Security
What leaves your computer? Not your files.
Backups go to a place you own. You don’t need an account to make one.
Six promises about your data.
Your files stay yours
Nothing goes to Genie9. No account needed.
AES-256 per job
With a password only you hold.
Sealed credentials
Never written into a job file.
No open port
Only your Windows account, and the PC’s administrators, can reach the agent.
No telemetry
No usage data, no crash reports, no analytics.
Support bundles
A zip you read before you send it.
What is sent, and when.
Backing up, restoring and Find never talk to Genie9.
- Backups, restores, Find
- Nothing to Genie9. A backup goes only to the destination you chose: a disk, a NAS or your own S3 bucket.
- Ask Genie
- When you press Ask: your prompt, your drives, top-level folder names on internal drives, and your jobs with their recent results. Passed to OpenAI to write the job. Never your user name (paths in your user folder go as {UserProfile}), PC name, file contents or passwords. The exact list
- Sign-in and licence
- Your e-mail, this device’s id, the app version, and Windows and its processor type. Activating a licence also sends its key and this PC’s name.
- Update checks
- App version, channel, platform, device id, edition, and when your updates end.
- Alert e-mails from Genie9
- Home or Pro, signed in: this PC’s name, the job and its result, when it ran, the destination and set, the file and verification counts, and the first 50 skipped files with their reasons. The run log only if you tick “Attach the run log”. To your sign-in address only. From 10.0.56 that box starts unticked.
- Your own mail server
- The same e-mail, through your SMTP server. It never touches Genie9.
Encryption · Home
AES-256. A password nobody can recover.
Every file is encrypted and carries a SHA-256 checksum, checked at restore.
- A wrong password writes nothing
- A lost password is final, by design
- Restore needs only the files and the password, in any edition
- It covers file contents: names and dates stay readable, so Find and Restore can list them
Credentials
Saved once. Sealed on this PC.
Share passwords and S3 keys are sealed with Windows data protection, never written into a job.
- Exports and support bundles carry no secret
- Switching on the service hands them over sealed for this PC
When it asks for administrator rights.
Say no, and nothing breaks: open files are skipped and listed in the report.
- 1
Installing
Setup, updates and uninstalling. Not to use it.
- 2
The Windows service
Once, to switch it on or off.
- 3
Open-file snapshots
At run time, unless the service is on.
- 4
A folder you can’t reach
Only if you choose to restart elevated.
The details.
- Encryption
- AES-256 per job, with a per-file SHA-256 check at restore.
- Credentials
- Windows data protection (DPAPI) for your account; for the PC in service mode.
- Local connection
- A named pipe, never a network port. Only your Windows account, and the PC’s administrators, can reach the agent; with the service on, other accounts on the PC are told it is managed by another account.
- Telemetry
- None. No usage statistics, no crash reports, no analytics. There is no switch because nothing is sent.
- Updates
- Signed by Genie9 Ltd. Installed only if checksum and signature match.
Your disk. Your copy. Your password.
Check every one of these in the app.