A backup app only works if you trust it with everything your clients gave you. This page is the plain-English truth about what we copy, where it lives, how it's protected, who can touch it, and how you stay in control. Where something is still on our roadmap, we say so — we will never claim protection we don't yet provide.
When you install RecoveredSafe on a sub-account, we read and store copies of your CRM data so we can restore it later: contacts (with custom fields, tags, notes, and tasks), opportunities, calendars and appointments, custom objects, email templates and campaigns, products and invoices, and conversation history. We also keep a safe archive of structures GoHighLevel gives us no way to rewrite — pipelines, forms, workflows, funnels, and payment records — to guide a rebuild.
We do not access anything we don't need to protect you, and we are honest about restore scope: all of your CRM data is one-click restorable; workflows, funnels, and forms are archived for a guided rebuild. See the full scope on our home page.
Backups are stored as encrypted objects on Cloudflare R2. We disclose the storage region and will notify you before any material change to where your data is held. Because backups are structured text, storage is small and inexpensive — which is why generous retention is a choice you get to make, not a cost we pass on.
Your data is used for exactly one purpose: to back it up and restore it for you. We will never sell it, share it, mine it, use it to target ads, or use it to train AI models. Ever.
We keep our vendor list short and purposeful:
Application hosting and encrypted object storage (R2) for your backups.
The platform we back up, via its official API and your authorized install.
Each processes data only as needed to provide RecoveredSafe. We'll update this list before adding a subprocessor that touches your data.
We follow SOC 2-aligned practices — least privilege, encryption, logging, and change control — today. A formal SOC 2 Type II audit and an independent penetration test are on our roadmap, not yet complete. We will publish them here when they are, and we will not claim a certification we don't hold.
If we ever discover a security incident affecting your data, we will investigate promptly, take steps to contain and remediate it, and notify affected customers without undue delay, consistent with applicable law.
Found something, or have a security question? Email [email protected] and a real person on the RecoveredSafe team will respond.