# Backups and restore (/docs/deploying/backups) Neon's free tier keeps about six hours of history. That covers "I ran the wrong query ten minutes ago", and nothing older. So the hosted version keeps its own backups: every night a GitHub Actions workflow dumps the whole database and stores it in an R2 bucket. The backup script's upload, retention and download were tested against a stand-in for R2. The dump itself and every restore step on this page were written without being run: there was no `pg_dump` on the machine they were written on. Until someone has done [the rehearsal below](#rehearse-a-restore) once, treat the backups as unproven. When you have, replace this note with the date and what you found. ## What is in a backup [#what-is-in-a-backup] | | In the nightly dump | Where it lives otherwise | | ---------------------------------------------- | ------------------- | -------------------------------------------------------------------- | | Accounts, workspaces, projects, the binder | yes | | | The current text of every note | yes | also in the collab worker's storage, for notes that have been opened | | Comments, properties, links, canon, settings | yes | | | The list of versions and attachments | yes | | | The bytes of version snapshots and attachments | **no** | the app's R2 bucket (`versions/`, `attachments/`) | R2 stores objects redundantly, but nothing here keeps a second copy of that bucket. If it were emptied, the text of every note would survive and older versions and attached files would not. A dump holds everything in the database, including email addresses, password hashes and every manuscript. Keep the bucket private, and delete any copy you download once you are done with it. ## How it runs [#how-it-runs] * `.github/workflows/backup.yml` runs at 02:23 UTC every night, and whenever you start it by hand (`gh workflow run backup.yml`). * It runs `scripts/backup.ts`, which calls `pg_dump` (custom format, compressed), uploads the file as `backups/plotra-T