If you synchronize a Safe with Apple iCloud (CloudKit), you can set it up again later on the same or another Mac, iPhone, or iPad. To do this, you need the previously saved synchronization configuration file and the corresponding Safe password.
This uses the same setup process as connecting another device to the Safe. You do not need to transfer the configuration file directly from one device to another: you can use the securely stored file later, provided the requirements below are met.
- Export the synchronization configuration.
- Keep the configuration file and Safe password available.
- Set up the Safe on the new device.
- Synchronize the encrypted contents from CloudKit.
What do you need to restore the Safe?
You need:
- the previously saved synchronization configuration file,
- the Safe password that was valid when this file was created,
- access to the associated iCloud account,
- an internet connection, and
- SimpleumSafe on the new or newly set up device.
The data stored in CloudKit must have been fully synchronized and must still be available.
The configuration file remains protected by the password used when it was exported. If you later change the Safe password, an older configuration file can still only be opened with the previous export password. Therefore, create and securely store a new synchronization configuration file after changing the password.
The synchronization configuration file does not contain the Safe password in plain text. However, it contains particularly sensitive information and key material required to set up the synchronized Safe.
Save the synchronization configuration file in advance
Create and save the configuration file while you still have access to the open Safe.
On a Mac
- Open the Safe.
- From the menu, choose Safe > Connect other Device to this Safe ….
- Enter the current Safe password.
- Select Share Sync Configuration as file, then choose Save.
- Save the synchronization configuration file in a secure location.
On an iPhone or iPad
- Open the Safe.
- Open Settings > Synchronization.
- Select Connect other device to this Safe.
- Enter the current Safe password.
- Select Share or Store and save the synchronization configuration as a file.
- Store the file securely afterward.
The names of individual buttons may vary slightly depending on the platform and app version.
Store the configuration file and password securely
Store at least the following information securely:
- the synchronization configuration file,
- the corresponding Safe password, and
- the separate recovery password, if one has been set up.
For example, you can store the configuration file as a protected attachment in a trusted password manager. Alternatively, you can keep the file and password separately in secure locations.
Treat the synchronization configuration file as particularly sensitive access information. Anyone who has both the file and the corresponding Safe password and can access the associated CloudKit data could potentially set up and decrypt the Safe.
Restore a CloudKit Safe on a Mac
- Install SimpleumSafe on the Mac.
- Make sure the Mac is signed in to iCloud with the associated Apple Account.
- In SimpleumSafe, choose Safe > Connect to existing Sync Safe ….
- Select Load Sync configuration file.
- Open the previously saved synchronization configuration file.
- Enter the corresponding Safe password.
- Follow the remaining steps in SimpleumSafe.
- Start synchronization and wait until the required data has been fully downloaded from CloudKit.
The initial synchronization may take some time depending on the amount of data and the internet connection.
A similar setup flow is also available on the Mac for a Safe using folder synchronization. In addition to the synchronization configuration file and its password, you need access to the original synchronization target. During setup, select or authorize that folder again. Folder synchronization is currently available only on the Mac.
Restore a CloudKit Safe on an iPhone or iPad
- Install SimpleumSafe on the device.
- Sign in to iCloud with the associated Apple Account.
- In SimpleumSafe, select Create or add Safes.
- Select Connect to existing Sync Safe.
- Open the previously saved synchronization configuration file.
- Enter the corresponding Safe password.
- Follow the remaining steps.
- Allow SimpleumSafe to fully synchronize the Safe data from CloudKit.
If possible, do not edit important files until the initial synchronization has finished completely.
Example: Prepare access while traveling
You can also use this option if you do not want to take a local copy of the Safe with you when you begin a trip:
- Save the synchronization configuration file securely before traveling.
- Store the corresponding Safe password securely.
- Verify that you can access the associated Apple Account and complete any required sign-in confirmations.
- Install SimpleumSafe at your destination only on your own or another trusted device.
- If necessary, set up the Safe using the configuration file and password.
- Wait until synchronization has finished completely.
Do not set up the Safe on a device that is not yours or that you do not trust.
Important: This is not a backup
- The file is available on all connected devices.
- The deletion is propagated to all connected devices.
- The earlier state is restored from the independent backup.
This procedure restores the synchronization state currently available in CloudKit. It does not automatically return the Safe to an earlier state.
Synchronization therefore does not protect you, for example, if you:
- accidentally delete a file,
- unintentionally overwrite a file,
- synchronize unwanted changes, or
- synchronize an incomplete data state with other devices.
Such changes may also be propagated to CloudKit and connected devices. If you then set up the Safe again, you receive the current synchronized state – not automatically an older, unchanged version.
To protect against accidental changes, deletions, or damage, you also need an independent backup that retains earlier data states.
What happens if the configuration file is lost?
If a working device is still connected to the Safe, you can create a new synchronization configuration file on that device.
If all configured devices have been lost or are no longer accessible and you no longer have a synchronization configuration file, the Safe password alone is not enough to set up the CloudKit Safe on a new device.
Save the configuration file in advance and periodically check that it is still available in its storage location.
Is the recovery password the same as the synchronization configuration?
No. The recovery password helps you regain access to an existing Safe if the regular Safe password is no longer available. The synchronization configuration file, by contrast, is required to set up the Safe synchronized through CloudKit on a new device.
These two precautions serve different purposes and should both be stored securely.