1 · Choose a backup file
A JSON backup produced by this product. A backup stamped with a different product is refused before anything is touched.
Scheduled backup
A URL your server's cron can fetch on a schedule. It writes a dated JSON backup into data/backups/ and keeps the newest 14, deleting older ones. Credentials — login hashes, API-key hashes, webhook secrets, 2FA seeds — are blanked in that file, so it is the copy you can hand to a bookkeeper. The /backup.sqlite download is the whole install, for bare-metal recovery; treat that one as secret.