Skip to main content

Privacy and security

O&O AutoBackup works with the storage destinations you choose. It does not require your backup data to be stored in an O&O cloud.

Data paths​

Local and network backups travel between your PC and your destination. WebDAV and S3 backups also involve the selected provider and network. Consult that provider's privacy, retention, and data-location policies.

Protect the destination​

  • Enable O&O AutoBackup encryption for removable or remote storage that could be accessed by others.
  • Use a unique password and keep the recovery key separately.
  • Restrict share and bucket permissions to the required account.
  • Disconnect at least one removable copy when it is not being updated.
  • Test recovery regularly.

Logs and support​

Operational logs can contain local paths, file names, server addresses, and failure details. Review them before sharing and send them only through an appropriate support channel. O&O Support never needs your backup password or recovery key.

Threat boundaries​

Encryption protects backup contents at rest, but it does not clean malware from source files or protect an unlocked Windows session. A connected destination can still be affected by malicious software operating with your permissions. Layered protection combines O&O AutoBackup, offline or immutable copies, Windows security updates, and safe account practices.