Skip to main content
Version: In Development

Backups

Backup is the most important job on the list. Systems fail eventually, and a backup is the difference between an afternoon's work and starting again from nothing.

What is in a backup​

A backup captures everything you have set up: your devices and the names you gave them, your scenes and instincts, your calibration figures, your dashboards, your history and your licence.

Device firmware is not included, and does not need to be. If a device fails you fit a new one and flash the same firmware version. New hardware has a new address, so it needs adding to your system again.

If Sensa supplied your unit​

Your system backs itself up. There is nothing to set up and nothing to remember.

  • Every night at 03:00. If you have set a maintenance window that covers 03:00, the backup moves to the end of that window instead, so an update and a backup are never fighting over the same few minutes.
  • Before every update. A snapshot is taken just before your system updates itself, so there is always a recent point to return to. The update waits for it to finish, which takes several minutes, and only then installs anything. See Updates.
  • Whenever you ask. Press Back up now on the Backup tab.

Every backup is named for what caused it, so the list reads plainly: Overnight backup, Manual backup, or Before update to 1.0.0.

How long a backup is kept​

Backups held on the vehicle are kept for three days, or the newest three, whichever leaves you with more. It applies to every backup on the vehicle whatever made it: overnight, manual, and the snapshot taken before an update. One rule you can hold in your head, rather than a different answer for each kind.

On a unit that runs every night, three days is three backups anyway, so the two halves agree and you need not think about it. The count only comes into play after the van has been off for a while.

Snapshots taken before an update used to be kept indefinitely. On a system that updates regularly they added up, one large file per update, on the same storage your system needs in order to keep updating at all. The end of that road is a unit that stops being able to update itself on the space its own updates used, so they now expire like everything else.

The newest three are always kept, however old they are

A van switched off or laid up for a fortnight has nothing inside the three-day window, and the rule applied literally would leave you with almost nothing to go back to, at the moment you are least likely to be watching.

So the three newest on each destination are exempt. Park the van in October, come back in November, and the backups from the days around parking it are still there. This is worked out per destination, so a USB stick that has been out of the van since Tuesday keeps its own three rather than being emptied because the unit's own storage is up to date.

A copy that exists only in the cloud does not count towards the three, because nothing on the van can reach it to check.

The tidy-up runs overnight, and again whenever your system starts. A unit that was switched off at 03:00 used to wait until the following night to clear anything, which on a van used at weekends meant backups piling up on the card. Now it catches up as soon as it comes back on.

Your cloud copy is not governed by this. Cloud copies run to their own schedule and are kept for 28 days, and nothing on the van can delete one. See The cloud copy.

Everything is encrypted​

Every backup your system takes is encrypted, including the copy that stays on the unit. A backup is only useful once it is somewhere else, and every way of getting one off the vehicle turns it into a copy that has left your control.

Your system holds the key that unlocks them, and without it a backup cannot be opened on any other machine. Keep a copy of that key somewhere other than the vehicle: your emergency kit is that copy, so download it and store it safely.

Keep your emergency kit

Press Download emergency kit on the Backup tab and store the file outside your vehicle: a password manager, a cloud drive, or a printed copy with your vehicle paperwork. If you lose both the unit and the kit, the backups you had copied elsewhere cannot be opened.

Sensa also keeps a copy of your key for you, so that losing the unit and the kit together is no longer the end of your backups. Sign in to mySensa, open your vehicle, and press Show backup key. Your system sends it up on its own the next time it connects, so there is nothing to set up.

Because we hold it, we can open your backups too. They are not readable only by you, and we would rather say so here than have you find out from a support ticket.

What we can promise is how it is held. Your key is not sitting in a database in plain text. It is locked with a key of our own that lives in a vault and cannot be taken out of it, so a copy of our database is not a copy of anybody's backup key. Unlocking yours is a deliberate step that is recorded when it happens, rather than a lookup nobody would notice, and our ability to do it at all can be withdrawn in a single move.

The Backup tab​

Open the Sensa Settings panel, then the Backup tab.

The top card tells you the state of things: when the last backup ran, when the next one is due, and the schedule in plain words, for example "Daily at 03:00, keeping 3 days of local, never fewer than 3". If nothing is scheduled it says so rather than promising a run that will not happen. "Local" is there on purpose: the window governs the copies on the vehicle and says nothing about your cloud copy.

Below it is the list of stored backups, newest first:

ColumnWhat it tells you
BackupWhat it was named for, and a pin if it is being kept
LocationWhere it is stored: this device, a USB stick, or the cloud
CreatedWhen it was taken, in your own time
SizeHow large it is

A backup still being written shows Creating… until it finishes. Back up now is unavailable while one is in progress, because your system will only write one at a time.

Everyday tablet logins can see the tab and the list, but cannot run, restore or delete anything. See Accounts and access.

Where your backups go​

Across the top of the Backup tab is a pill for each destination, showing where your backups are actually going and how each one is doing.

DestinationWhat it is
This deviceThe unit's own storage. Always there, and the fastest to restore from
A USB stickA stick plugged into the unit, named after its own label so you can tell two apart
CloudA copy held by Sensa, where your licence includes it

Each pill reads its state beside it: Up to date, No backup yet, Last backup failed, Not connected for a stick that has been unplugged, or Can't check when your system could not find out. "Can't check" is not a fault, it is your system declining to claim something it does not know.

Tap a pill to switch that destination off, and tap it again to switch it back on. You are asked to confirm, because a destination switched off is one that quietly stops protecting you. Everyday tablet logins see the pills but cannot change them.

If nothing is both switched on and available, the tab says so in plain words: Nothing is being backed up. No new backups are taken until you fix it, and if you have switched this device off it says that the backups already on it are kept. It is a state you can reach deliberately, so it is said loudly rather than hidden.

A USB stick​

Plug a stick into the unit and it is offered as a destination on its own. Each successful backup is written to it as well as everywhere else you have switched on, so an offsite copy builds up without you doing anything. Nothing is written while the stick is out.

Format the stick as exFAT

A stick sold as FAT32 cannot hold a file over 4 GB. Backups work perfectly until they reach that size, and then stop, with nothing having visibly changed. Sensa says so under the pills rather than refusing the stick, but the safe answer is to reformat it as exFAT before you rely on it.

The cloud copy​

Where your licence includes it, your system uploads a backup to storage Sensa holds for you. It is the only copy that survives the vehicle itself, and the only one that fills without you remembering to do anything.

A copy goes up weekly, not nightly. A full backup is a large file and a van is often on a mobile connection with a data allowance, so uploading every night would cost you more than it protects. Cloud copies are kept for 28 days, which leaves you about four of them spanning the last month.

The timing follows how old the copy we already hold is, not the day of the week. A van that is away, out of signal or switched off for days at a time would otherwise skip its week entirely without anything noticing.

It is part of your support plan. If the plan lapses, the Cloud pill stops being offered and no new copies go up. Everything else carries on exactly as before, because losing an off-vehicle copy over a late renewal is not a sensible way to treat somebody's backups.

Uploading a backup takes considerably longer than making one, so the tab shows the upload separately, with its own progress. Your system is not stuck: the backup on the unit is already finished and safe by the time the upload starts.

A cloud copy cannot be deleted from the van

Delete removes a backup from the unit and from a USB stick. On a copy that only exists in the cloud there is simply no Delete button to press. This is deliberate. The offsite copy exists for the day the vehicle is stolen, and anything in the vehicle that could erase it would hand a thief the one copy they cannot otherwise reach. Cloud copies expire on their own after 28 days.

Restore is still offered on those rows, which is the whole reason they are listed. If you delete the copy held on the unit, the cloud copy stays behind as a row of its own, labelled Sensa cloud, and you can put it back from there.

Putting a backup back​

Each row in the list has a Restore button.

Restoring puts everything back to how it was when that backup was taken: your devices, dashboards, settings and history. Anything you have changed since is lost. Your system restarts to do it, which takes several minutes, and the page reconnects on its own when it comes back.

Because it cannot be undone, Restore asks you to confirm in a dialog naming the backup and when it was taken, rather than a button you might press twice by reflex.

A few things Sensa checks before it starts:

  • A backup or a restore already running. You are asked to wait rather than told something vague went wrong.
  • The encryption key. If a backup was made under a different key, for example one taken from another unit, it cannot be unlocked here and retrying will not help.

If something goes wrong after the point of no return, the Backup tab shows what happened when your system comes back up.

If you run Sensa on your own Home Assistant​

On an Enthusiast or DIY system you look after your own backups, and Home Assistant's own backup screen is the place to do it. The Sensa Backup tab is not offered, because writing your Home Assistant's settings from underneath you would not be right.

  1. Open Settings > Backups
  2. Click Create backup and choose Full backup
  3. Set a password, which becomes the encryption key
  4. Save the backup file somewhere safe: a USB stick, a cloud drive, or a NAS
  5. Save the password in a password manager. Without it the backup cannot be opened

Take a backup once a month, and after every meaningful change to your setup.

Keeping a copy off the vehicle​

A backup that only exists on the unit does not survive the unit. Whichever system you have, keep at least one copy somewhere else, and refresh it after any meaningful change.

To recover from a hardware failure, swap hardware, or set up an offsite copy, follow the Recovery steps.