How To

Encryption and backup

Connections at rest — the stored connection strings — can be encrypted with a phrase, and the whole app data folder can be backed up with one control. Both live in Settings.

Encryption and backup

Connections at rest — the stored connection strings — can be encrypted with a phrase, and the whole app data folder can be backed up with one control. Both live in Settings.

Encrypt connections

Open Settings → Encryption. The section shows the State (configured or not, and unlocked or locked) and the Key derivation parameters.

  • Set phrase: choose a phrase and confirm it. DataPad derives a key from it and encrypts the store.
  • Change phrase: re-encrypt the store under a new phrase.
  • Clear phrase: remove the encryption (you are asked to confirm).
  • Lock now: drop the in-memory key for this session, so the connections become unreadable until you unlock again.
  • Unlock: enter the phrase to decrypt the store for this session.

While the store is locked, the connections tree is empty and reads are refused with an CONNECTIONS_ENCRYPTION_LOCKED error; submit the phrase in the unlock prompt to continue. A wrong phrase returns ENCRYPTION_WRONG_PHRASE and lets you retry. A corrupt or tampered store returns a terminal CONNECTIONS_ENCRYPTION_FAILED surface with no phrase field, because a retry cannot help a damaged store.

The phrase is never stored: DataPad keeps only the derived key for the session. If you lose the phrase, the encrypted connections cannot be recovered.

Back up the app data folder

Open Settings → Backup. The section shows the App data folder path (with Copy path) and the documented copy procedure. Back up now copies the folder to a destination you choose:

  • Pick a destination with the OS folder dialog.
  • DataPad copies the files, excluding the backup destination itself and transient files, and reports how many files and bytes were copied and how long it took.
  • The completion panel keeps the destination and offers Open folder to show it in your file manager.
  • A destination that is not empty, or a failed write, renders the real structured error (BACKUP_DESTINATION_NOT_EMPTY, BACKUP_OPEN_FOLDER_FAILED, and so on) rather than failing silently.

To restore, copy a backup back over the app data folder while the app is closed. If the store was encrypted, the same phrase is required to read it afterwards; a backup is only useful with its phrase.

The app data folder

The folder holds the connection store, the licence, the MCP settings, the JSON graphs, and the rolling logs. The Backup section names its exact path, and Copy path puts it on the clipboard so you can paste it into a file manager.