n8n Backup · Version 3.0.0

Privacy policy

Your backup data stays under your control.

Who provides this extension

n8n Backup - Export Workflows is published by Steward the Teacher. Contact stewardobeng@gmail.com for support or privacy questions. This independent extension is not affiliated with or endorsed by n8n. This policy describes version 3.0.0. Last updated: September 17, 2026.

What the extension handles

You provide account names, n8n server URLs, and API keys. The extension reads workflow definitions and, when the server permits it, credential metadata such as names, types, and IDs. Workflows may contain parameters, pinned data, or embedded sensitive information. Credential secret values are not exported by the credentials endpoint. The extension also stores backup metadata, scheduling preferences and outcomes, and restore history including workflow names and created IDs.

Current-tab detection

When you open the toolbar popup, the extension may inspect the current tab URL and a few public page markers: n8n metadata tags, the page title, the app element, and favicon markers. It uses these locally to recognize an n8n editor and prefill an account URL. It does not read browsing history, track all tabs in the background, read login cookies, extract API keys from pages, or collect arbitrary page text.

Where data goes

Accounts and preferences are stored in Chrome local extension storage; archives and their metadata are stored in local IndexedDB. There is no developer-operated backend, analytics, advertising, cloud synchronization, or automatic upload to a third party. The publisher does not receive your keys, workflows, archives, or usage telemetry through the extension.

Direct communication with your n8n server

Connection tests and manual or enabled scheduled backups send API requests directly to the server you configure, using your API key. A confirmed restore sends selected workflow definitions to the destination server you choose. That server receives the request data, API key, and ordinary connection information such as your IP address, and applies its own policies. The extension omits browser cookies and rejects API redirects. HTTPS encrypts network traffic; an explicitly configured HTTP server does not provide transport encryption. Use HTTPS for remote instances. Local storage does not mean these requested API operations are offline.

Optional vault encryption

If you enable the vault, saved API keys and archive contents are encrypted locally using AES-GCM with a key derived from your password using PBKDF2. Passwords are not saved or sent to the publisher. The unlocked derived key is held in trusted Chrome session storage while unlocked and clears on browser restart or extension reload/disable. Account names, URLs, backup metadata, schedules, and restore history are not encrypted. An interrupted migration can leave some previous records unencrypted until resumed. Locking stops new access; already running operations may finish. There is no password recovery.

Downloads, exports, and imports

Downloaded workflow ZIPs are unencrypted even if the stored copy uses the vault. Portable library exports can be encrypted using a separate password. These files go to the location you select on your computer. The extension does not upload them; if you place them in a synchronized folder or share them, that is governed by the services you choose. Portable exports contain backups, not saved account keys, schedules, or restore history. Imports add archives locally; they do not automatically restore workflows to a server.

Retention and deletion

Local backups remain until you delete them; they are not automatically pruned. Remove an account to remove its saved API key; its backups remain separately available until deleted from the library. Pausing a schedule stops future scheduled runs, but its local configuration and outcome may remain. Restore history remains in local extension storage. Uninstalling the extension or deleting the browser profile removes extension-local data, including remaining schedules and history. This does not delete downloaded files or workflows already created on an n8n server. Delete those separately. Device loss or storage failure can also remove local data; keep independent copies.

How information is used

Information is used only to provide the disclosed backup and recovery features: account selection, current-tab recognition, backups, comparison, encryption, scheduling, export/import, and confirmed restoration. User data is not sold, used for advertising, or used to determine creditworthiness or lending. The use and transfer of user data by this extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Support and this website

If you email support, the publisher receives the address, message, and attachments you choose to send through email service providers. This voluntary correspondence is used to handle your request. Do not send API keys, vault passwords, or sensitive backup files. You may request deletion of support correspondence at the contact address, subject to applicable retention obligations. These documentation pages include no analytics, remote fonts, or tracking scripts. The website hosting provider may process routine access logs under its own policy; this is separate from extension data storage.

Changes and contact

The published policy date will be updated if these practices change. Material changes to extension data handling will be disclosed before they take effect as required by applicable policy. Contact stewardobeng@gmail.com for questions about this policy or support.