Keeping It Safe

Atomic writes, history, the bin, the backup folder, and a full disk.

What happens every time you stop typing

Quillard saves constantly, and every save is written to a temporary file first and then renamed into place. A rename is the one operation a disk treats as all-or-nothing, so a crash in the middle of a save leaves the good file untouched rather than half a book.

Any temporary file left behind by a crash is cleared at the next launch. You will never be asked to choose between two versions of your own work.

The save button. ⌘S writes this book to a .quill file of its own.
The save button. ⌘S writes this book to a .quill file of its own.

Three kinds of going back

History keeps around a hundred and twenty versions of each book, deduplicated, and any of them can be restored. Rolling backups take a copy every twentieth save and keep fifteen. Undo is a hundred and twenty steps, coalesced sensibly so that a sentence you typed comes out as a sentence rather than forty keystrokes.

Deleted books go to Recently Deleted and stay there for thirty days. Deleted chapters, sections, clippings and notes go to the bin and come back in the place they left, not at the end of the list.

The backup folder

All of the above lives on one disk. One dead drive takes the lot — so Quillard can mirror the whole library into a folder of your choosing, as a dated archive it writes and then reads back to check.

Choose that folder under File → Config → Folder. The useful trick is to pick a folder your computer already syncs somewhere else — Dropbox, Google Drive, iCloud Drive, OneDrive, a git repo. Quillard writes the archive; the service you already trust carries it off the machine. There is no account to make and nothing new to trust.

If the folder you choose sits on the same disk as your library, Quillard says so plainly, because a copy there dies with the original.

Knowing that it worked

A backup you have not checked is a rumour. Quillard reads the newest archive back on a schedule and complains loudly if it will not parse.

Backup state in the status bar: amber when no folder is set, grey with the time when one is.
Backup state in the status bar: amber when no folder is set, grey with the time when one is.

The same line appears in Config, with the exact time of the last archive that succeeded. If none has succeeded, it says that instead of saying nothing.

When the disk fills up

Below five hundred megabytes free, a strip appears and tells you. Below fifty, it turns red, the rolling backups and snapshots pause, and the library itself keeps saving — because the last thing to give up should be your words.

If there is genuinely not enough room to write the library safely, Quillard refuses the save and says so, rather than writing half a file over a whole one.

Nothing here asks you to trust us. It asks you to keep a copy somewhere else, and it tells you when you have not.