How Daily Backups work, and where they go
Updated 29 September 2026
Daily Backups keeps a copy of your calendars every night, so a deleted event, a week you wish you hadn't cleared, or a sync that went wrong is something you can undo yourself. It's included on every paid plan.
Backups are off until you choose where they go. That's deliberate: a copy of your calendar is only as safe as wherever it's kept.
The five choices
On the Daily Backups page you pick one. They're listed safest first.
- Your storage, locked (recommended). Each night's copy is delivered to your own Amazon S3 (or Backblaze B2, Wasabi or Cloudflare R2), Azure, Dropbox, Google Drive or OneDrive, locked so only you can open it. We keep no copy.
- Your storage. The same delivery, not locked.
- Our servers, locked. We keep 30 days, locked so only your passkey, your recovery code or your password opens them. We can't read them.
- Our servers, not locked. We keep 30 days, readable. Not recommended.
- No backups. Nothing is kept. Not recommended.
If you sign in with a passkey and haven't chosen, we switch on option 3 for you, locked to your passkey, and email you to save a recovery code.
Locked with a passkey, a recovery code or a password
- With a passkey, your backups are locked to it. Your passkey does the unlocking on your own device; nothing we hold can open them. You also get a recovery code, shown once, in case you lose every device your passkey is on.
- Without a passkey, backups to your own storage are AES-256 zip files locked with a strong password we create and show you once. Keep it in your password manager. Windows and macOS can't open these zips on their own; use 7-Zip on Windows or Keka on a Mac.
Write-only storage
With Amazon S3 or Azure you can give us a key that can only upload: it can't list, read or delete anything. After every delivery we check that the same key still can't read what it just wrote. If someone later widens its access, we email you and show a warning until it's upload-only again.
Dropbox, Google Drive and OneDrive can't be made write-only. We only ever get our own app folder (or, for Google Drive, only the files we created), but we can read what we put there. If GetCalendario were breached, those files could be read. For guaranteed write-only access, use S3 or Azure.
Getting a day back
On the Daily Backups page, choose Get a calendar back:
- Pick the calendar and the day.
- Get the file. For Dropbox, Google Drive and OneDrive there's a link straight to it; for S3 and Azure, the exact path to download. Backups on our servers are fetched for you.
- Unlock it, with your passkey, recovery code or password. This happens in your browser; the file and its events never reach us.
- Take the whole calendar, or only some dates.
- Download the
.icsfile and import it into Google Calendar or Outlook. We suggest importing into a new, empty calendar first, then moving what you need.
Keeping them tidy
On our servers, each backup is deleted after 30 days. In your own storage, how long they're kept is up to you; we never delete there. Most services let you set a rule that removes files after 30 days.
Opening a locked file without GetCalendario
Every backup contains calendar.ics (to import), raw.json (what your calendar
provider sent, for the record) and README.txt.
A locked .gcb file is an open format, so you never depend on us to read your
own backup:
- It starts with
GCB1, then a two-byte length, then a readable JSON header naming the calendar and day, with one entry per way to open it. - Each entry holds the file's key, sealed with libsodium's
crypto_box_sealto that method's public key. For a recovery code or password, the entry also carries the Argon2id salt and costs used to turn it into a key. - The rest is a zip of the three files, encrypted with libsodium's
secretstream(XChaCha20-Poly1305) in 64 KiB chunks.