---
title: Is my data encrypted?
---

# Is my data encrypted?

## What it is

This is a map of what Omniscio encrypts and what it doesn't, so you can find the
exact answer fast. Each row links to the page with the full details.

## Where to find it

There is no single screen that answers this — it is spread across the encryption settings at **Settings → Security**, the backup settings, and what your operating system does for you. This page is the map that points at each one.

## How it behaves

### Short answer

The **copies** Omniscio makes of your data — the automatic backups, the cloud
mirror — are encrypted. Two of them are encrypted **conditionally**, and the
table below says exactly when: an automatic backup is written unencrypted if
your OS keychain is unavailable, and the weekly configuration bundle is emailed
unencrypted until you set a passphrase. Your **secrets** (API keys, account
logins, integration tokens) are encrypted. The **live database
Omniscio is actively using** is not encrypted by default — it sits on your disk
protected by your computer's normal login and, if you've turned it on,
full-disk encryption like BitLocker (Windows) or FileVault (Mac) — but you can
now **optionally turn on encryption for the live database at rest**. →
[Database Encryption](database-encryption.md).

### What's encrypted, surface by surface

| Your data                                                                                                                        | Encrypted at rest? | Details                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------------------------------------- | ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Automatic local backups** (every few hours + the "Back up now" button) and the **cold-storage archive** of older conversations | ✅ Yes — unless your keychain is unavailable | AES-256-GCM, using a key kept in this computer's system keychain — so a backup folder copied to another machine is unreadable there. Restoring is automatic on this computer. **The condition:** the key lives in the OS keychain, and when that keychain is unavailable (a headless launch, a reset credential store, a changed OS account) Omniscio deliberately writes the backup **unencrypted** and warns you rather than skipping the backup and leaving you with no copy. → [Are my automatic backups encrypted?](database-compaction.md#are-my-automatic-backups-encrypted) |
| **Backup Mirror** (a full snapshot written to a Dropbox / OneDrive / iCloud folder)                                              | ✅ Yes             | Encrypted with a **passphrase you choose**, so it stays readable when you move to a new computer. → [backup-mirror.md](backup-mirror.md)                                                                                                                                         |
| **Weekly Setup Backup emailed to Gmail** (your configuration — projects, snippets, recipes; **never** your chats)                | ✅ Yes — once you set a passphrase | AES-256-GCM + PBKDF2, but **only when you have set a passphrase** in the Setup Backup settings. The passphrase ships empty by default, and the weekly schedule does not require one — so until you set it, the weekly bundle is emailed as a **plain, unencrypted ZIP**. Set a passphrase before turning the weekly schedule on. → [setup-backup.md](setup-backup.md) |
| **API keys, account logins, integration tokens**                                                                                 | ✅ Yes             | Encrypted through your operating system's keychain, never written in plain text, and never handed to the app's UI layer.                                                                                                                                                         |
| **The live database** Omniscio reads and writes as you use it (`mission-control.db`)                                             | ⚠️ Optional | Off by default (protected by your OS login + optional full-disk encryption). You can now opt in to encrypt the live database at rest — sealed by your OS keychain, or in a zero-knowledge mode by a passphrase you set (prompted at launch), with a mandatory one-time recovery code either way. → [Database Encryption](database-encryption.md)                        |
| **The manual "Export all data" ZIP** (Settings → Backup & Restore)                                                                  | ❌ No              | Deliberately unencrypted — it's a file _you_ choose to make and share. For an encrypted copy instead, use Backup Mirror or Setup Backup. → [data-transfer.md](data-transfer.md)                                                                                                  |

### Encrypting the live database (opt-in)

Encrypting a database _while the app is constantly reading and writing it_ is
much harder than encrypting a backup copy that's written once and never
reopened — it touches every single read and write and rules out some of the
speed tricks Omniscio uses to stay fast on a large database. So it's a
deliberate, separate piece of work, and it's **off by default**: the
highest-risk case — a backup file copied off your machine, or lingering on disk
after you delete something — is already covered because every backup copy is
encrypted. If you want the live file protected too, you can now **opt in** —
see [Database Encryption](database-encryption.md).

## Related

- [Database Encryption](database-encryption.md) — the opt-in at-rest encryption for the live database- [Reclaim disk space / how backups work](database-compaction.md) — the automatic backups, including the encryption details
- [Backup Mirror](backup-mirror.md) — the portable, passphrase-encrypted full snapshot
- [Setup Backup to Gmail](setup-backup.md) — the weekly encrypted configuration backup
- [Export / import all data](data-transfer.md) — the manual (unencrypted) ZIP
