Trust is the product

Security & Privacy

Last updated: August 10, 2026

A backup app only works if you trust it with everything your clients gave you. This page is the plain-English truth about what we copy, where it lives, how it's protected, who can touch it, and how you stay in control. Where something is still on our roadmap, we say so — we will never claim protection we don't yet provide.

What we back up — and what we leave alone

When you install RecoveredSafe on a sub-account, we read and store copies of your CRM data so we can restore it later: contacts (with custom fields, tags, notes, and tasks), opportunities, calendars and appointments, custom objects, email templates and campaigns, products and invoices, and conversation history. We also keep a safe archive of structures GoHighLevel gives us no way to rewrite — pipelines, forms, workflows, funnels, and payment records — to guide a rebuild.

We do not access anything we don't need to protect you, and we are honest about restore scope: all of your CRM data is one-click restorable; workflows, funnels, and forms are archived for a guided rebuild. See the full scope on our home page.

Encryption

Least privilege & access

Where your data lives

Backups are stored as encrypted objects on Cloudflare R2. We disclose the storage region and will notify you before any material change to where your data is held. Because backups are structured text, storage is small and inexpensive — which is why generous retention is a choice you get to make, not a cost we pass on.

Your control over your data

What we will never do

Your data is used for exactly one purpose: to back it up and restore it for you. We will never sell it, share it, mine it, use it to target ads, or use it to train AI models. Ever.

Transparency

Subprocessors

We keep our vendor list short and purposeful:

Cloudflare

Application hosting and encrypted object storage (R2) for your backups.

GoHighLevel

The platform we back up, via its official API and your authorized install.

Each processes data only as needed to provide RecoveredSafe. We'll update this list before adding a subprocessor that touches your data.

Compliance & credentials Honest today

We follow SOC 2-aligned practices — least privilege, encryption, logging, and change control — today. A formal SOC 2 Type II audit and an independent penetration test are on our roadmap, not yet complete. We will publish them here when they are, and we will not claim a certification we don't hold.

Incident response

If we ever discover a security incident affecting your data, we will investigate promptly, take steps to contain and remediate it, and notify affected customers without undue delay, consistent with applicable law.

Reporting a concern

Found something, or have a security question? Email support@recoveredsafe.com and a real person on the RecoveredSafe team will respond.