Sync is not a backup — deletions sync too. A practical plan for your notes: open-format exports, the 3-2-1 rule, and a restore you actually test.
· Privacy & Ownership · 7 min read
Somewhere in your future there is a bad day. A laptop bag left on a train, an SSD that stops answering, a sync job that goes wrong in a novel way, an app that announces it is "sunsetting" with ninety days' notice. You don't get to schedule the bad day or skip it. The only thing you choose — and you have to choose it in advance — is whether it costs you an afternoon or a decade of accumulated thinking.
Most people believe they have already made that choice, because their notes "are in the cloud" or "sync to my phone." That belief rests on the single most expensive misunderstanding in personal data: sync is not a backup. The two solve different problems, and confusing them is how someone with three copies of their notes loses all three in the same second. This article is the fix — what actually destroys note archives, what a real backup looks like, and a setup that takes about fifteen minutes once and then runs on a calendar instead of on willpower.
Sync has one job: make every copy identical, as fast as possible. It is very good at this job, which is exactly the problem. Sync cannot tell a change you meant from a change you didn't. Delete the wrong note and the deletion races to every device you own. Botch a reorganization, overwrite a page you needed, let a buggy merge mangle a file — the damage replicates with the same efficiency as your good edits. Three synced copies are not three chances to recover; they are one copy with excellent distribution.
A backup is the opposite discipline. It preserves past states, it stays independent of the live system, and it does not change when the live system does. The test is one question: if you deleted a note last Tuesday and only noticed today, can you get it back? Sync answers no by design. Only something that still holds Tuesday's state can answer yes.
The cloud version of the misunderstanding is subtler but ends the same way. Storage operated by your note app is not your backup; it is the app's live database, subject to the app's fate. And even a cloud drive you control, if it holds the only copy, is one flagged login or one lost 2FA device away from becoming a very secure vault you can no longer open.
Not exotic disasters. In roughly descending order of likelihood:
Notice how little of that list is dramatic and how much of it is an ordinary Tuesday.
Backup practitioners have a rule of thumb — three copies, two kinds of storage, one off-site — and it translates cleanly to a note archive:
1. The live copy. Your notes in your app, wherever they live. This is the copy you think with. It counts, but it is the copy everything else exists to protect.
2. A local export in an open format. The backup that matters most, and the one most people skip. Periodically export everything to plain files — Markdown or plain text — on your own file system. An open-format export survives the app that produced it: it needs no vendor, no account, and no particular decade to stay readable, which is the entire argument for plain text compressed into a folder. It is also your escape hatch: a tested export means no app can hold your archive hostage, because leaving is always one copy away.
3. A copy off your device. Put that export somewhere a house fire or a stolen bag cannot reach — your own cloud drive, an external disk in a drawer somewhere else, a private git repository. This copy defends against the physical world the way the open format defends against the digital one.
One warning, because it quietly undoes everything else: a backup written in a proprietary format is a backup of your lock-in. If the best your app can export is a blob only the same app can read, treat that as a convenience feature and keep looking for the path to plain files. If there isn't one, that is information too.
Backup systems fail silently. The export that has been writing empty files for six months. The "complete archive" that skipped everything created after an update. The folder that turns out to contain shortcuts rather than files. Verification costs five minutes:
The habit sounds paranoid right up until the first time it catches something, after which it sounds cheap.
Manual backups fail for a predictable reason: they depend on remembering, and the weeks when you are too busy to remember are exactly the weeks you produce the most notes worth protecting. In descending order of reliability:
There is a class of software built on the premise that your notes should live on your device, not on a company's servers. Local-first design deletes whole rows from the threat table — no service shutdown, no account lockout, no pricing wall between you and your own writing. What it does not delete is the homework: when the canonical copy sits on your hardware, backup responsibility is explicitly, honestly yours.
Good local-first tools say so in features rather than fine print. Indenta is a concrete example: notes live in the browser's local database, everything exports to plain Markdown in one action, and the optional Google Drive sync writes to your own Drive — snapshotting the previous version before each overwrite, so recent history survives even a bad merge (the User Guide covers both). The honest caveat cuts the same way: browser storage can be wiped by clearing site data, which is precisely why the exported copy — rule two above — stays non-negotiable no matter how local-first the app is.
Tonight, not someday:
The bad day is coming for every archive eventually; the only variable is what it costs. Fifteen minutes tonight buys the cheap version.
Try it in practice: Indenta is a free, offline-first outliner — nested notes, backlinks, tags, and peer-to-peer sync, with no account required. Start writing in your browser, or read the User Guide first.