Changelog

Current public download: version 1.0.15, released 8 August 2026.

Every public stable release appears here automatically.

[1.0.15] — 2026-08-08

This release makes connecting a computer to MomentBackup Hub more dependable and gives clear help when the Hub certificate changes.

Fixed

  • Saving Hub reporting settings now immediately sends the latest signed status report when one exists. If no backup has run yet, the app explains what to do.
  • A Hub certificate mismatch now shows safe, specific help instead of a generic internal-error message.

[1.0.14] — 2026-08-07

This release keeps update actions reachable with long release notes and makes settings feedback easier to use with a keyboard or screen reader.

Fixed

  • Long update notes now scroll inside the app, so Install and Later stay on screen and the notes render as readable text.
  • Confirmation panels keep keyboard focus nearby, Escape closes them, and focus returns to the button that opened them.
  • Settings controls now have distinct spoken names and announce their helper text and status messages through the existing accessibility regions.
  • Destructive actions now meet readable contrast in both light and dark themes.

[1.0.13] — 2026-08-06

This release makes backup plans easier to manage, adds safe agent access, makes encryption the user’s choice for every destination, and fixes setup, scheduling, and repository-opening problems found in testing.

Added

  • Create, rename, duplicate, turn off, and run several File History backup plans. Each plan keeps its own folders, destinations, schedule, and history.
  • Settings → Agent access can connect compatible AI tools to a customer-safe local server. Access is off and read-only by default; changes require an explicit opt-in.
  • Filesystem repositories now appear as one .mbackup package while keeping their incremental contents. Existing repositories still open in place.
  • A signed-in free trial follows the account across computers and keeps the original 21-day clock.

Changed

  • Files & Folders setup now asks for folders, destination, schedule, and optional password protection directly before the first backup.
  • Every destination accepts an encrypted or a plaintext repository. The app states plainly when an off-site copy of a plaintext backup is also plaintext, and never converts or chooses encryption on the user’s behalf.
  • Overview, History, Destinations, and automatic backup status now identify the plan they belong to.
  • Opening a .mbackup package takes the user straight to the existing-backup flow. Restore remains available without a trial or license.
  • macOS packages remain Apple silicon (ARM64) only. Intel (x86-64) macOS packages are no longer produced.

Fixed

  • Encrypted first setup no longer starts a backup before its password is saved or loses changes during background refreshes.
  • Automatic backup checks every due plan, keeps per-plan history, and reports the result that needs the most attention.
  • Local-drive identity is checked again at the actual write, preventing a replugged or replaced disk from silently using stale identity.
  • Finder and second-launch .mbackup opens now reach the existing-backup flow.
  • Agent access returns clear permission and unknown-tool errors and follows settings changes without an app restart.
  • Recovery screens now show the true newest recovery point as Latest.
  • Backup Explorer no longer shows a false empty folder while the first backup is still finishing its recovery-point refresh.
  • Turning automatic backups off during setup now also leaves the saved backup plan off, so every screen reports the same state.
  • Editing a cloud or object-storage extra copy opens its own settings form instead of a blank external-drive form.
  • Saving plan settings no longer drops keyboard focus out of the settings window, long plan names shorten cleanly in headers, and the plan list names the plan that is actually running a backup.

[1.0.8] — 2026-08-02

This release makes the right 64-bit MomentBackup download clear and available across macOS, Windows, and Linux.

Changed

  • Download pages now show separate ARM64 and x86-64 choices for every supported desktop platform.
  • Release packages and updater feeds now cover both supported architectures.
  • MomentBackup remains 64-bit only; no 32-bit app package is shipped.

Fixed

  • Sign-in confirmation now renders safely when a link scanner opens it first.
  • macOS ARM64 downloads use a stable fallback when immutable release metadata would otherwise make the browser display the package as raw data.
  • Windows backup index files now publish safely when security software briefly holds a new file open.

Security

  • Publication checks bind each installer, signature, updater entry, and download to its exact operating system and CPU architecture.
  • Release, download, and update infrastructure moved to the MomentBackup organization with per-service deployment credentials and unchanged proofs.

[1.0.6] — 2026-08-01

This release tightens install, update, and recovery checks across macOS, Windows, and Linux while keeping MomentBackup focused on personal backup.

Changed

  • Personal licenses now cover 1, 3, 5, or 10 computers.
  • Trial and download choices are clearer.
  • Household Hub is clearly marked as unavailable in the 1.0 app and website.

Fixed

  • Windows backup index files now publish safely when security software briefly holds a new file open.
  • Long installed-product checks keep running while the host remains healthy, with clear progress warnings instead of arbitrary time limits.
  • Release checks now catch missing, stale, reused, or mismatched proof before anything can be published.

Security

  • macOS packages must match the exact Watari Labs signer and team identity.
  • Publication still requires exact signed builds, visible license consent, and installed backup, verify, restore, upgrade, and rollback proof.

[1.0.4] — 2026-07-29

This release focuses on reliable everyday backup, restore, installation, and updates across macOS, Windows, and Linux.

Changed

  • Faster backup, restore, startup, and large-list work.
  • Clearer setup, scheduling, update, and recovery flows.

Fixed

  • Fresh-install settings can be saved before the first backup.
  • Windows signed installers and app updates replace files safely.
  • Linux packages and background scheduling behave consistently.
  • Backup verification and restore checks reject stale or unsafe data.

Security

  • Hardened release signing, update verification, credentials, and repository integrity checks.

[1.0.1] — 2026-07-02

The redesigned interface, shipped as a whole. Every screen was rebuilt on the new shell after 1.0.0 was cut, so this release replaces the entire UI.

Added

- Live backup progress in the main window: progress bar, files, speed, and ETA, with a safe Cancel and a final report (size, duration, warnings) when the run ends. Interrupted runs are pointed out on the next launch. - Restore progress and results: live progress and safe cancel during restores, ending with restored/skipped/failed counts and the report location. - Restore test: run a safe sample restore with byte verification from Schedule & scans, with a visible last-tested state. - "Test my recovery key" in Settings → Security proves a typed recovery key can unlock the backup without storing it; the key's saved-at-setup state is shown. - "If this computer dies": a plain recovery walkthrough on the Overview once a first backup exists — latest backup, destination, emergency-kit status, and the recovery route for this platform. - Restores check the target's free space first and warn or stop before filling the disk mid-restore. - The Overview summarizes the protection story: what is protected, where, the off-site copy, last backup and verification times, and the next setup step when something is missing. - First-run setup rebuilt: guided setup with destination choice, encryption and recovery-key handling, a review step showing what will be backed up and its measured size, restore-from-existing-backup for replacement computers, an in-place exclusions editor, and an emergency-kit step at completion.

Changed

- The entire interface was redesigned: new shell, navigation, and screens. - macOS window chrome fixed: traffic lights get their own space, and the window is draggable from the sidebar and top bar. - Setup copy rewritten to plain statements of fact.

Fixed

- Escape in a nested dialog no longer closes the whole setup flow. - The recovery-key screen can no longer be dismissed accidentally while the one-time key is shown. - Setting up over an existing backup now offers to adopt it instead of silently re-keying the repository.

[1.0.0] — 2026-06-23

The first stable public release. Builds on the V1-beta with the commercial, trust, and consumer-cloud work needed for a paid launch.

Added

- Purchase and licensing: a one-time personal license via Polar (merchant of record), with self-contained Ed25519 license keys verified **offline** — an air-gapped machine can be licensed by typing the key or carrying a license file. A web activation page handles the post-purchase handoff and deep-link. - First-run EULA acceptance gate, with the full End User License Agreement bundled in the app. - Consumer-cloud backup destinations: **Google Drive** (one-click OAuth) and **WebDAV** (Nextcloud/ownCloud-style), alongside local disk, NAS/SMB, and S3-compatible buckets. - Email notifications: **Gmail** (one-click OAuth) or bring-your-own **SMTP** — opt-in and best-effort, never required for a backup to succeed. - Scheduling: day-of-week backup windows and change-triggered backups (open app), plus a retention-thinning preview. - A round of consumer 1.0 polish across first-run setup, restore safety, backup health, destination reconnect, and the recovery/emergency-kit surfaces.

Changed

- A 14-day money-back guarantee.

Guarantees

- Restores are never license-gated: existing backups stay browsable, unlockable, verifiable, and restorable even with an expired trial or no license.

[0.9.0] — 2026-06-10

The V1-beta cut: the consumer surfaces, reliability layer, and release machinery for the first stable release. See docs/v1-scope.md for exactly what V1 claims and on which platforms.

Added

- First-run setup wizard with encryption on by default and a gated recovery-key ceremony (you must confirm the key is saved before finishing). - Auto-updates: signed update artifacts, a Check for updates row in Settings → About, and a tagged-release pipeline producing installers for macOS, Windows, and Linux. - Crash safety: a global panic hook writes crash logs under the app data directory; Settings → About gains a redaction-safe "Save diagnostics…" export (never file contents or passwords). - Whole-computer schedule calendar (Full backup / Catch-up / Quick update) with a month preview, plus retention thinning visualized in plain words. - "Go back in time" snapshot scrubbing with ←/→, a jump-to-date control, and crossfading file lists. - Unified window chrome on all three platforms: overlaid title bar on macOS, frameless windows with custom caption controls on Windows/Linux. - Command palette actions: Back up now, Set up backup, theme and accent.

Changed

- The whole interface was recomposed for consumer-simple clarity: an 8-screen plain-language IA, grouped settings lists instead of stacked boxes, one primary action per screen, and Advanced disclosures for every power surface. - All sizes are decimal (KB/MB/GB/TB) everywhere; backup kinds read as plain words (Full backup / Catch-up / Quick update); scheduler status and history messages use the same vocabulary end to end. - Recovery instructions ("My computer died") rewritten for a stressed reader, with the evidence machinery folded behind Advanced recovery tools.

Fixed

- Backup, restore, and migration paths no longer panic on malformed paths or metadata — they fail with typed errors; a worker panic can no longer abort a whole parallel backup or restore run. - Reclaim on encrypted repositories maps referenced hashes to on-disk names before sweeping (pre-existing fix, recorded here for the release trail).

Known limitations

- Code signing and notarization are wired but inactive until certificates are enrolled; updater downloads require the releases feed to be publicly reachable. - Disaster-recovery imaging is Windows-first; macOS whole-machine restore defers to Apple Recovery by design. - Licensing/activation is not yet implemented (pricing model undecided).