Help & Documentation
Offline-first guidance for safe gear lists.
Cloud Sync & Accounts
Optional multi-device sync — how it works and when to use it
Cine Power Planner stores everything on your device by default. Cloud Sync is the optional feature that mirrors your data to the cloud so a second device can pick up where you left off. This page covers what it is, when to use it, how to sign up, and what to do when something goes wrong.
What Cloud Sync is (and isn't)
Cine Power Planner is local-first: your projects, device library, contacts, and templates live in your browser's IndexedDB by default, with an additional OPFS backup. The app works fully without an account. Cloud Sync is opt-in — you only need it if you want the same data on more than one device, or a copy outside this browser.
- Local-first: nothing leaves your device unless you sign in and enable sync.
- Optional: skip it entirely if you only use one device.
- Bidirectional: changes flow both ways once two devices are signed into the same account.
- Resilient to offline use: changes you make while offline are queued and uploaded the next time you have internet.
- Hosted in Germany on our own infrastructure (Hetzner, Nuremberg). The cloud database is self-hosted Supabase — no third-party cloud vendor sits between you and your data.
- Encrypted in transit (TLS). Server-side, data is stored under your account in a Postgres database that only the app and its administrators can reach.
Tips
- You can sign up later. The app you start using today without an account is the same app — adding an account doesn't change how anything works locally.
- Even with Cloud Sync on, the local IndexedDB copy is still the primary store. Cloud Sync just keeps a second copy in step.
When to enable Cloud Sync
Some workflows benefit a lot from sync, others not at all. A short decision aid:
- Use sync if you regularly switch between a laptop and a tablet, or office and home computer, and want your work to follow you.
- Use sync if multiple people will collaborate on the same project — sync is the channel collaboration travels over.
- Use sync as a second copy in case the device gets lost or the browser profile gets wiped.
- Skip sync if you only ever use one device and you regularly export manual backups.
- Skip sync if a client or production contractually requires that no production data leave your machine.
- Skip sync if you're working with a borrowed or shared computer — sign in only on devices you fully control.
Tips
- Sync is reversible. Sign out and the device falls back to local-only. Your data on that device stays put.
- Even with sync enabled, exporting an occasional manual backup (Settings → Backup & Data) protects you against account problems or accidental mass deletes.
Creating an account
An account is an email and a password. There's no separate subscription required to sign up — the free tier covers all sync features. Paid plans only raise the active-project limit.
- Open Settings from the sidebar (Support section).
- Open the Account tab.
- Click 'Create account'.
- Enter your email and pick a strong password (a password manager is the safest way to generate one).
- If a Cloudflare bot-protection check appears, complete it. It's currently disabled, so most sign-ups won't see it; when shown, it's a one-click step that usually solves itself with no input from you.
- Optionally fill in display name, phone, address, company, and notes. These show up to collaborators when you share a project, and as the issuer block on PDFs you issue (invoices, sub-rental quotes, delivery/return notes).
- Accept the terms and submit.
- Check your inbox for the verification email and click the link. Until you verify, sync stays paused.
Tips
- Use an email you'll keep access to. Password resets and verification all go there.
- Display name is what teammates see in chat, comments, and the sessions list. It can be a nickname.
- Your Tax/VAT ID, IBAN, and signature image live under Settings → Account → Billing & Issuer Details and are stamped onto issued PDFs. Fill them out once before issuing your first invoice.
Common Pitfalls
- Skipping email verification. The verification email sometimes lands in spam — search for 'Cine Power Planner' if it doesn't show up in 5 minutes.
- Using a one-time corporate email you may lose access to. Password resets will also stop working.
Cloud Sync consent — granting and withdrawing
Cloud Sync is treated as a distinct data-processing activity from just using the app: it mirrors your projects, devices, contacts, and templates to our server. As of v0.223 the app records an explicit consent decision before uploading anything, and lets you withdraw that consent at any time. Local-only use never asks for consent — no data leaves the device.
- When you'll be asked: right after your first sign-in. The sign-up form itself asks only for the age confirmation, the terms and privacy-policy acceptance and the optional marketing emails; it has no sync checkbox. The first time an account without a recorded decision signs in, a Cloud Sync consent dialog opens: 'Consent and continue' turns sync on, 'Sign out instead' signs you out and uploads nothing.
- Accounts created before the consent record existed see the same one-time dialog at their next sign-in. It stays open until you choose; until then nothing is uploaded, and signing out instead keeps your data on this device.
- What gets recorded: the timestamp, the privacy-policy version you accepted, and (for withdrawals) an optional free-text reason. This audit trail is what lets us prove on request that no upload happened without your consent.
- Your consent state: each decision is recorded as Granted (with the grant timestamp), Withdrawn (with the withdrawal timestamp), or Not yet decided. The Cloud Sync consent prompt reflects this — you'll be re-prompted whenever a decision is still pending.
- Withdrawing consent: confirm by typing the word WITHDRAW; you may optionally add a reason (up to 1000 characters) that helps us improve the product.
- What withdrawal does: the server-side withdraw-consent edge function purges your cloud data (projects, devices, contacts, templates, attachments — everything that was synced). Your local IndexedDB copy is left intact, and you stay signed in. Sync simply stops running.
- Re-consenting: granting consent again restarts sync. The local copy on this device is uploaded fresh; other devices need to be signed back in to pick up the new state.
Tips
- Consent is per account, not per device. Granting on a laptop covers all signed-in devices on the same account.
- Withdrawing leaves NO trace of your project content on the server — only the consent audit row stays, so we can show when you withdrew. Deleting the account (Settings → Security & Privacy → Danger Zone → Delete Account) removes that audit row too.
- If you simply want sync to stop on one device without withdrawing globally, sign out on that device instead. The cloud copy is untouched and other signed-in devices keep syncing.
Common Pitfalls
- Withdrawing consent and then expecting to recover the cloud copy. Withdrawal is destructive on the server side — the purge runs immediately. If you want a backup first, Settings → Backup & Data → 'Download full backup' before withdrawing.
- Confusing consent withdrawal with account deletion. Withdrawal removes cloud data; the auth row + audit history stay so you can re-consent later. Deletion removes everything including the auth row.
Signing in and out
Sync only runs on devices that are signed in. Signing out is the explicit way to turn sync off for a device; you choose whether its local data stays.
- Sign in on a device → Cloud Sync starts running there in the background.
- Sign out → the 'Sign Out Options' dialog asks what happens to this browser's data. 'Keep Data Offline' stops sync and keeps your projects here; the free-tier project limit then applies, so with more projects than the limit you pick which stay active and the rest are archived (read-only). 'Clear Device Data' removes all local projects and settings from this browser; your cloud copy is untouched.
- Before it stops, sign out gives any edits still queued for the cloud up to 5 seconds to finish uploading. With 'Keep Data Offline' anything left stays in this browser and uploads the next time you sign in to the same account. With 'Clear Device Data' you are told how many changes did not make it and that signing out would delete them — cancel to keep them. The 5 seconds is a hard limit, so an unreachable server can never leave Sign Out hanging.
- Signing out also removes this browser's push-notification registration for your account (and, on an iPhone, its Lock Screen live-progress registration), so the next person on this device does not receive your notifications.
- Sign back in later → sync resumes from where it left off. New changes are reconciled with whatever the cloud has.
- "Keep me signed in" (on the sign-in form) controls how long the session lasts: on, it survives a restart; off, it's cleared when you close the browser — or, in the mobile app, when you fully quit it. On the web it's off by default (safer on shared computers); in the mobile app it's on by default.
- You can stay signed in indefinitely on devices you fully control.
- Sign out before lending a laptop or working on a public/shared computer.
- Switching accounts on a shared device wipes the local data first. When a DIFFERENT account signs in on a device that still holds another account's data, Cine Power Planner erases that local copy before the new account loads — otherwise you'd see the previous person's gear, contacts and invoices.
- If the outgoing account still has unsynced changes, you get a warning naming how many. Cancel it and the new sign-in is called off, so nothing is erased: let the first account sign back in, wait for the sync status to reach "Synced", then switch.
- A link from one of our emails (confirmation, password reset, invitation, email change) that belongs to a different account than the one in use here does not switch on its own. 'Sign in to a different account?' asks first: 'Keep the current account' changes nothing, 'Switch account' removes the current account's data from this device, unsynced changes included. Only continue if you requested the link yourself.
Tips
- All currently-signed-in browsers and devices appear under Settings → Security & Privacy → Sessions & Devices. Revoke any session you don't recognise.
- Signing out doesn't delete your cloud data. Signing back in pulls it back down.
- The cleanest hand-over is always: first account signs out (after sync finishes), then the second signs in.
Reading the sync status
The sidebar profile button (bottom-left, where your avatar lives) shows the current sync state. Hover or tap it for the full label.
- Offline — no internet, or you're not signed in. Local changes are saved as usual and will sync once a connection is back.
- Syncing — changes are still on their way to the cloud. This covers both an active upload and changes waiting their turn (a retry back-off, a conflict you haven't resolved yet, or a very large first upload). The status only turns to 'Synced' once nothing is left waiting.
- Synced — everything in this browser matches the cloud. Other signed-in devices will receive the changes shortly.
- Error — something interrupted sync (auth expired, server unreachable, conflict pending). Open the sidebar profile menu to see the message; usually a sign-out / sign-in fixes it.
Tips
- Cmd/Ctrl + S forces a save to local IndexedDB and the OPFS backup immediately. It doesn't push to the cloud directly — the sync engine will pick it up within seconds when you're online.
- First sync after creating an account or restoring on a new device can take a couple of minutes for large libraries (hundreds of devices, many projects). The status stays on 'Syncing' until everything is uploaded.
- A long 'Syncing' is not a hang: it means changes are genuinely still queued. If it never settles, open the sidebar profile menu — the pending count there tells you how many changes are still waiting.
- Right after you sign in or come back online, the app downloads the latest cloud copy before it uploads your queued changes, so they can't overwrite newer edits from another device. That wait lasts about 30 seconds at most: after that your changes upload even if part of the download is still being retried.
Working offline
Offline use is a first-class workflow, not a degraded mode. You can install the app as a PWA (see the Troubleshooting topic), fly somewhere without internet, and continue creating and editing projects.
- Open the app while offline — it loads from the cache and shows everything you already had.
- Make changes — they save to local IndexedDB exactly as they would online.
- Each change is also queued in an outbox.
- When you're online again, the outbox uploads in the background. The status indicator briefly shows 'Syncing', then 'Synced'.
- You don't need to do anything to trigger this — the app reconnects automatically when the network returns.
Tips
- Open the app once at the office before leaving for a remote location. That guarantees the latest assets are cached for offline use.
- If you'll be offline for days, export a manual backup before you go (Settings → Backup & Data). That's belt-and-suspenders insurance for the trip.
Resolving conflicts
A conflict means the same field or record was changed on two devices while both were partially offline. When both sides hold real work the app does NOT silently pick a winner — it pauses sync and asks you to choose.
- Conflicts are rare. They only happen when two devices edit the same record without seeing each other's change first.
- Signing in on a brand-new device is not a conflict. When every differing field is empty on this device and filled in the cloud, there is nothing here to lose — the cloud copy is accepted automatically and no dialog appears.
- The Conflict Resolver dialog opens automatically when one is detected.
- Each conflicting record shows two columns: 'Local' (what's on this device) and 'Cloud' (what came from the other device).
- For each conflict you choose: 'Keep local', 'Use cloud', or — for lists like a category's items — 'Merge items', which keeps both sides and de-duplicates.
- Keyboard shortcuts switch the view mode: press 1 for Simple View, 2 for Category View (projects only), and 3 for Field-by-Field View.
- 'Apply merge' only applies once every field has a choice. 'Skip This Conflict' postpones the decision: the conflicting record stays queued and the dialog returns on the next sync pass.
- Wait for the Conflict Resolver dialog to appear.
- Read both columns. The 'Local' column shows your current state; the 'Cloud' column shows what other devices saw.
- Pick a resolution for each conflicting field. Use 'Merge items' for lists where both sides have additions you want to keep.
- Confirm. The chosen values are written locally and then pushed to the cloud.
Common Pitfalls
- Skipping or closing the dialog and expecting the devices to agree. The record stays out of step until you decide; the dialog comes back by itself on the next sync pass — the sync indicator cannot reopen it.
- Picking 'Keep Local' on every field without reading the other side. If the cloud version is the more complete one, you've just overwritten it with the older state.
- Assuming an empty 'Local' column means your data is gone. It means this device never had that value. The app now resolves that case on its own; if a dialog still appears, at least one field holds something only this device has.
Profile picture
Your profile picture appears next to your name in chat messages, comment threads, and the Sessions & Devices list. Collaborators see it when you share a project.
- Settings → Account.
- Click the avatar at the top of the page.
- Choose an image file (JPG, PNG, or WEBP).
- Crop to a square — that's the shape it renders at everywhere in the app.
- Save. The picture syncs to your other signed-in devices within a few seconds.
Tips
- Square images render best. Tall or wide images get center-cropped.
- The app compresses uploaded images — don't expect pixel-perfect retention of huge originals.
- Profile picture is account-wide. It's separate from the per-contact photos in the Contacts page.
Your images and attached files
As of v0.222 (CS-17) all image and attachment storage in the cloud is private: profile pictures, contact pictures, gear pictures, project assets, and call-sheet attachments. The app fetches them via short-lived signed URLs that refresh automatically while you're using a signed-in session.
- What changed: five cloud storage buckets (profile-pictures, contact-pictures, gear-pictures, project-assets, call-sheets) were flipped from public to private. They can only be reached by signed sessions on your account.
- Why: stops anyone with a leaked or shared public URL from reading your production assets out-of-band.
- What you'll notice: nothing during normal use. Images on the dashboard, project cards, owned-gear cards, contacts and call-sheets render exactly as before — the signed-URL hook refreshes the URL in the background a few minutes before each one expires.
- What changed for shared links: any image URL you bookmarked or copied to an external doc before v0.222 (those were the old public URLs) returns HTTP 400. Open the relevant page in the app and copy the link from there — the share flow generates a fresh signed link each time.
- Local cache: images you've already loaded once stay in the browser cache for offline viewing, even after the signed URL itself has expired.
- Virus scan: every file you upload is scanned for malware on the server. Until the scan has passed, only the device that uploaded it can open it; your other devices and your collaborators get it once it is clean, normally within seconds. If the scanner is unavailable, the file is kept and scanned as soon as it is back, so nothing is lost. A file found to be infected is deleted from the cloud.
Tips
- If a contact picture or gear picture suddenly fails to load after switching devices or networks, a hard reload (Cmd/Ctrl + Shift + R) re-runs the signed-URL refresh.
- External-facing references to project images (e.g. a Notion page that embedded a gear-picture URL from before CS-17) need to be re-added from the in-app share menu.
Security and where your data lives
We try to be precise about what 'cloud' means here, because most apps are vague about it.
- All cloud-sync traffic is TLS-encrypted in transit.
- Server-side storage: Postgres running on our self-hosted Supabase instance.
- Image and attachment storage: five private buckets accessed via short-lived signed URLs (no public URLs, since v0.222 CS-17). See 'Your images and attached files' above.
- Physical location: Hetzner data centre in Nuremberg, Germany.
- No third-party cloud vendor (AWS / Google Cloud / Azure) holds your data.
- No analytics or tracking on your project content. Besides opt-in crash reports, the only telemetry is an anonymous daily count of how often each tool is opened (with Cloud Sync consent only; no account, device or IP stored).
- Cloudflare Turnstile is integrated as a bot check for sign-up/sign-in but is currently disabled (it may be enabled later); even when active it doesn't see or store your project content.
- Email/password is the only sign-in method. Sessions can be revoked individually from Settings → Security & Privacy → Sessions & Devices.
Tips
- Use a unique strong password and a password manager.
- Sign out of devices you no longer use; review Sessions & Devices periodically.
- Even with Cloud Sync, occasional manual backups (Settings → Backup & Data) are good practice.
Good habits
Small habits that make Cloud Sync feel smoother day to day:
- Open the app on every signed-in device once before going offline for an extended period. That makes sure each device has the latest state cached.
- Try not to edit the same project on two devices at the same minute. The app handles it, but you'll get a conflict dialog later that takes time to resolve.
- Archive projects you've finished. They still sync, but they don't load on startup, which keeps everything snappier.
- Export a manual backup once in a while. Sync is great, but a local .json file is the most portable form of insurance.
- Use a recognizable display name. Collaborators and chat messages all use it.
- Review Sessions & Devices every few months. Sign out anything you no longer recognize.
Sync isn't working — quick fixes
The Troubleshooting topic has a deeper sync section. This is the short list:
- Sync stuck on 'Syncing' for more than ~10 minutes → sign out, close the app, open it, sign back in.
- Changes don't appear on another device → confirm both devices are signed into exactly the same email.
- 'Offline' even though you have internet → corporate network or VPN may be blocking our domain. Try from a different connection to confirm.
- Auth errors right after creating an account → your system clock is probably wrong. Sync needs the device clock to be roughly correct.
- Conflict dialog appears repeatedly → resolve every row in the dialog (don't dismiss it), then save. The dialog reappears only if new conflicts come in.
- Profile picture won't upload → use a smaller image (under ~5 MB) in JPG/PNG/WEBP and try again.
Tips
- If sync errors persist, send a bug report from Help → Support & Feedback. The report bundles the relevant logs automatically — you don't need to copy them by hand.
Cloud Sync is opt-in and reversible. Use it when you need the same data on more than one device, skip it when you don't.
Related Topics
See also
