Recall

Privacy

Recall — Build to Great

Privacy at Recall

Recall is designed around one small, learner-confirmed source section. Source preparation happens locally, generation requests are minimised, and saved study data stays in the browser profile where it was created.

The short version

  • Your original PDF and raw pasted-text draft are prepared in this browser.
  • Only the section you review and confirm, plus controlled study settings, can be sent for activity generation.
  • Saved activities, attempts, and review schedules use local browser storage. There is no account, cloud backup, or cross-device sync in the MVP.
  • Recall is initially intended for adults aged 18 and over.

Before generation

PDF and pasted text are prepared locally

Text-based PDFs

The browser opens the PDF, extracts selectable text from the pages you choose, normalises it, and builds selectable source segments. The PDF binary and filename are not sent to Recall's server.

Pasted plain text

The browser normalises and segments one bounded plain-text draft. It does not fetch URLs or interpret pasted HTML. The raw draft remains only in active browser memory while you prepare the section.

The original PDF, raw pasted-text draft, full extracted document, unselected pages, and unselected source segments are neither uploaded nor persisted by Recall.

One bounded request

What is sent for generation

Nothing is sent until you confirm a contiguous source range and explicitly create an activity. That request contains only:

  • versioned request metadata and a random, content-free request ID;
  • the controlled source kind and confirmed text segments, with page numbers for PDF segments or segment order for pasted text;
  • the selected difficulty, an optional short difficulty note, recall precision, and assessment format; and
  • one approved method ID only when you explicitly request a method override.

Never included

The request does not include the PDF binary, filename, raw pasted draft, unselected source text, local study library, prior attempts, learner responses, review history, or review schedule.

AI processing

How the generation provider processes the section

Recall's server validates the request, then sends the confirmed section and controlled generation instructions to its configured OpenAI Responses API provider. The provider returns one structured activity; Recall validates its method, shape, source anchors, and evidence before showing or saving it.

Provider requests use stateless mode with store: false. Recall does not create provider files, conversations, background responses, or reusable prompt state containing your source text.

This configuration is not a promise of zero provider retention or special legal treatment. The provider and hosting platform may process operational data under their applicable terms and policies.

Public endpoint protection

Pseudonymous rate limiting and duplicate protection

The hosting platform necessarily exposes network metadata to Recall's server. For abuse and cost protection, the server converts available network metadata into a keyed digest using a rotating server secret. This creates a pseudonymous network bucket; it is not described as anonymous data.

The rate-limit store receives the digest, controlled counters, and expiry times—not source or learner text. Counter records expire no later than 25 hours after the last counted generation attempt.

A random request ID also holds a content-free in-flight lock to prevent duplicate provider calls. That lock expires after at most two minutes. Network-bucket keys are not sent to analytics.

Saved on this device

IndexedDB, saved study data, and deletion

After a generated activity passes validation, Recall saves the confirmed source section, controlled learner settings, generated activity, activity preferences, attempts, and review-unit schedules in this browser profile's IndexedDB. It does not save the original PDF, filename, raw pasted draft, or unselected source text.

Saved data is specific to this device and browser profile. The MVP has no account, cloud backup, or cross-device sync. Clearing browser site storage may remove saved study sets and review material.

The Library can delete one study set together with its attempts and review units. The Privacy & data menu in Recall can clear every Recall-owned IndexedDB store without clearing unrelated origin data.

Content-free measurement

Optional analytics and operational logs

Recall can be deployed with optional, coarse product analytics. The app continues to work when analytics is disabled or unavailable.

If enabled, analytics categories are limited to controlled source-input and preparation outcomes, generation outcomes and error categories, approved method and engine IDs, practice and review progress, coarse count buckets, deletion events, and small controlled usefulness answers.

Analytics does not receive source text, excerpts, filenames, free-text difficulty notes, generated answers, learner responses, study titles, request bodies, or content hashes. Operational server logs may contain request IDs, timestamps, duration, response status, configured model identifier, coarse token or cost aggregates where available, and typed error categories—but not educational content.

Age boundary

Recall's initial public version is intended for people aged 18 and over. Expanding access to minors requires a separate privacy, safety, consent, support, and legal review.