saved.sh
DocsPricingDownloadBlog

By source

  • Database backupsPostgres today, on any of the three paths.
  • Files and foldersDirectories on your own hardware. Local path only.
  • Anything you can scriptThe escape hatch, with no reduced guarantees.

By how it runs

  • Backups you driveCLI or API, driven by whatever you already run.
  • Backups on your infrastructureOur worker, your hardware. We never hold the credential.
  • Fully managed backupsWe execute and orchestrate. Nothing to host.
  • Compliance and custodyYour bucket, your account, our orchestration.

Understand it

  • How it worksThree paths, one artifact lifecycle
  • SecurityWhat we can and cannot see
  • CompareAgainst snapshots, cloud-native and scripts
Get started
saved.sh

External backups for the systems a business actually runs on.

A product of reops.

Product

  • Documentation
  • Solutions
  • Compare
  • How it works
  • Security
  • Pricing
  • Download

Developers

  • CLI
  • REST API
  • Recover

Company

  • Blog
  • Privacy
  • Terms

© 2026 saved.sh

Your data survives what holds it.

All postsPricing

We do not delete your backups when your card fails

The moment a customer most needs their data is often the moment their billing broke. So a failed payment starts a ladder, not a deletion, and downloads keep working the whole way down.

1 August 2026·saved.shView as Markdown

A company gets breached on a Tuesday. In the scramble, nobody notices that the card on file expired last month, or that the finance contact who receives the invoices left in June.

By the time someone thinks to restore from backup, the account is delinquent.

This is not a hypothetical edge case. Billing failures cluster around exactly the kind of organisational disruption that also causes data loss, which means a backup product's dunning policy is a data-loss policy whether it was designed as one or not.

What we do

Day 0Credit runs outwe warn you, nothing changesDay 7New work stopsexisting artifacts untouchedDay 30Read-onlyno new backups, everything readable1 yearNothing deleted before thisthe floor, not a grace periodDownloads keep workingat every rung, in every stateGETTING YOUR DATA OUT NEVER STOPSTHE LADDER STOPS THE SERVICE. IT NEVER STOPS YOUR ACCESS TO WHAT YOU ALREADY STORED.
The ladder stops the service. It never stops your access to what you already stored.

Credit runs out and we warn you. At day seven new work stops: no new runs, schedules paused, and configuration stays editable so you can fix the setup while you fix the billing. At day thirty it goes read-only.

Downloads work at every rung. Nothing is deleted for a year.

The one number that matters

A year. Not thirty days, not ninety. Long enough that a lapsed card, an unread email, a departure, or a company going quietly through a bad quarter does not turn into permanent data loss.

Why "stopped" and "blocked" are different rungs

There is a distinction in the middle of that ladder worth explaining, because it came out of asking what a delinquent customer is actually trying to do.

At stopped, new runs are paused but configuration is still editable. That is deliberate. Someone whose billing has lapsed is frequently also mid-way through fixing whatever caused the disruption, and locking their configuration at that moment punishes the recovery, not the debt.

At blocked, nothing new is created or modified. Even here, every artifact that already exists is readable and downloadable.

7days

Before new work stops

30days

Before read-only

365days

Before anything is deleted

No late fees

No penalties, no interest, no reactivation charge. A late fee on an unpaid backup bill collects almost nothing and converts a lapsed customer into an angry one. Paying the invoice reverses the ladder from any stage.

The incentive problem, named

It is worth being direct about why this is not obvious. A backup vendor holding delinquent customers' data has enormous leverage, and the shortest path to collecting an unpaid invoice is to make the data hard to reach.

We think that is a genuinely bad thing to build, and the fact that it works is what makes it worth refusing on purpose rather than by omission.

What to check with any vendor, including us

Find the deletion timeline in their terms. Not the dunning schedule, the deletion timeline. If it is thirty days, or absent, you have learned what happens to your data on your worst month.

Getting your data out is separate from paying for it

Availability is unconditional; the bytes are metered. Those two things are not in tension, and keeping them separate is what stops a billing state from becoming a custody question.

Your backups are yours. The invoice is a different conversation.

Read next

Pricing a backup product honestly

Four meters, no seats, and one line item that is genuinely hard to price. Here is what each one measures and which of them will actually dominate your bill.

Backups that survive the thing that took out production.

How it worksStart free