Free data destruction free analysis request →
Products Recover
+32 (0)800 11 400 free analysis request

Software

Recover, our data recovery software

Deleted files or a formatted drive: with Recover you get your data back yourself. Free, without limits, for Windows, macOS and Linux. The source drive is only read, never written to.

Free download ↓

What Recover does

Recover is Datarecuperatie software for getting files back from hard drives, SSDs, USB sticks, memory cards, RAID sets and disk images. It is meant for logical problems: files that were deleted, or a drive that was formatted.

The most important rule is built into the software: the source drive is only ever read. You always write recovered files to a different drive.

Recover after a scan: partition, folder tree and file list
After a scan: the partition, the folder tree and the recovered files.

Step by step: the manual →

First the question: is the drive healthy?

A scan reads the entire surface of the drive. With a mechanical or electronic fault, that can cause exactly the damage that makes data unrecoverable. That is why Recover explicitly asks, before every scan, whether the drive is physically sound.

If the drive clicks, ticks or grinds, disappears and comes back, gets very hot, or has been dropped, opened or water damaged, stop right away and have it checked by a lab. If the drive is healthy and the problem is logical, you can continue. Safer still is to make a disk image first and work from that: Recover offers that choice straight away.

Recover asks before scanning whether the drive is physically healthy
Before every scan: a check for signs of physical damage, with the option to make a disk image first.

Signs of a failing drive? Request a free analysis →

What you can do with it

  • For every deleted file Recover shows straight away what to expect: intact, partly reused or overwritten. So you know before recovering which files will come back complete.
  • From the search indexes of Windows (Windows Search), macOS (Spotlight) and Linux (Tracker), Recover fills in the folder structure and file names, even for files the file system no longer knows.
  • A log keeps track of what happened.
  • Open virtual disks and images directly: VHD, VHDX, VMDK, QCOW2, VDI, E01 (also compressed), DMG and split raw images.
  • Assemble RAID sets from separate drives or images: RAID 0, 1, 5, 6, 10 and JBOD. Recover reads the Linux md metadata on the drives and rebuilds a missing drive (up to two for RAID 6). After free registration.
  • Dynamic multithreading, tuned to the condition of the drive: a healthy drive is read with several threads at once; as soon as it reports read errors, Recover falls back to a single reader. The result is the same, and the drive is not put under extra strain.
  • Open encrypted volumes with the password or recovery key: BitLocker (also with a .BEK file or suspended), LUKS1 and LUKS2, VeraCrypt and TrueCrypt, encrypted DMG and APFS FileVault. After free registration.
  • Lost partition search: Recover scans the drive for the signatures of NTFS, exFAT, FAT, ext, APFS, HFS+, XFS, Btrfs and ReFS, and reads a found partition straight away.
  • The interface is translated into 54 languages.

Files

Read partitions and the file system, find deleted files and filter them: deleted only, hide unrecoverable, everything in one list, or supplemented from the search index. Recover per file, per folder or the whole list.

Carve (signature search)

Where the file system knows nothing any more, Recover looks for files by their recognisable start and structure (file carving): 334 formats, 554 extensions, from photos and documents to databases, video and mail archives.

Disk image

Make a full copy of the drive and continue working on that, so the original drive is stressed as little as possible. Recover also opens existing image files.

Technical: file system, carving and search index

During a scan, Recover reads the file system structures, such as the Master File Table (MFT) on NTFS, and shows the records of deleted files alongside the existing ones. Whether a deleted file can still be fully recovered depends on whether the location of its data is still known and has not been overwritten.

File carving works without a file system: it searches the drive for known file headers and structures. That way it finds files after heavy damage or formatting, but without their original name or folder.

The search indexes of Windows, macOS and Linux keep file names and paths in their own databases. Recover reads those databases and uses them to rebuild the folder structure.

Supported file systems

File systemWhere you find itDeleted files
FAT12, FAT16, FAT32 USB sticks, memory cards yes, with long names
exFAT memory cards, external drives yes
NTFS Windows yes, also fragmented and whole folders
ext2, ext3, ext4 Linux, many NAS devices yes, ext3/4 via the journal
XFS Linux servers, NAS written, not yet confirmed on real cases
Btrfs Linux, Synology written, not yet confirmed on real cases
HFS, HFS+ older macOS yes
APFS macOS not yet confirmed
ReFS Windows Server, Storage Spaces yes on 3.x; 1.x content search only
UDF DVD, Blu-ray, some cameras yes
UFS BSD, older Unix, some NAS yes
F2FS Android, flash memory folders and names
JFFS2, UBIFS flash memory in routers and devices yes
ZFS TrueNAS, Solaris, Proxmox file contents read (byte-verified); deleted via carving
VMFS VMware datastores (ESXi) file contents read (byte-verified); deleted via carving
bcachefs Linux (recent) file contents read (byte-verified); deleted via carving

In total Recover reads 27 file systems with their folders and names, down to the byte-verified file contents (including ZFS, VMFS and bcachefs), with CoreStorage additionally detected and identified. Partition tables: GPT (also with 4K sectors), MBR with logical partitions, or no table. Compressed NTFS files are flagged but not yet decompressed.

Usage reporting: open about what is sent

Recover reports to Datarecuperatie which kind of drive is used and which functions are used. File names, paths and file contents are never sent. That is also stated at the top of the software window.

In the settings you see exactly what a report looks like before it is sent. Including the drive serial number is a separate choice, and reporting can be switched off completely.

Usage reporting settings in Recover, with an example report
The settings show literally what a report contains.

Recover next to other free software

As of 24 September 2026. Where Recover falls short, it says so. Data on the other programs comes from their own websites and is not re-checked daily.

FeatureRecoverRecuva FreePhotoRec / TestDiskDMDE Free Edition
Price ✅ €0 ✅ €0 ✅ €0 ✅ €0
Windows, macOS, Linux ✅ all three ⚠️ Windows only ✅ all three ✅ all three
File names and folders back ✅ 27 file systems ✅ FAT and NTFS ❌ PhotoRec only gives f0001234.jpg ✅
Deleted files with their name ✅ FAT, exFAT, NTFS, ext2/3/4 (via the journal), HFS/HFS+, ReFS, UDF, JFFS2, UBIFS, UFS ✅ FAT and NTFS ❌ ✅
No limit on the number of files ✅ ✅ ✅ ❌ 4,000 at a time
Content search (carving) ✅ 334 types, 550+ extensions ❌ ✅ 353 families ⚠️ limited
Exact length per recovered file ✅ from the format's structure – ❌ often runs on to the next file ⚠️ partly
Search indexes ✅ Windows Search, Spotlight, SQLite ❌ ❌ ❌
Reads SMART ✅ incl. NVMe ❌ ❌ ✅
Refuses to scan a dying drive ✅ ❌ ❌ ❌
Disk imaging ✅ ❌ ✅ ✅
E01 (EnCase) ✅ incl. compressed ❌ ❌ ✅
VHD, VHDX, VMDK, QCOW2, VDI ✅ with snapshot chains ❌ ❌ ⚠️ partly
Names from the recycle bin ✅ ✅ ❌ ⚠️
RAID and NAS ✅ 0, 1, 5, 6, 10 and JBOD, also RAID 6 with two drives gone (after free registration) ❌ ❌ ⚠️ manual
Encrypted volumes ✅ BitLocker, LUKS1/2, VeraCrypt/TrueCrypt, encrypted DMG, FileVault (after free registration) ❌ ❌ ❌
Lost partition search ✅ reads a found partition straight away ❌ ✅ TestDisk, strongest of the free tools ✅
Graphical interface ✅ three platforms, 54 languages ✅ ⚠️ QPhotoRec, limited ✅

⚠️ = partly, or depending on version or edition. Search indexes: Windows Search, Spotlight and Linux SQLite indexes remember names, folders and dates, even of files the file system no longer knows.

Read the Recover manual →

Recover next to paid software

The professional programs labs use. Prices in dollars as the vendors list them in September 2026; some charge separately per platform or for commercial use.

FeatureRecoverDMDE StandardDMDE ProfessionalR-StudioR-Studio TechnicianUFS Explorer Professional
Price ✅ €0 $48 $95 (multi-OS $133) $79.99 $899 ± $700
Use for clients ✅ allowed ❌ own use only ✅ ✅ ✅ ✅
Three platforms, one licence ✅ ❌ ⚠️ multi-OS only ❌ per platform ✅ ✅
File systems read ✅ 27 ± 7 ± 7 ± 8 ± 8 ✅ 20+, incl. ZFS, VMFS, Novell
ReFS ✅ 3.x, incl. deleted files ⚠️ ⚠️ ✅ ✅ ✅
RAID and NAS ⚠️ 0/1/5/6/10/JBOD with Linux md metadata; DDF, Intel RST and Storage Spaces not yet ✅ ✅ ✅ ✅ ✅ incl. NAS profiles
Encrypted volumes ✅ BitLocker, LUKS1/2, VeraCrypt/TrueCrypt, DMG, FileVault ⚠️ partly ⚠️ partly ⚠️ partly ⚠️ partly ✅
E01 ✅ free ✅ ✅ ❌ Technician only ✅ ✅
Content search ✅ 334 types, exact lengths ⚠️ ⚠️ ✅ broad ✅ broad ✅ broad
Search indexes ✅ ❌ ❌ ❌ ❌ ❌
Refuses a dying drive ✅ ❌ ❌ ❌ shows only ❌ shows only ❌ shows only
Lost partition search ✅ ✅ ✅ ✅ ✅ ✅
Remote assistance ✅ paid, operated by our lab ❌ ❌ ⚠️ ✅ ✅
Forensic hash verification ⚠️ SHA-1 on verification ❌ ⚠️ ⚠️ ✅ ✅

Prices of September 2026, excluding VAT. Check them with the vendor: they change, and several vendors price per platform and per commercial licence.

Where Recover stands alone

Reading search indexes

Windows Search, Spotlight and SQLite indexes hold names, paths and dates of files whose metadata is gone. No other program in this comparison reads them.

Refusing a dying drive

The others show SMART at most and keep scanning. A full scan on a drive with a failing head costs exactly the last readable sectors.

Exact lengths, with a written account

Every recovered file follows its format's structure. Where that is impossible, a public document says why, including formats we refuse on purpose because they have no provable end.

Formats identified at the end

Some formats (like Macrium Reflect X backups) only identify themselves in their last bytes. Recover bounds them from back to front.

E01 for free

Forensic images in EnCase format, also compressed. R-Studio asks the $899 Technician licence for this.

Modern, with almost 40 years of experience

Recover is newly developed: a fresh codebase that handles modern file systems, encryption and containers from the ground up, without old code dragged along over the years. But it comes from a lab that has been working on clients' drives for almost forty years. Not one or the other, but both.

The tests are our own and checked byte for byte every time: 153 references for content search, 46 file system variants, 150 RAID setups, 48 md arrays, 12 deletions by the real Linux kernel, and real cases from the lab.

ZFS, VMFS and bcachefs are now read in full down to the file contents, verified byte for byte against real volumes. What remains open: a few hardware-RAID edge cases (DDF per-member matching), deleted-file recovery for XFS/Btrfs/APFS awaiting real samples, ZFS zstd, and the closed Oracle Solaris ZFS encryption (recognised and reported, not decrypted). For those cases there is remote assistance: almost four decades of lab experience that the tool need not replace itself.

Two things that apply to every tool: on an SSD or a virtual disk with TRIM, deleted files are often truly gone, and with ext3/4 the window closes once the journal wraps around. The sooner a device is stopped, the more can be recovered.

Request remote assistance →

When a lab is the better choice

Software helps with logical problems. With a physical fault it does more harm than good. Have the drive checked in these cases:

  • the drive makes unusual noises (ticking, clicking, scraping);
  • the drive is not recognised, or only now and then;
  • the drive was dropped, got wet or has been opened;
  • Recover refuses the drive after the SMART check;
  • a RAID or NAS with several drives failed at once.

Request a free analysis →

Download Recover

Recover is free, for Windows, macOS and Linux. Choose the version for your system.

Windows For Windows · version 0.4.0

Right-click the file and choose "Run as administrator".

Linux For Linux · version 0.4.0

Make the file executable first (chmod +x), then start it with sudo -E.

Do not install Recover on the drive you want to recover data from, and always write recovered files to a different drive.

How to start Recover with full access ↓

Starting Recover with full access

To read physical drives, Recover needs elevated rights: administrator on Windows, root on macOS and Linux. Without them you see no drives, only image files.

Windows

Right-click Recover-gui.exe and choose "Run as administrator". The UAC prompt appears anyway, because Recover requests elevated rights itself. Without them you see no physical drives.

Command line: first open an administrator prompt (right-click Windows Terminal or cmd, "Run as administrator"), then:

recover-cli.exe devices
recover-cli.exe info \\.\PhysicalDrive1
recover-cli.exe ls \\.\PhysicalDrive1 --deleted

Drive names: \\.\PhysicalDrive0, \\.\PhysicalDrive1, … for whole drives, \\.\E: for a single volume.

macOS

Once, beforehand: give Terminal Full Disk Access (System Settings → Privacy & Security → Full Disk Access) and restart Terminal. Then start Recover from Terminal:

sudo /Applications/Recover.app/Contents/MacOS/Recover

Before scanning: find the drive and unmount it.

diskutil list
diskutil unmountDisk /dev/disk2
sudo ./recover info /dev/rdisk2        # command line

Do not double-click and do not use "sudo open -a": the app would then run as your user and the drive list stays empty. Keep Terminal open while the app runs.

Choose /dev/rdisk2, with the r: that is the raw device, which reads much faster.

Linux

chmod +x Recover-gui-linux recover-cli-linux-static    # once after download
sudo -E ./Recover-gui-linux                            # -E keeps your DISPLAY
sudo ./recover-cli-linux-static info /dev/sdb

Without -E the graphical version may not start, because root does not know your graphical session. Alternative without sudo: add your user to the disk group (sudo usermod -aG disk $USER), then log in again.

Drive names: /dev/sda, /dev/nvme0n1 for whole drives, /dev/sda1 for a single partition.

The same on all three

Images need no elevated rights. If you work on an .img file, simply double-clicking or starting without sudo is enough.

The recommended way remains: first make an image (Disk image tab, or from the command line), then work on that file. Every scan then reads the healthy copy instead of stressing the drive again.

recover image /dev/sdb copy.img

Always recover to a different drive than the original.

Technical: a shortcut, and where the settings live

When Recover runs as root, the settings (including usage reporting) end up in root's home folder: /var/root/.config/recover/ on macOS, /root/.config/recover/ on Linux, and %APPDATA% of the elevated account on Windows. What you set in the menu therefore applies to the sessions you actually work in, but not to a start without elevated rights.

Handy to set up on macOS and Linux:

echo 'alias recover-gui="sudo /Applications/Recover.app/Contents/MacOS/Recover"' >> ~/.zshrc   # macOS
echo 'alias recover-gui="sudo -E /path/to/Recover-gui-linux"' >> ~/.bashrc                   # Linux

Why it works here

More about our lab →
  • Nearly 20,000 donor drives The right part is usually ready.
  • X-ray in-house First see, then act.
  • Rework and reballing Chips removed and refitted safely.
  • Our own software Up to hundreds of terabytes.
  • Mobile cleanroom The device stays in your building.
  • Since 1988 Nearly forty years of equipment and experience.

Download Recover for free

For Windows, macOS and Linux. If your drive is physically failing, or the risk is too high, request a free analysis.

Interesting? Liked it? Share this post with your network!