> ## Documentation Index
> Fetch the complete documentation index at: https://3to1go.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Design decisions

> Deliberate choices in how 3to1go backs up, detects changes, keeps snapshots, and restores.

These behaviors are intentional. Knowing them up front avoids surprises.

## Full snapshots

Each backup is a complete `tar.zst` archive of the marked folder's included regular files. Empty directories, special files, and the root `.upload_dir` marker are omitted. There are no incremental backups, block-level deduplication, or delta chains. Every snapshot is self-contained and can be restored on its own with its encryption key.

## Path-and-size fingerprinting

Edge decides whether a new snapshot is needed from a fingerprint of the folder's **sorted file paths and sizes**. It does not hash file contents or look at modification times.

This means an edit that keeps every file's path and size the same does **not** trigger an automatic backup.

<Tip>
  To capture that kind of edit, use **Force Upload** on the job in Edge. If the job has an older staged archive, use **Clear staged backup** first so Force Upload builds a fresh one.
</Tip>

## Count-based retention

Central keeps up to the most recent **N** snapshots per job and Edge instance, where N is Central's **Keep Last Snapshots** setting (default `3`). Retention is count-based, not age- or total-storage-based. Central separately limits the size of each incoming archive.

## Restore replaces files

Restoring a snapshot writes its files back into the job's folder and **overwrites** local copies of the same files. Files that aren't in the snapshot are left untouched. Edge shows a preview of how many files will be replaced and added before anything is written. See [Restore](/edge/restore).

## Permissions

Snapshots preserve regular files' permission bits, including executable and private-file permissions, and restore applies them where the operating system supports it. Ownership, ACLs, and special permission bits are not preserved. Older snapshots can't recover permissions they never recorded.

## Edge skips its own runtime data

On startup Edge marks its spool and state directories with a hidden `.3to1go-runtime` file. Those directories are excluded if Edge ends up backing itself up, even through another mount path. Edge's configuration and encryption key are still included.

## One operator per app

Each app's sign-in is meant for one operator, to keep unauthorized people out. The current UI includes accounts and an admin flag, but there is no tenant isolation or per-user ownership of backups. See [Sign-in and accounts](/shared/sign-in).
