Who we are
AlreadyBack LLC, a Wyoming (USA) limited liability company, operates the AlreadyBack services: automated backup, restore, and resilience for data your organization keeps in third-party SaaS platforms (for example, Airtable). This policy explains what we collect, how we protect it, who can read it, and the rights you have over it.
Our privacy philosophy is simple: we collect the minimum needed to operate the Services, we never monetize your data, and we process your backed-up content only on your instructions.
Two kinds of data, two roles
- Your account data — the personal data we collect to run your account: email, name, organization, billing status. For this data, AlreadyBack is the data controller.
- Your backed-up content — the data we copy from the third-party services you connect. It belongs to you. For this data we act strictly as a processor on your documented instructions: we back it up, verify it, and restore it when you ask. Nothing else.
Our Data Processing Agreement (DPA) is incorporated into our Terms of Service and readable in full at /dpa; contact privacy@alreadyback.com only if you need a countersigned copy or bespoke clauses.
What we collect
- Account data: email, name, organization name.
- Connection credentials: the authorization tokens (for example, OAuth tokens) for the services you connect — stored encrypted and used only to run the backups and restores you configure. Revoking our access at the source service stops it.
- Backed-up content: the records, schemas, and file attachments we back up on your instructions, encrypted before storage (see the next section).
- Usage telemetry: cookieless website analytics and technical logs (errors, security events), aggregated or de-identified where possible.
- Payment information: if you purchase a paid plan, payment is handled by our payment provider (a merchant of record). Full card details never touch our systems.
On what legal basis
For the account data we control, we rely on the following legal bases under the GDPR:
- Contract: to create your account, run the backups and restores you configure, and process payments — without this we cannot provide the Services.
- Legitimate interests: to keep the Services secure, prevent abuse, and understand aggregate usage through cookieless analytics — balanced against your rights.
- Legal obligation: to meet tax, accounting, and other legal requirements — for example, retaining billing records.
- Consent: for anything optional we ask you to opt into; you can withdraw it at any time.
For your backed-up content, you are the controller and set the legal basis; we process it only as your processor, on your instructions.
Where the GDPR does not apply, we process personal data as permitted under the applicable law.
Encryption — and who can read your data
Honesty first: any backup service that connects to a SaaS platform’s API — ours included — reads your data in order to copy it. There is no way to back up what you cannot read. What matters is what happens next, and who holds the keys.
- Encrypted before storage: every backup is encrypted with AES-256-GCM before it is written to storage, using keys unique to your organization. Storage providers only ever hold ciphertext.
- Managed keys (the default): AlreadyBack generates and safeguards your organization’s keys. That means our systems are technically able to decrypt your backups. We do so only to run the operations you request — backups, verification, restores — and that access is restricted and logged.
- Bring your own key: on eligible plans, you can replace the managed key with one you provide. We hold your key sealed (never in plaintext) and use it for exactly one purpose — running the backup, verification, and restore operations you schedule or request — and you control its lifecycle: replace it or revoke it at any time.
- Who can access it: access to systems that can reach your data is limited to authorized personnel, granted only when needed to operate or support the Services, and logged.
- What we never do: we never mine, profile, sell, or advertise with your backed-up content — and no AI or machine-learning system ever processes it. Not for training, not for features, not for support. Ever.
For the full picture of our security controls — infrastructure, monitoring, and how to report a vulnerability — see our Security page.
Where your data lives
You choose the storage region for your encrypted backups when you onboard: United States or European Union. The stored copy stays in the region you choose. The systems that run backups and restores operate in the United States, so backup data is processed there transiently in memory during a run, and is never written to persistent storage outside your chosen region. Your account data operates in the United States.
Sub-processors
We use a small set of infrastructure providers to run the Services — hosting, object storage, and transactional email — each operating under data-processing terms consistent with this policy. Our current sub-processors are published at /sub-processors, with at least 30 days’ notice before any change. We never share your data with advertisers or data brokers, and we never sell it.
How long we keep data
- Backup snapshots: kept for your plan’s retention window, shown when you pick a plan and in your dashboard. Expired snapshots are deleted from storage at the end of that window.
- Account data: kept while your account is active, then up to 3 years after closure where legal, tax, or accounting obligations require it.
- Connection credentials: the OAuth tokens for the services you connect are kept until you disconnect the integration or delete your account, then deleted.
- Security and access logs: typically 90 days, unless a security investigation requires longer.
- If your subscription ends: your backups remain available for export for 60 days, then are deleted. If you request deletion of your account data, we delete without waiting for that window.
- Cryptographic erasure: when backups are deleted — at the end of the export window or on your deletion request — the per-organization encryption keys wrapping them are destroyed, rendering the stored ciphertext permanently unrecoverable.
Your rights
Under GDPR (EU/EEA and UK), you can access, correct, erase, restrict, object to, and port your personal data, and withdraw consent at any time. You can also lodge a complaint with your local supervisory authority.
Under US state privacy laws (including the California CCPA/CPRA), you can know what we collect, request deletion or correction, and opt out of the sale or sharing of personal data — we do not sell or share personal data in the first place — all without discrimination for exercising these rights.
To exercise any right: email privacy@alreadyback.com from the address on your account. We verify every request against the email on your account (an authorized agent may act on your behalf with proof), and we respond within 30 days (GDPR) or 45 days (CCPA/CPRA, extendable once by 45 days where the law allows) of receiving your request.
Appeals: if we decline a request, you may appeal by replying to our decision or emailing privacy@alreadyback.com. For manifestly unfounded or excessive or repetitive requests, we may charge a reasonable fee or decline, and will explain why.
No automated decisions: we do not use your personal data for automated decision-making that produces legal or similarly significant effects.
Children
The services are not directed to or intended for anyone under 18. Content relating to children under 13 (or under 16 where EU law applies) may not be backed up through the services — see the data restrictions in our Terms of Service.
Data we refuse by design
AlreadyBack is deliberately not built for regulated high-sensitivity data. Do not use the services to back up protected health information (HIPAA), personal data of children under 13 (COPPA), or under 16 where EU law applies, biometric identifiers (BIPA and comparable laws), regulated financial data (GLBA and comparable), or consumer health data (Washington My Health My Data Act and comparable). The full list and its consequences are in our Terms of Service.
International transfers
If you are in the EU/EEA or UK, some processing (see “Where your data lives”) happens in the United States. Where required, we rely on the EU Standard Contractual Clauses (and the UK Addendum) with our sub-processors, alongside the technical measures described above — encryption before storage chief among them. The transfer safeguards are set out in our Data Processing Agreement.
EU / UK representative
Whether GDPR Article 27 (or UK GDPR) requires an EU/UK representative depends on the scale and nature of our processing of EU/UK personal data. Where it applies, we will appoint one — through our selected provider — before onboarding the customers concerned, and publish their contact details here.
Changes to this policy
We may update this policy as the services and the law evolve. Material changes get at least 30 days’ notice by email and in-app before they take effect, with the change summarized in plain language.
Contact
Privacy questions, rights requests, or complaints: privacy@alreadyback.com · AlreadyBack LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA.