | **No Backup** | Nothing is made eligible for cloud backup. Your database stays only on this device. | | **Encrypted Backup** *(recommended)* | The bundle can only be opened again with a password you choose. | | **Standard Backup** *(not recommended)* | Recovery leans on Android's own backup protection, with no password of your own. | The difference is **not** whether the backup is encrypted — it always is. The difference is what lets a *new* phone open it. Encrypted mode wraps that recovery material under your password; standard mode leaves it to the platform, which is weaker and labelled so. --- ## What is in the bundle - A snapshot of the calendar database: events, series, tags, alerts, categories, sharing state. - Your [event notes](/docs/everyday-use/notes-and-descriptions.html), zipped in. They are plain Markdown files on disk, which Android is told not to back up; archiving them into the sealed bundle is what makes them restorable *and* encrypted, rather than lost or copied out in the clear. What is deliberately **not** eligible for the phone's backup: the live database itself, the app's preferences, and the notes as they sit on disk. One directory is eligible, and it contains only the sealed bundle. The snapshot is sealed with a key derived from a master key that lives in the device's secure element. Your password never becomes that key directly — it unwraps it, through [Argon2id](https://en.wikipedia.org/wiki/Argon2), a deliberately slow, memory-hard derivation that makes guessing a stolen bundle expensive rather than cheap. --- ## Keeping it current **Back Up Now** re-seals whatever is in the database at that moment. It needs no password: the key it seals with is already on the device. Changing *to* encrypted mode, or changing the password, does need the password, because that is the part it re-wraps. After that, when the bundle actually leaves for the cloud is Android's decision — typically while charging, idle and on Wi-Fi. Calendite tells the system there is new data; it does not get to choose the moment. --- ## Restoring On a new phone, or after a reinstall, the setup wizard opens on **Welcome Back** instead of its usual first step. It reads the bundle's unencrypted header, so it can tell you which mode it was made in and when, before you type anything. Restoring replaces the events, tags, country and work pattern the rest of the wizard would otherwise collect, which is why it comes first. What it cannot bring back is **permissions** — those belong to the install — so the wizard still asks for those, and then gets out of the way. - A **wrong password** says so and leaves the backup untouched. Try again. - **Set up as new** is a delay, not a decision: the backup stays put, and More → **Backup & restore** offers *Restore from backup* whenever you do find the password. - **Delete this backup** on that screen removes it for good. --- ## Lost passwords The password is used and then discarded — it is never stored, on the device or anywhere else. That is the property that makes the backup worth having, and it has exactly the consequence you would expect: **nobody can recover an encrypted backup without its password.** Not you, not us. Put it in your password manager when you set it. The restore screen says as much, because that is the moment people wish they had. --- ## Next - [What leaves your device](/docs/privacy/what-leaves-your-device.html): where the backup sits in the complete list - [How the encryption works](/docs/privacy/how-the-encryption-works.html): the library doing the sealing - [Troubleshooting](/docs/troubleshooting.html)