Local-first, encrypted at rest
Capture and grouping run on your machine. The local store is encrypted with your OS keychain. What leaves the device is opt-in, scoped, and visible to you.
Use the prompt below to have ChatGPT, Claude, or Perplexity review Recall’s published privacy claims.
This reviews our published privacy architecture, not proprietary implementation code.
Priya is evaluating Recall before installing it on her work laptop. The product looks useful, but one question comes first: what does it see, what stays local, and what can she delete?
If a tool watches my screen, I want a straight answer before I let it in.
Tell me what Recall sees. Then let a second opinion stress-test the claim.
That is why we make the privacy model readable. You can ask any AI assistant to review the claims, find gaps, and tell you what still needs proof.
Capture and grouping run on your machine. The local store is encrypted with your OS keychain. What leaves the device is opt-in, scoped, and visible to you.
Recall reads what you can see on screen across tabs and apps. It never opens the microphone, the camera, or the system audio. No voice, no calls, no video.
No third party receives your work content. Zero analytics SDKs, zero tracking pixels, zero ad networks. We do not sell, share, or syndicate your context.
Your sessions are not used to train any model, ours or anyone else's. The patterns Recall learns about your day stay scoped to you.
One toggle pauses capture. One action wipes a session, a day, or everything. Forgetting is not buried in settings.
Recall is for the person doing the work. There is no team-wide view of who opened what or for how long. Surveillance is not a feature.
If your team or your legal review needs the boring details, here they are. No asterisks, no enterprise-only carve-outs. The defaults are the policy.
You have the right to access, export, or delete every byte Recall holds about you, on demand and without friction. Data minimization is the default, not a setting.
California residents can request a full export or full deletion at any time. We do not sell personal information, full stop, in any state.
The local Recall store is encrypted with a key bound to your OS keychain. If your laptop is locked, your context is locked with it.
No third party receives your work content. Providers used for basics like app distribution, payments, email, hosting, or licensing do not receive the context of your work. AI features run against your own provider key, or against a local model.
Six layers, each with a one-line scope. If you are reviewing Recall for your team, paste this into your AI of choice and ask it the hard questions. The answers should not require us in the room.
Capture, grouping, and the patterns Recall learns about your day all run on your device. The boundary below is the one we will not cross without you.
There is no work content to clone, leak, or delete from our side. Pause, scope by app, or wipe local history at any time, in one tap.
Metadata can still be sensitive. That is why Recall keeps the useful signal narrow, local by default, and visible to you.
App names, window or document titles, URL domains and stems, time-on-task, switching patterns, and context labels you confirm or correct.
No microphone audio, camera, system audio, keystrokes, clipboard contents, passwords, payment fields, 2FA fields, private or incognito windows, or raw screen recordings.
Sync is off by default. If enabled, it is limited to account and license state and selected session metadata, not raw screen content.
Pause capture, exclude apps, windows, or domains, edit context cards, or delete a session, a day, or everything from one place.
Work contentThe actual contents of your work: message bodies, email bodies, documents, calls, voice, video, passwords, payment details, private windows, or raw screen content.
Session metadataThe minimal structure Recall uses to help you return: app and window context, rough timing, switching patterns, and labels you approve.
On your machine, in an AES-256 encrypted store keyed to your OS keychain. Nothing leaves the device unless you explicitly enable sync, and even then only the high-level session metadata you choose, never raw screen content.
Never. Recall only reads what is already visible on your screen across tabs and apps. The microphone, the camera, and system audio are never touched. Voice and video are out of scope by design.
No raw screen recordings are stored. Recall is designed to keep the work signal narrow: app and window context, timing, switching patterns, and labels you confirm. Any temporary processing is discarded and is not kept as history.
Recall avoids known sensitive surfaces and lets you exclude apps, windows, and domains. Metadata can still be sensitive, so the default is local storage, pause is one tap, and exclusions apply before any new history is kept.
We do not use analytics SDKs or tracking pixels. If diagnostics are added later, they will be opt-in or scoped, and they will not include work content.
Yes to both. EU and UK users can request access, export, or full deletion at any time. California residents have the same rights under CCPA. We collect the minimum needed to make Recall work, and we do not sell personal information in any jurisdiction.
No third party receives your work content. Providers used for basics like app distribution, payments, email, hosting, or licensing do not receive the context of your work. AI features that require a model run against your own provider key or against a local model.
No. There is no team-wide dashboard, no manager view, no leaderboard. Recall is built for the person doing the work, not for someone watching them.
Recall ignores known sensitive surfaces by default, auto-redacts password, payment, and 2FA fields, and skips private and incognito windows entirely. You can also exclude any app, window, or domain permanently, or tap pause and capture stops immediately.
Yes. Remove a single session, an entire day, or every recorded byte from one screen. Forgetting is not buried in settings.
No. We do not use your work to train anything, ours or anyone else's. The patterns Recall learns about your day stay scoped to your device.