Docs

How it works

This page follows your data from your device to storage and back, and explains what Clawgnition can and cannot see along the way. If you want to know exactly what you are trusting us with, read this.

The short version

centraid seals a copy of your vault on your device, then uploads those sealed bytes straight to storage. Clawgnition arranges the storage and keeps track of your versions, but never touches the readable contents. When you need your data back, centraid pulls the sealed bytes and unseals them on your device.

The journey of a backup

  1. Your vault lives on your device. centraid keeps your notes, files, and memory locally — usually a database plus your media.
  2. centraid makes a snapshot and seals it. A snapshot is a point-in-time copy of your vault. centraid encrypts it on your machine using a key that never leaves the device. The result is sealed bytes: encrypted data that is meaningless without your key.
  3. The sealed bytes upload directly to storage. centraid asks Clawgnition for short-lived, tightly-scoped permission to write to your vault's storage area, then sends the bytes straight there. The upload does not pass through Clawgnition's servers as readable data.
  4. Clawgnition records that a snapshot landed. We note the new version, keep your version history in order, and update how much storage you are using. We store the encrypted bytes and this bookkeeping — nothing else.
  5. You get a new version to roll back to. Each snapshot becomes a version in your recovery window.

The two halves: control plane and data plane

It helps to picture Clawgnition as two separate things:

  • The control plane is the part you log into and that centraid talks to. It manages your vaults, hands out short-lived storage permissions, records your snapshots, tracks usage, and keeps your version history. It never reads your file contents.
  • The data plane is the storage itself, where the sealed bytes actually live. centraid moves bytes to and from it directly, using the short-lived permission the control plane issued.

Keeping the bytes off the control plane is deliberate. It is what lets large vaults move quickly, and it is part of why we never see your data.

What Clawgnition holds — and what it never holds

We hold We never hold
Sealed (encrypted) snapshot bytes we cannot read Your encryption keys
Bookkeeping: byte and object counts, snapshot order, version state The readable contents of your vault — file names, sizes, or text
Account basics: your email, billing state, usage totals Long-lived storage credentials (the ones we issue expire quickly)

Because your key never reaches us, we cannot recover your data if you lose that key. This is the flip side of real privacy: only you can unseal your vault. Keep a safe copy of your encryption key as centraid guides you to. See Your keys.

Nothing of ours runs inside your app

There is no Clawgnition plugin, SDK, or library that lives in centraid or your code. The connection is just three values you paste into centraid's settings (see Guided setup). This is on purpose: your ability to restore or leave should never depend on our software being installed somewhere.

Getting your data back

Restores and exports work the same way in reverse: centraid asks for short-lived, read-only permission, pulls the sealed bytes straight from storage, and unseals them on your device. Because only your device holds the key, restoring always runs through centraid — never through the dashboard. Reading your data back is always free. See Restoring and Leaving.

Common questions

If the bytes go straight to storage, how does Clawgnition know a backup happened?

centraid tells the control plane when a snapshot is complete, and that registration is the official "a backup landed" moment. It is also what the freshness check watches. See Staying fresh.

Can an employee at Clawgnition open my vault?

No. The bytes are sealed with a key we never receive. An operator can see that a vault exists and how much space it uses, but not what is inside it. See Privacy & security.

Does the sealed data include my file names and folder structure?

No. The internal layout of your vault is inside the sealed data, opaque to us. We keep only the counts and version bookkeeping needed to store and list your snapshots.