Skip to content

Data locations

This page lists where BioTrack keeps its files on a Windows PC. It is for IT staff planning backups, audits, monitoring or support.

All collector data lives in %ProgramData%\BioTrack (usually C:\ProgramData\BioTrack). Only SYSTEM, the Administrators group and the collector service account have full access. The Windows user set up for BioTrack can open the folder, read only the local channel secret, and write only to maintenance-transfer.

  • DirectoryC:\ProgramData\BioTrack
    • attendance.db encrypted database (attendance, employees, settings)
    • attendance.db.key database key, protected with machine-scoped DPAPI
    • collector-rpc.key secret for the authenticated local channel
    • Directorylogs/ collector service logs
      • …
    • Directoryservice-logs/ service wrapper logs
      • …
    • Directorymaintenance-transfer/ staging area for backups being restored
      • …
    • Directoryservice/
      • Directorybackups/ automatic daily backups, latest 30 kept
        • …
      • Directorycrash-evidence/ crash records
        • …
      • Directoryplaintext-migration-quarantine/ only after upgrading from an unencrypted release; removed after 30 days
        • …
      • network-approval.json approved terminal address and listener port
      • network-setup.log log of the firewall approval helper
      • BioTrackCollectorService.exe service wrapper
      • BioTrackCollectorService.xml service wrapper configuration
ItemNotes
attendance.dbThe single source of truth for this site. Encrypted; open it only through BioTrack.
attendance.db.keyWithout it the database and daily backups cannot be opened. Never copy it off the PC or share it.
collector-rpc.keyNever share it.
service\backupsEach daily backup has a manifest. These are same-machine recovery points, not portable exports.
maintenance-transferBioTrack copies a chosen portable backup here before restoring it.

Portable backups are saved wherever you choose when you create them: a .db file and a .manifest.json file beside it. See Backup and recovery.

Each Windows user who opens BioTrack gets their own folder under %LOCALAPPDATA%\BioTrack (usually C:\Users\<name>\AppData\Local\BioTrack):

  • Directory%LOCALAPPDATA%\BioTrack
    • Directoryui-logs/ desktop window logs (may include employee names)
      • …
    • Directoryui-session/ window preferences and browser storage
      • …

The desktop window does not store attendance data here.

ItemLocation
ApplicationC:\Program Files\Biotrack\Biotrack.exe (installed for all users)
Commissioning scriptsC:\Program Files\Biotrack\resources\commissioning\
Setup logA temporary file in the installing administrator’s %TEMP% folder. Setup shows its path on success and failure.
PropertyValue
Service nameBioTrackCollector
Runs asNT SERVICE\BioTrackCollector (virtual account, no password)
Start typeAutomatic (delayed start), with automatic restart on failure
Listener portChosen during setup; default 8089
FirewallOne inbound rule allowing only the configured terminal address on the listener port

See Security and privacy for how these files and the service are protected.