Overview
Personal Backup protects your device key shares - the portion of the MPC key material stored only on your mobile device. Since these shares exist only on your phone, you risk losing access if your device is damaged, stolen, or replaced. Personal Backup secures your account by encrypting your shares with a recovery phrase and storing them on Utila’s servers, so you can restore access at any time.
Personal Backup is user-level, not vault-level. One backup covers all the vaults you participate in.
Without a personal backup
If you lose your device, delete the app, or upgrade to a new phone, you risk losing signing capabilities in every vault you belong to.
Recovery requires other vault members to re-provision your access manually.
If you all vault signers lose signing capabilities and their personal backup then the vault funds will be lost forever
The vault owner, all admins, and all signers must create a Personal Backup as part of their initial setup.
With a Personal Backup, you can restore your device key shares on any device by entering your 13-word recovery phrase, without depending on other signers.
For the process, see Create a personal backup of device keys.
Understanding the 13-word recovery phrase
When you create a Personal Backup, the Utila app automatically generates a 13-word recovery phrase:
Words 1 through 12 are your secret recovery words. These are used to derive the encryption key that protects your device key shares. They must be kept private and stored securely.
Word 13 (the hint word) is a public identifier. It is stored on Utila's servers and shown in the app to help you identify which backup is yours. It is not secret and cannot decrypt your shares on its own.
Write down all 13 words in the exact order they are shown, and store them securely offline. If you lose words 1 through 12, you cannot recover your device key shares from that backup.
Utila recommends storing the phrase in a secure physical location and managing it collectively at the organizational level according to your security policy.
Active and Inactive backups
The active (primary) backup
A user can have only one active backup at a time. The active backup is the one Utila uses for all backup, recovery, and validation operations. It is identified in the app as Active Backup.
You can view details of the primary personal backup. Tap the menu, select My profile, and then tap Personal Backup. On the primary personal backup page, tap Inspect Backup. From here you can test the access to the backup by entering the phrase to confirm you still have it.
When you open a vault on a new device, you are asked to enter the phrase for your active backup to restore access.
Inactive backups
When you create a new backup, the previous backup becomes Inactive. Inactive backups are previous versions of your backup. Their encrypted copies remain on Utila's servers and can still be used for recovery, as long as you have that backup's phrase.
You can view inactive backups in the Personal Backup section of your profile. From there you can:
View the backup's details (hint word, last validated date)
Activate an inactive backup, making it the new primary and deactivating the current one. You will need to enter that backup's phrase.
Test access by entering the phrase to confirm you still have it.
If you created a new backup because you lost your old phrase, you will not be able to recover device key shares that were only encrypted under the old backup, since those require the old phrase.
