← Back to Recall

Privacy Policy

Last updated: May 31, 2026

1. Who we are

Recall is operated by Prashanth Nimmagadda("we", "us", "our"), an individual (sole trader) based in England & Wales. We are the data controller for the personal data described in this policy and are registered with the UK Information Commissioner's Office (ICO) under reference [ICO REGISTRATION NUMBER]. This policy explains what personal data we collect, why we collect it, and the rights you have under the UK GDPR and the Data Protection Act 2018. Where you are in the EEA, the EU GDPR applies; where you are in California, the CCPA/CPRA applies.

2. How your recordings are processed (on-device first)

Recall is designed to keep your meetings private. On the free plan, recording, transcription, and decision extraction are intended to run on your own device.

  • On supported hardware — Apple Intelligence on recent iPhones, Gemini Nano on recent Android devices, and WebGPU in supported browsers — your audio is transcribed and turned into decisions locally. Your audio is not uploaded to us.
  • Where on-device processing is unavailable on your device, your audio and transcript text are sent to our AI processing partners (listed in section 7) for the sole purpose of generating your transcript and decisions, and are deleted by those partners after processing.

We never use your recordings, transcripts, or decisions to train AI models.

3. Data we collect

Account data

Your name, email address, a securely hashed password (never stored in plaintext), and your sign-in provider (email, Google, Apple, or a passkey).

Your content

The decisions, notes, and to-dos you create sync to your account so you can search them across your devices. Audio is processed as described in section 2.

Usage data

With your consent, we collect anonymized product-analytics events (for example, which features are used) via PostHog to improve Recall. No audio, transcript, or decision content is ever shared with analytics providers.

Diagnostics

If the app encounters an error, we collect technical diagnostic data (such as a stack trace and device type) via Sentry to fix faults. We configure this to exclude the content of your meetings.

Payment data

This version of Recall is free. We do not collect or process any payment or card data. If we introduce paid plans in future, payments will be handled by a PCI-DSS-compliant processor and we will update this policy before any charge is made.

4. Legal bases for processing

  • Performance of a contract — processing your account and content to provide the service you signed up for.
  • Consent — optional product analytics. You can withdraw consent at any time via the cookie banner.
  • Legitimate interests — keeping the service secure, diagnosing faults, and preventing abuse, balanced against your rights.
  • Legal obligation — where we are required by law to retain certain records.

5. Data retention

We keep your account data for as long as your account exists. Decisions, notes, and to-dos you delete are removed immediately and permanently purged within 30 days. If you delete your account, all associated personal data is permanently deleted within 30 days, except where we are required by law to retain limited records for longer.

6. Your rights

Under the UK GDPR and the Data Protection Act 2018 you have the right to:

  • Access — request a copy of your data; you can export it yourself at any time.
  • Rectification — correct inaccurate data (edit your profile in Settings).
  • Erasure — delete your account and all associated data from Settings.
  • Portability — export your decisions in JSON, CSV, or Markdown.
  • Object or restrict — object to or restrict certain processing.
  • Withdraw consent — turn off analytics at any time via the cookie banner.

To exercise any right, email privacy@recall.stillform.app. We will respond within one month. You also have the right to lodge a complaint with the ICO (the UK supervisory authority) at ico.org.uk— though we'd appreciate the chance to help first.

7. Processors and third-party services

ServicePurposeData shared
VercelApplication hostingAccount data, request metadata
SupabaseDatabase & file storageAccount data, your content
Groq / OpenAI / Anthropic / GoogleAI transcription & decision extraction (only when on-device processing is unavailable)Audio, transcript text
PostHogProduct analytics (with consent only)Anonymized usage events
SentryError diagnosticsTechnical diagnostics (no meeting content)

8. International transfers

Some of our providers process data outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organizational safeguards.

9. Cookies

We use essential cookies required to sign you in, and one optional analytics cookie (PostHog) that is only set with your explicit consent. You can change your choice at any time via the cookie banner.

10. Children

Recall is not directed at children under 16. If we learn that a child under 16 has created an account, we will delete it. Contact us at privacy@recall.stillform.app if you have a concern.

11. Changes to this policy

We will tell you about material changes by email or in the app before they take effect. The date at the top of this page reflects the most recent update.

12. Contact

Data controller: Prashanth Nimmagadda
[CONTACT / SERVICE ADDRESS], United Kingdom
ICO registration: [ICO REGISTRATION NUMBER]
Email: privacy@recall.stillform.app