A synced folder is not a backup

You have your records in a cloud-synced folder, on your laptop and your phone, so there are three copies. Then one afternoon a folder gets dragged somewhere odd, or a sync client resolves a conflict its own way, and all three copies agree on the new state within about ninety seconds.

Sync is not backup. They solve different problems, and the reason the confusion is so common is that sync genuinely does protect against one thing — hardware failure — while looking as though it protects against everything.

What sync does and doesn’t cover

Sync makes copies identical. That’s its function, and it is very good at it. The consequence is that any change propagates: a rename, an overwrite, an accidental deletion, a partially corrupted file written by a crashing application. Fidelity is the product, and it applies to mistakes.

Backup makes copies of the past. Its function is that yesterday’s state still exists somewhere after today has happened. That is a different property and it is the one you need when the problem is not a dead disk but a wrong action.

Set out plainly, the risks to a records archive are:

  • Hardware failure. Sync covers this well.
  • Accidental deletion or overwrite. Sync propagates it. Backup covers it.
  • Silent corruption. Sync propagates it, and may propagate it before anyone notices. Backup covers it if the backup is old enough.
  • Ransomware or mass encryption. Sync propagates it enthusiastically. Backup covers it if a copy was offline or immutable.
  • Account loss. Losing access to the provider takes every synced copy’s authority with it, and frequently the copies too.
  • Provider decisions. Service changes, closures, policy shifts, an unpaid renewal.

Sync addresses one of six. It is worth having for that one; it is not a plan.

Versioning is not quite backup either

Most sync services keep previous versions and a recycle bin, and this is genuinely useful — most accidental-deletion incidents are resolved from there.

Two caveats worth knowing. Version history is time-limited, and the retention window is set by the provider and often shorter than the period you need records for. And it lives in the same account, so it does not survive the account itself being lost or compromised. A deletion you notice on Thursday is recoverable. A deletion you notice in eighteen months, when someone asks for a specific document, generally is not — and records are exactly the category where the gap between event and discovery is measured in years.

What a working arrangement looks like

The old rule of thumb still holds up: at least three copies, on at least two different kinds of storage, with at least one somewhere else entirely. Applied to a personal or small-business records archive, that means:

The working copy. Wherever you actually file things. Local, fast, the one you use.

A synced copy. Covers hardware failure and gives you access from a phone. Do not count it as a second copy for backup purposes, because it isn’t independent — it’s the same copy in another place.

A copy that does not update automatically. This is the one that does the real work. An external drive you connect deliberately, or a backup service that keeps its own version history separate from your live storage. The essential property is that a mistake in the live archive does not reach it until you let it.

Offsite. Fire, theft and flood take everything in one building including the external drive in the drawer beneath the laptop. A second drive kept elsewhere, or a service, or both.

The append-only nature of a records archive makes this easier than it is for most data. Once a year is closed, its files do not change again — see an inbox and an archive on why the archive should be write-once. A closed year copied to a drive and put somewhere else is about as safe as domestic storage gets, and it needs doing exactly once.

Keep or bin

KEEP OR BIN — copies of the archive

  · Local working copy
                    → KEEP. Where the work happens.

  · Cloud-synced mirror
                    → KEEP, but it is not a backup.
                      Same copy, second location.

  · Deliberately connected external drive
                    → KEEP. The copy a mistake can't
                      reach on its own.

  · Closed years on a drive kept elsewhere
                    → KEEP. Highest value per minute
                      of effort in the whole system.

  · Provider version history as the
    recovery plan
                    → NOT A BACKUP. Time-limited, and
                      it dies with the account.

  · A backup you have never restored from
                    → UNVERIFIED. Untested backups
                      fail at a rate you cannot know.
                      Restore one file and look at it.

  · Whether copies satisfy a requirement to
    retain records, and in what form
                    → ASK LOCALLY. Format and
                      retention rules vary by
                      jurisdiction and record type.

Test it, cheaply

An untested backup is a belief. The test is small: pick a document from two years ago, restore it from the backup rather than the live copy, and open it.

That single exercise catches the realistic failures — the folder that was never included in the backup’s scope, the sync client that silently stopped weeks ago, the archive format nothing on your current machine will open, the encrypted backup whose passphrase is stored only in the thing being backed up. All four are common and all four are invisible until the day they matter.

Twice a year is plenty. Doing it once is infinitely better than doing it never.

The other half of durability

Copies protect against loss. They do nothing about the file still being readable years later, which is a separate problem: formats fall out of support, and the dates and notes attached to a file are frequently stripped when it is copied — what happens to metadata covers that second failure. A perfectly backed-up archive of files nothing can open, with all their dates reset to the day of the last restore, is a recognisable outcome.

What this doesn’t settle

Whether digital copies are acceptable at all where originals existed. How many copies anyone requires. How long any of it must survive. Whether records must be held in a particular jurisdiction, or kept in a format that can be produced on request.

Those are rules and they vary — see how long to keep things for building a scheme around numbers you don’t have yet, and ask your tax authority or an adviser for the numbers themselves. What is true in every jurisdiction: a deletion that reached all three of your copies within two minutes was never protected by having three copies.