Skip to main content

Settings → Backup & Restore

This page holds two things that look alike and are not: the encryption of your memory on this disk, and the backup archive you carry to another machine. The rail entry is Backup & Restore; the page subtitle reads Backup your profile configurations, layout settings, API keys, and chat logs into a single compressed ZIP file, or import an existing configuration.

The page runs top to bottom: Encryption at rest, Carrier passphrase, a red warning to read before restoring, then two cards side by side, Create Backup and Restore Backup, and finally the box How your secrets are handled.

Encryption at rest

Encrypt your vault databases on disk with AES-256 (SQLCipher).

The card first shows Loading… while the app asks how your keys are kept, then one of the states below.

Not open yet on most builds

On the builds shipped today, the card shows this text instead of the activation flow: Encryption is not open yet, on purpose. The only key custody available today ties the key to this machine — a memory sealed here could not be reopened on another computer, and there is no way back once it is done. We are finishing a recovery-phrase custody that travels with you first. If you already hold a 24-word phrase from another machine, you can restore it below. Only the button Restore from a recovery phrase is offered. The activation is withheld on purpose rather than offered with a warning: sealing a memory to one machine is a one-way door.

On a build where the key can travel but no carrier passphrase is set yet, the card says Set a carrier passphrase first — otherwise this key could never leave this machine. and again only offers the Restore button. Set the passphrase in the next section first.

Enabling encryption

When activation is available, the card explains the trade: Your memory is currently stored in cleartext on disk. Enabling encryption seals every vault with a key kept in your operating system keychain, so a stolen laptop, a leaked backup or a synced folder cannot be read. It does not slow down the app noticeably at rest, but retrieval does more work on each read.

  1. Enable encryption

    Click Enable encryption. The button is disabled when your operating system keychain cannot be used, with this explanation: Your operating system keychain is unavailable, so a key cannot be sealed safely on this machine. Encryption cannot be enabled here — enabling it would mean writing the key in cleartext next to the data it protects, which we refuse to do.

  2. Write down the 24 words

    The recovery phrase is shown once, as 24 numbered words in four columns, under this warning: Write these 24 words down on paper and keep them somewhere safe. They ARE your key. If you lose this machine, they are the only way back into your memory — no one can restore them for you, not even us. Shown only once. Copy puts them on the clipboard (the button reads Copied). Click I wrote it down to continue, or Cancel.

  3. Type back a few words

    To make sure your recovery phrase is safely written down, type back the words at these positions. Each field is labelled Word #{n}. Show the phrase again goes back one step. Confirm and encrypt becomes active once every field is filled; wrong words say Those words do not match your recovery phrase. Try again.

  4. Read the result

    Encryption enabled — {count} vault(s) encrypted. or simply Encryption enabled. when there was nothing to convert yet. If a vault was busy: Encryption is enabled, but some vaults were in use and will be encrypted the next time you restart the app.

Once encrypted

The card reads Your vaults are encrypted at rest. with the date. Under it, a check field: You can check that the phrase you wrote down is correct, any time. It is never sent anywhere. Type the phrase (placeholder Type your 24-word recovery phrase) and click Check: This phrase matches your key. or This phrase does not match. Check what you wrote down.

Restore from a recovery phrase

On a new machine, paste the 24-word recovery phrase you saved to unlock your encrypted vaults. Paste the words into the field (placeholder word1 word2 word3 …) and click Restore key. Success reads Recovery phrase accepted — your key is sealed on this machine.

The errors are spelled out: A recovery phrase is 24 words. Check the count., One of the words is not a valid recovery word — likely a typo., The phrase does not check out — a word is wrong or out of order., Encryption is already enabled on this install., The operating system keychain is unavailable, so the key cannot be sealed here., No activation in progress. Start again., Encryption was enabled but some vaults could not be migrated yet., and the generic Something went wrong.

Carrier passphrase

Lets your API keys and connected accounts travel with you, instead of being locked to this machine.

This card is separate from encryption on purpose. Encryption answers "is my memory encrypted on this disk?"; the carrier passphrase answers "can I carry my secrets to another machine?". While the app checks, the card reads Checking how your secrets are sealed…. The passphrase itself is never kept after you submit it, and no key material ever reaches the interface.

No passphrase yet (the default)

Right now your secrets are sealed to this machine's keystore. They are safe here, but they cannot be opened anywhere else — not on a new laptop, not from an external drive. A passphrase changes that. On a machine without a system keystore, a line adds: This machine has no system keystore, so it will ask for the passphrase at every start.

Two password fields, Choose a passphrase and Type it again, with the hint At least 12 characters. A short sentence you will remember beats a short jumble you will not., then Set the passphrase. Under it, the warning that matters: There is no way to recover this passphrase. Nobody holds a copy — that is what makes it yours. Write it down somewhere safe.

Two passphrases that differ say The two passphrases do not match.; fewer than 12 characters say Too short — use at least 12 characters. Success reads Passphrase set. This machine is trusted, so you will not be asked again here.

Locked

On a machine that holds a passphrase but is not trusted yet: Locked, Your secrets are sealed with a passphrase and this machine is not trusted yet. Enter it once and this machine will stop asking. Type it into Your passphrase (Enter submits) and click Unlock. Unlocking also trusts the machine: Unlocked. This machine is now trusted. A wrong one says That passphrase does not open this carrier.

Unlocked

Either Unlocked — this machine is trusted (This machine can open your secrets without asking. The passphrase is still what protects them anywhere else.) or Unlocked for this session (This machine will ask for the passphrase again next time.). Three buttons:

  • Forget this machine (only when trusted): This machine has been forgotten. It will ask for the passphrase next time. The footer explains the scope: Forgetting a machine deletes only the shortcut that skips the passphrase. No data, no key and no secret is touched — the next start here simply asks again.
  • Lock now: Locked for this session.
  • Change the passphrase, which unfolds a form: Every secret is re-sealed under the new passphrase in one pass. If it is interrupted, the next start finishes it — or undoes it if nothing had moved yet. You will never be left with half your secrets locked. Fields Your current passphrase, the new one and its confirmation; buttons Change it and Cancel. Success: Passphrase changed — {count} secret(s) re-sealed.

Other messages you may meet: This carrier already has a passphrase., No passphrase is set on this carrier., The passphrase settings file could not be read., This machine cannot store the shortcut securely, so it will ask every time., and Something went wrong.

Read carefully before restoring

The red banner between the two cards: This action replaces your active system files directly. Your physical index files and vault notes on disk are safe and untouched, but settings, conversations, and API keys will be overwritten.

Create Backup

Package your settings, layouts, active identity profiles, and conversations into a ZIP file. (Omits heavy temporary log files).

  1. Decide about the wallet

    If a sovereign wallet exists on this machine, a checkbox Include my sovereign wallet? appears, off by default: Adds your wallet private key to the archive so your license and funds follow you to a new machine. Protected by a passphrase you choose. Left unticked, an orange warning stays on screen: Your wallet private key will NOT be in this backup — on a new machine, the wallet and your license would be lost.

  2. Choose the wallet passphrase

    Ticking the box reveals Wallet key passphrase: Minimum 8 characters. This passphrase encrypts the wallet key inside the archive — you will need it again when restoring. From 8 characters a green note confirms The wallet private key will be included, encrypted with your passphrase. Shorter, the export refuses: The wallet passphrase must be at least 8 characters long.

  3. Backup configuration

    Click Backup configuration. A native save dialog titled Export Backup proposes the file name mnemosyne-os-backup-YYYY-MM-DD.zip (the file type reads "Archive ZIP", in every language). Success reads Backup successfully created!

Sovereign by design

The page says it under the passphrase field: Sovereign by design: nothing is ever transmitted to us and we store nothing — no account, no cloud copy, and NO password recovery service. If you forget this passphrase, no one (not even us) can recover the wallet key from this backup. Write it down and keep it somewhere safe. See the Wallet page for what the wallet holds.

Not every key travels

The wallet's private key is the only wallet secret this page talks about. Do not treat a backup as a full copy of every key you were given with your Engramm licence; keep that material where you stored it when you obtained the licence.

Restore Backup

Import a previously generated backup archive (.zip). All your current local settings will be overwritten.

  1. Enter the wallet passphrase if needed

    The field Wallet key passphrase is Only needed if the backup contains a wallet key. Leave it empty for an archive made without the wallet.

  2. Restore from file (.zip)

    Click the dashed button Restore from file (.zip) and pick the archive (the file type reads "Sauvegarde Mnemosyne OS", in French in every language).

  3. Confirm

    A system confirmation asks: WARNING: Restoring this backup will overwrite all your current configuration files, API keys, custom setups, and conversation history. Mnemosyne OS will restart immediately after. Are you sure you want to proceed?

  4. Let the app restart

    On success the app relaunches by itself. Nothing else to do.

Two errors concern the wallet: This backup contains a wallet key — enter its passphrase to restore it. and Incorrect passphrase for the wallet key in this backup. Any other failure prints the error the app returned; when it returns none, a generic French line is shown whatever your language (Erreur lors de la restauration de la sauvegarde., and Erreur lors de la création de la sauvegarde. on the export side).

What a restore does not touch

Your vault databases and the documents watched by DocWatch stay where they are. The archive carries settings, layouts, identity profiles, conversations and API keys, and only those are overwritten.

How your secrets are handled

The info box at the bottom is the privacy model of the page, in the app's own words:

  • Sovereign wallet — its private key is stored encrypted and bound to this machine. Without the option above it is NOT in the backup: on a new computer the wallet (and your license) would be lost. With the option, it travels encrypted by your passphrase and is re-bound to the new machine when you restore.
  • Cloud API keys — included, but encrypted by the operating system and bound to this machine and your user session. Restoring on the same machine: they keep working. On another machine they are unreadable by design — simply re-enter them in the AI & Models settings.
  • Passphrase — it never leaves your machine and is not stored anywhere. If you forget it, the wallet key inside the backup cannot be recovered.

The Carrier passphrase section above exists precisely for the second point: with a passphrase set, API keys and connected accounts can be opened on another machine, instead of being re-entered.