---
title: Off-machine backup prompt (a backup that survives losing the computer)
---

# Off-machine backup — first-run prompt

## What it is

> **STATUS: the BANNER is off; the inbox alert is back ON.** A brand-new user should not be
> greeted by a data-loss warning, so the `<OffMachineBackupOffer/>` banner mount was removed
> from `AppBanners.tsx` (owner, 2026-08-18) and is still absent. The component + its routing
> stay in-tree; if backup nudging returns it will be an inbox notification, not a banner.
>
> The matching "Backups are on the same disk" **inbox alert was RE-ENABLED on 2026-08-30**
> (audit B1): `BACKUP_COLOCATION_ALERT_DISABLED` in `backup-failure-alerts.ts` is now `false`,
> and brand-new users are instead protected by the new-user alert hold (`new-user-alert-hold.ts`
> holds the `backup-colocated` key through onboarding and for 24h after setup). So the risk IS
> surfaced today — as a persistent inbox card carrying a one-click **Open Backup settings**
> action, plus the in-panel warning described under [Where you see it](#where-you-see-it).

### What it is

A gentle, one-time prompt that invites a new user to set up a backup that lives **off**
this computer. It exists because a default Omniscio install keeps **no backup that
survives losing the machine**: the only backup that is on by default (the local
auto-backup ring) writes to the **same disk** as the database, so one disk failure,
theft, or ransomware event destroys every project, session, and conversation with no
copy anywhere else. Every off-machine copy (Setup Backup to Gmail, the cloud-folder
Backup Mirror, Portable Backup) is opt-in and off by default, so most people never turn
one on. This prompt closes that gap.

It is **consent-first**: it never turns a backup on by itself. Uploading a copy of
someone's whole database off their machine without asking is a privacy violation, so the
prompt only _asks_, then acts on the user's choice.

## Where to find it

### Where you see it

- **A slim banner across the top of the app** (accent-toned, not alarming): "Your
  projects and history live only on this computer. If it is lost, stolen, or its disk
  fails, there is no copy anywhere else. Set up an off-machine backup so you never lose
  your work." with a **Set up backup** button and a **Not now** (X) dismiss.
- Clicking **Set up backup** opens a small **chooser** with two options:
  - **Back up to Gmail** — Omniscio emails an encrypted copy to your Google account on a
    schedule (quick to turn on). If no Google account is connected yet, the option is
    honest about it: "You will connect your Google account first…".
  - **Back up to a cloud folder** — save an encrypted copy to Dropbox, OneDrive, or
    iCloud Drive; it captures everything and you set a passphrase.
- Each choice opens the matching **Settings → Backup & Restore** section (Setup Backup or
  Backup Mirror), which is where the real configuration — folder pick, passphrase, and
  the "I've saved my passphrase" safety step — already lives. The prompt routes you
  there; it does not re-implement config, and it flips nothing on by itself.
- **Settings → Backup & Restore → Automatic Backups** carries a standing warning whenever no
  off-machine backup is on: **"No off-machine backup"**, explaining that a lost, stolen, or
  failed drive would take the data and every backup of it together. Its copy names the Backup
  Mirror, so it carries a **Set up Backup Mirror** button that scrolls straight to that card and
  highlights it. Like everything else here it only takes you there — it never turns the
  mirror on, because copying a database somewhere new is the user's decision.
- This post-onboarding banner is now the **only** surface for the off-machine backup
  message: the matching Setup v2 onboarding frame ("Keep a backup off this computer") was
  **REMOVED** (owner, 2026-08-18 — "remove this backup card, will tell them later"), so the
  message is deferred to this banner right after setup rather than shown mid-onboarding.

## How it behaves

### When it shows

Only on a desktop install where the user is **past onboarding**, has **no off-machine
backup configured yet** (Setup Backup off, Backup Mirror off, mirror auto-sync off), and
**has not already dismissed** the prompt. It never shows on the mobile web embed, never
mid-onboarding, and never once you already have an off-machine backup. It is shown at
most once — dismissing it (or choosing a mechanism) sets `backupOffMachineSetupOfferDismissed`
so it never returns. You can always set a backup up later from Settings → Backup & Restore.

### Also fixed: the database-error dialog

The fatal "could not open its database" dialog used to steer a recoverer only to the
same-volume `backups` folder — the exact copy a disk loss destroys. It now keeps that
hint for a _damaged-but-present_ database, but adds honest guidance for a disk/machine
loss: "…that local 'backups' folder is unreliable too… Restore from an off-machine
backup instead: the encrypted copy sent to your Gmail, or your cloud backup folder."

## For agents

### Under the hood (for agents)

- Decision logic is a pure function: `src/renderer/src/features/backup-onboarding/off-machine-backup-offer.ts`
  (`shouldOfferOffMachineBackupSetup`, `hasOffMachineBackupConfigured`).
- UI: `src/renderer/src/features/backup-onboarding/OffMachineBackupOffer.tsx`
  (banner + `DialogShell` chooser; honest-Gmail via the `GMAIL_STATUS` IPC), mounted in
  `src/renderer/src/app/AppBanners.tsx`.
- Routing uses `navigateToSettingsProject({ section: 'data-transfer', settingId })` with
  `settingId` `setup-backup-gmail` or `backup-mirror`.
- Onboarding cascade frame: **removed 2026-08-18** (`BackupFrame.tsx` deleted from
  `src/renderer/src/features/onboarding/setup-v2/setup-v2-nav.ts`); this
  banner is the sole off-machine-backup prompt now.
- Setting: `backupOffMachineSetupOfferDismissed` in `src/shared/types/settings/backups-settings.ts`
  (a boolean; reachable via `GET`/`PATCH /settings`). DB dialog:
  `src/main/db/db-init-error-dialog.ts`.
- No backup default changed; the prompt only routes + records its one-time dismissal.

## Related

- [backup-mirror.md](backup-mirror.md) — the encrypted folder-mirror backup this prompt routes you into.
- [data-folder-recovery.md](data-folder-recovery.md) — what to do when the data folder itself has gone missing.
- [inbox-alerts.md](inbox-alerts.md) — the persistent card the same risk raises now that the banner is off.

