Sync between devices

Carry your Accounts to a new machine, sealed.

What it's for

Sync keeps one set of Accounts on more than one of your machines. Everything is sealed on the device before it leaves, under a passphrase we never receive, and every device on your licence shares the same set. It stays off until you set a passphrase, and it only ever moves when you press Push or Pull — nothing syncs in the background.

Come here to set up a second machine, or to pull the fleet down after you changed something on another one.

Set it up

Set the sync passphrase

Choose a passphrase of at least 12 characters and set it on this device. Use the same passphrase on every machine — it is what derives the key, and a different one on each device seals a set the others cannot open.

Push from the machine that has the Accounts

Push seals every Account and proxy locally, then uploads. You cannot push or pull until a passphrase is set.

Pull on the other machine

Set the same passphrase there, then Pull. Umbra reloads with the merged set.
The Sync pane showing the three-column trust panel, a passphrase field, and Push and Pull buttons.
The passphrase is set per device; the trust panel spells out both sides.shot-tour · Sync between devices pane: three-column trust panel (Sealed before it leaves / What our server can see / Never synced), a passphrase field, and Push / Pull buttons

The passphrase is the whole margin

Because the key is only ever derived from that passphrase, its strength is the entire security margin. Anyone who obtained the stored data could grind guesses against it offline, at their own pace, with no server-side rate limit standing behind it. The 12-character minimum is a floor, not a recommendation — pick something long and unguessable.

The field shows a strength estimate as you type — Too weak / Weak / Okay / Strong — judged entirely on this device (nothing you type is sent anywhere). It deliberately errs on the harsh side: against an offline attacker, over-rating a passphrase costs more than under-rating one. A few unrelated words beat any amount of symbol-swapping.

Encrypted, not zero-knowledge

Be precise about the promise. Sealing hides the contents of your Accounts and proxies — not that they exist, how many there are, or how big each one is.

The server can read
Each item's id and how many you have, the exact size of every sealed record, the id and time of anything you delete, your licence key, which of your devices synced when, the public salt and a sealed verifier — and, through your licence, your account email.
The server cannot read
The contents of any Account or proxy — logins, cards, Fingerprints, addresses, proxy passwords. Those are sealed on your machine.

So "encrypted" is true and "zero-knowledge" is not the word for it. Don't describe it to a teammate as zero-knowledge, and don't read "encrypted" as "uncrackable." The fuller data map is on What we can see.

Team licences share one copy

There is one synced copy per licence, so on a Team plan your whole team shares it — and shares the one passphrase that opens it. Passphrase strength is still the whole margin, now held by more people. This describes cloud sync only; the Team decision board is a separate, opt-in feature and is not end-to-end encrypted.

Lose the passphrase, and delete is the only way forward

We hold no copy of your passphrase and there is no back door, so we cannot open the sealed copy to recover it — and neither can you.