Reliability

Backups, recovery, and what we don’t promise

What happens to your compliance records if a server fails — stated plainly, including the parts that are still limitations rather than guarantees.

This page describes Check ID for Teams, where your organization’s scan records live on our servers. On the free and individual tiers nothing is stored on our servers at all: records stay on your device and in your own iCloud account, so recovery there is Apple’s backup of your device, not ours.

How your data is backed up

Check ID Cloud runs on DigitalOcean’s managed PostgreSQL. It takes automated daily backups with point-in-time recovery, retained on a rolling window by DigitalOcean, and stores them separately from the running database. We do not keep a second copy outside DigitalOcean today. If you need a copy of your records held somewhere we do not control, export them — that option is always open to you and is described below.

Backups contain what the database contains. That is scan outcomes, guest lists, devices, staff profiles and audit entries — and no name, date of birth, address, document number or image from any scanned ID, because none of that is ever sent to us. A restored backup therefore cannot expose ID details, because they were never there.

What we would do in a failure

If the database were lost or corrupted, we would restore it from the most recent good backup and bring the API back against the restored database. Because scan records are signed per organization with a key we hold, a restore has to bring that key back too, or the records would come back unreadable — so our recovery procedure treats the key and the database as one unit rather than two.

You would lose any records written between the last good backup and the failure. We would tell you if that happened, and roughly what window was affected. Devices queue scans locally when they cannot reach us and upload them when they can, so scans taken during an outage are generally not lost — they arrive late rather than never.

What we do not promise

We would rather be exact about this than reassuring.

There is no uptime guarantee. Check ID is offered “as is” and “as available” under our Terms of Service, with no service level agreement and no credits for downtime. If you need a contractual uptime commitment, talk to us before you buy rather than after.

We have not yet completed a full restore drill. Backups existing is not the same as a restore having been proven end to end, and we will not claim the second because the first is true. When that drill has been run we will say so here, with the date.

Deletion is permanent. If you delete your data, or close the last account in your organization, we cannot get it back — not from a backup, not on request. Backups age out on their own schedule and are not a recovery route for something you chose to delete. Export first.

Our liability is limited. If data is unavailable, delayed, or lost, the limits in section 16 of our Terms of Service apply, including to any regulatory fine or penalty you incur. That is a real limit and you should read it, particularly if your compliance obligation depends on records being available on demand.

Keeping your own copy

The most reliable protection against anything on this page is a copy you hold yourself. Every Teams plan can export the full compliance log as CSV or PDF, for any date range, at any time — including while a subscription is lapsed. Exports are not gated behind an active plan, deliberately, because the moment you most need your records is the moment you are least likely to be thinking about billing.

A hosted report link is not a substitute for that export. It is a fixed copy of one report, and you can delete it whenever you like. Your export is yours.

If you need a full copy of everything we hold for your organization, email support@checkidapp.com and we will provide it.