Privacy Policy
This policy covers BBS Manager (our iOS app for Borg Backup Server), the borgbackupserver.com website, and any hosted services we offer. We collect as little as possible — here is exactly what that means.
The short version
- We never sell or rent your information, and we never share it for advertising. There are no ad networks or cross-app trackers anywhere in the app.
- Your server addresses, credentials, keys, and passphrases stay on your device. They are not transmitted to us and we have no way to read them.
- The app contains no analytics, crash-reporting, advertising, or tracking SDKs. We do not collect an advertising identifier and we do not track you across apps or websites.
- The only data the app sends to a server that isn't yours is what push notifications require — and only if you turn them on.
- Website analytics runs only if you accept the cookie banner.
- We do not store or use any information beyond what is described on this page.
Contents
- Scope and who we are
- What stays on your device
- Push notifications
- Subscriptions and payments
- What the app does not collect
- Support requests
- Website analytics
- Demo requests
- Website local storage
- Server logs and CDN
- Hosted services
- The self-hosted software
- Retention
- Who we share data with
- Security
- Your rights and choices
- Children's privacy
- International users
- Changes to this policy
- Contact
Scope and who we are
The Borg Backup Server app and website are operated by Marc Pope, a sole proprietor located in North Carolina, USA. For the purposes of data protection law, we are the data controller for the limited information described here.
This policy applies to BBS Manager, our mobile app for iOS (the “App”), this website, and hosted services we make available. It does not apply to the open-source Borg Backup Server software you install on your own infrastructure — see The self-hosted software below.
What stays on your device
The app connects directly to the Borg Backup Server instances you point it at. That traffic goes from your phone to your server. It does not pass through us, and we do not proxy, mirror, inspect, or log it.
The following are stored locally on your device and are never transmitted to us:
- Server addresses and hostnames you add;
- Authentication credentials, API tokens, and keys — held in the iOS Keychain, which is encrypted by the operating system;
- Repository passphrases, if you choose to save them;
- App preferences and settings; and
- Cached job, archive, and status data fetched from your servers so the app can render quickly.
We have no ability to read any of it. Deleting the app removes this local data from your device.
Push notifications
Push is the one place where data leaves your device for a server that isn't yours. It is optional — if you decline the notification permission or leave push disabled, nothing in this section applies to you.
If you enable push notifications, our own first-party notification relay stores:
| Data | Why |
|---|---|
| Apple push token | Required by Apple Push Notification service (APNs) to deliver a message to your specific device. |
| Device identifier | Distinguishes your devices so an alert reaches the right one and a stale registration can be replaced. |
| Server binding | Associates the device with the Borg Backup Server instance permitted to send it alerts, so notifications are routed only to the person who registered them. |
Notification payloads carry operational information — for example that a job succeeded or failed, and which job or host it relates to. They do not contain the contents of your backups, your credentials, or your repository passphrases.
No third party sits in this path other than Apple's APNs, which Apple operates and which is required for any iOS push notification. We use no third-party push vendor. This data is used solely to deliver the notifications you asked for — never for analytics, profiling, advertising, or any other purpose — and it is not sold, rented, or shared.
You can turn push off at any time in iOS Settings or in the app. Disabling notifications, unregistering a device, or deleting the app causes the corresponding registration to be removed or to expire as invalid.
Subscriptions and payments
Subscriptions are purchased through the Apple App Store. Apple processes the payment, not us. We never see or store your name, billing address, payment card, or Apple ID. We receive only aggregate, anonymous sales and subscription reporting from Apple, which does not identify individual customers.
Purchase receipts are validated against Apple's own service. We do not transmit receipt data to any third-party receipt-validation or subscription-analytics service.
What the app does not collect
To be explicit, the app contains no:
- analytics or product-telemetry SDK;
- third-party crash-reporting SDK;
- advertising SDK, ad identifier (IDFA), or attribution/marketing SDK;
- social-network login or embedded tracking pixel; or
- location, contacts, photos, microphone, or camera access for tracking purposes.
We do not build profiles about you, we do not track you across other companies' apps or websites, and we do not sell or share personal information as those terms are defined under the California Consumer Privacy Act or similar laws. If you send a crash report to Apple through iOS, Apple may make an aggregated, anonymized version available to us through its developer tools; that is an Apple feature governed by Apple's privacy policy, and it involves no SDK or data collection by us.
Support requests
If you email support@borgbackupserver.com or open a GitHub issue, we receive whatever you choose to send us — typically your email address and a description of the problem. We use it only to answer you. Please redact credentials, keys, and hostnames from logs before sending them.
Website analytics
This website uses Google Analytics 4 to understand how the site is used — pages visited, approximate region, and how visitors find us. Analytics cookies are set only after you choose “Accept analytics” in the cookie banner. If you decline or ignore the banner, no analytics cookies are set and no analytics data is sent. You can change your mind by clearing this site's data in your browser, which will show the banner again.
There is no analytics of any kind in the BBS Manager app.
Demo requests
If you request a live demo on this website, we collect your name, email address, and optionally a company name. These are used to send your activation link and provision your temporary demo instance. Demo instances and their data are automatically deleted when the 24-hour demo expires. We don't add you to mailing lists or share these details with anyone.
Website local storage
The website stores two small values in your browser's local storage: your cookie-consent choice, and a cached GitHub star count. Neither contains personal data and neither is sent anywhere.
Server logs and CDN
Like virtually every website, our web server and CDN (Amazon CloudFront) keep standard access logs — IP address, requested page, browser user agent — used for security and operations, and rotated automatically. Our push relay similarly keeps short-lived operational logs needed to diagnose delivery problems.
Hosted services
Where we operate a hosted Borg Backup Server plan on your behalf, we necessarily hold more: the account email and details you register, subscription and billing status from our payment processor, the configuration of the instance we run for you, and operational logs and metrics for the infrastructure. The backup data you store on a hosted plan remains yours; we process it only to operate the service you have asked us to run, and BorgBackup's client-side encryption means archive contents encrypted with a passphrase you hold are not readable by us.
The same commitments apply: we do not sell or rent it, we do not use it for advertising, and we do not use it for anything except operating and supporting the service.
The self-hosted software
The open-source Borg Backup Server software you install on your own infrastructure sends no data to us or to anyone else. It has no telemetry, no phone-home, and no usage reporting. Data handled by that software is entirely under your control and is governed by your own policies, not this one.
Retention
| Data | Retention |
|---|---|
| On-device app data | Until you remove the server, clear the data, or delete the app. |
| Push registrations | Until you disable push, unregister the device, or the token becomes invalid. |
| Demo request records | Deleted with the demo instance; request earlier deletion any time. |
| Support correspondence | Kept as long as needed to resolve the issue and for a reasonable period afterward. |
| Web and relay logs | Rotated automatically on a short cycle. |
| Website analytics | Per Google Analytics retention settings, and only if you consented. |
Who we share data with
We do not sell, rent, or trade your information, and we do not share it for advertising or cross-context behavioral purposes. The limited service providers that necessarily handle data on our behalf are:
- Apple — App Store distribution, payment processing, and APNs push delivery;
- Amazon Web Services — CDN and hosting for this website and our relay;
- Google Analytics — website analytics, only with your consent; and
- our infrastructure and payment providers for hosted plans, where you purchase one.
We may also disclose information if required by law, or to protect our rights, safety, or the integrity of the service — and, if we are ever involved in a merger or sale of assets, as part of that transaction, subject to this policy.
Security
Connections between the app and your servers use TLS. Credentials on the device are held in the iOS Keychain. Our relay and website run over HTTPS with HSTS. Because the data we hold is deliberately minimal, the blast radius of any incident on our side is small — but no system is perfectly secure, and we cannot guarantee absolute security.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to withdraw consent. Because we hold so little, most requests are simple:
- Push data — disable notifications or delete the app, or email us to have your registration removed;
- Website analytics — decline the cookie banner, or clear this site's data to be asked again;
- Demo records, support email, hosted accounts — email us and we will delete them.
Email support@borgbackupserver.com for any privacy request. We will respond within the period required by applicable law. You will never be discriminated against for exercising these rights. EU/UK users also have the right to complain to their local data protection authority.
Children's privacy
The Service is a system administration tool intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
International users
We operate from the United States, and the limited data described here is processed there. If you use the Service from outside the US, you understand that your information will be processed in the US, which may have different data protection laws than your country. Where required, we rely on appropriate safeguards for such transfers.
Changes to this policy
We may update this policy as the product changes — for example when hosted plans launch. The “Last updated” date at the top reflects the current version, and material changes will be announced in the app or on this site before they take effect.
Contact
Marc Pope — sole proprietor, North Carolina, USA
Email: support@borgbackupserver.com
GitHub: github.com/marcpope/borgbackupserver/issues
See also our Terms of Service.