I received an email from CrashPlan today informing me they have deleted one of my backups. [0]
They have a retention policy [1] that states backups from PCs that have not connected to the service for 6 months will be deleted. However, this policy has never previously been enforced and is not highlighted during signup or setup. I've been a paying user of CrashPlan for around 8 years and was not aware of this policy. The computer in question was listed as not having been active for nearly 2 years. I have several other backups that have been inactive for up to 5 years. I have not yet received any emails about these other devices, but I can only assume I will be soon.
I received no prior warning or notification that this was going to happen.
I contacted support [2] and they claimed the new enforcement was due to a recent audit of the service.
Although the email I received informed me that the data had already been removed, as of this moment it appears to still be accessible. Support have so far been unable to tell me how long it will remain available for, so I'm in the process of downloading many gigabytes of old backups as fast as I can in the hope some automated process doesn't delete them before I have restored them all.
Not the kind of action I want to see from a service that I need to trust with backups of my data.
[0] - http://pastebin.com/SrJuwgDV
[1] - http://support.code42.com/CrashPlan/4/Subscriptions/Backup_Retention_Policy_For_Inactive_Cloud_Destinations
[2] - http://pastebin.com/ee32yhzB
Jarrod from Code42 here. Sorry about the scare. Wanted to clarify a few things.
If a restore has been initiated from the archive of the device in question it's considered "connected" and your data won't be deleted. To be clear - no automated process is going to remove your data while you’re restoring.
You are correct in your assumption about the other devices— we are in the process of enforcing this policy when we previously haven't. We realize that many users won't be aware of this existing retention policy. That's why we've been testing different messages to small batches of users (small meaning .3% of our user base) and seeing how they respond.
Like the email says many of the affected archives are from backups that were once connected to an older device. This often happens because people aren't aware of our "adoption" process that is used to connect and existing backup to a new device. Because silent, continuous backup is very "set it and forget" many folks just end up backing up their new machine instead of getting rid of the old backup. Bit by bit the data in those forgotten archives adds up. Thus why we’ve begun enforcing this policy.
We’re trying to learn as much as possible from these small test batches so that we can clean up some of these “dusty archives” as we call them sooner rather than later while making sure we do right by our customers. I’ve certainly learned a lot from the feedback you’ve provided here.
Please let me know if you have additional questions.
Best Regards,
Jarrod