Bank-grade privacy and security for your engineering memory.
Your memories hold architecture, incidents, constraints and the reasoning behind your code. We treat them as the sensitive infrastructure they are. We do not train AI models on them. We do not sell your data. Period. Here is how Recallium Cloud is built, what leaves your machine, who can see what, and how you take it all back.
We do not train on your memories
Your memories, notes, files and the outputs generated from them are never used to train AI models. Not ours, not anyone’s.
We do not sell your data
Your data is not sold, not shared for advertising, and not combined with data from other sources. It exists to serve your team.
Isolated by default
Every tenant is separated by row-level security in the database. Sharing follows the repository, and a memory stays personal until you share it.
Yours to take back
GDPR compliant. Export everything as a ZIP, made available for you to take. Delete your account and your data is purged on a schedule you can cancel, with backups rotating out behind it.
Built like a vault to hold sensitive information
Institutional engineering memory should not live in database files scattered across laptops. Recallium Cloud is centralized infrastructure with authorization, isolation and governance built into the platform. These are the controls in production today.
- Encrypted in transit. TLS on every connection: browser, CLI, MCP client and local software to the API.
- Encrypted at rest. Database, storage and backups are encrypted at rest with Google-managed keys on Google Cloud.
- Private database. The database sits on a private network with no public IP address. Encrypted connections only; plaintext is refused.
- Row-level tenant isolation. Row-level security enforces who can read each row. Isolation is in the database, not only in application code.
- Sign-in and sessions. Sign-in through WorkOS. MCP clients use OAuth 2.1. Logout revokes the session server-side.
- Credentials that expire. Credentials for the local software expire after 90 days without use and can be revoked at any time from your account.
- 30 daily backups. The 30 most recent daily backups are kept. When you delete your account, they rotate out one per day.
- No trackers in the API. No third-party analytics or error-tracking service runs inside the API. Public access to storage is prevented at the bucket level.
- Infrastructure access logged. Administrative access to the cloud infrastructure is audit-logged. Hosted on Google Cloud, us-central1, United States.
What leaves your machine
Two things reach Recallium: the memories your agents save deliberately, and a record of which files changed, kept for audit. Not what is inside them. Nothing else.
Sent
What your agents save on purpose, plus which files changed, for audit.
- Memories and documents that your agents, or you, choose to store.
- Which files were touched. Edited or read, as repository-relative paths with counts. Paths, never contents.
- Branch and commit that the work happened on.
- Hashes of the project path and the hostname, so the same machine and repository can be recognized without naming either.
- Agent, model name and token counts for each session.
- When Recallium ran.
Never sent
Stays on your machine. The server has no column that could hold any of it.
- Source code. No file contents, no diffs, no snippets.
- Chats. Your prompts and the assistant’s responses stay on your machine.
- Memory contents. Your agent’s memory, rules and notes files on disk. Recallium sees that a file changed, never what is in it.
- Secrets. API keys, credentials, environment files and anything else in your working tree.
Search query text is kept for 30 days to improve retrieval, then deleted. Verify what is connected on your own machine with npx -y recallium status.
Who can see what
Authorization is decided on the server with role-based access control (RBAC): by organization, team, project and role, enforced by row-level security in the database. Sharing follows the repository, not the person, and roles can follow the groups in your enterprise identity provider.
Your organization roles mapped from your IdP groups through SSO
├── Admin manages members, roles and projects
└── Team: Platform members and roles, on Recallium Cloud
├── Member: Priya her agent reads and writes the team's projects
└── Projects one per repository the team connects, shared by every teammate's agent
Priya's personal space hers by default, no team involved
└── Personal projects repositories only Priya connects, hers until she shares themOne person, end to end: Priya is an engineer on the Platform team. Her agent reads and writes every project her team connected. Any repository only she connects lands in her personal space, visible only to her until she promotes it to the team. Her role comes from the group she belongs to in her company's identity provider, and an admin can change it without touching the data.
What touches your memory text
Encrypted end to end in transit, and at rest. This is the path a memory's text takes, and what sits at each stop.
To tag, summarize and embed a memory, the service reads its text and sends it to a model. Content goes to a provider only as needed to process that request, and we use providers that do not retain it after the request completes. Embeddings run on providers we pin, not on whichever host is cheapest that minute.
What the service will never do with that text is train a model or sell it.
How you leave, in full
Questions security teams ask
Do you train AI models on our data?
No. We do not train AI models on your memories, notes, files or the outputs generated from them, and we do not sell your data.
Who can see a team’s memory?
Sharing follows the repository, not the person. On Cloud Free nothing is shared. On Cloud Pro, the memory of a repository your team connects is read and written by every teammate’s agent, while a repository only you connect stays yours. A memory stays personal until you share it. Roles (RBAC) decide who reads and who administers, can be mapped from your enterprise identity provider’s groups through SSO, and row-level security in the database enforces the result on every read.
Does the local software send our source code?
No. Recallium only tracks which files changed, for audit, not what is inside them: repository-relative paths with counts, the branch and commit, hashes of the project path and hostname, and when Recallium ran. It never sends file contents, prompts, assistant responses or secrets, and the server has no column to store them. What agents save as memories is what they save deliberately.
Which AI providers see our content?
Memory text is sent to a model to tag, summarize and embed it. Content goes to a provider only as needed to process your request, and we use providers that do not retain it after the request completes.
How is data encrypted?
TLS in transit on every connection. At rest, the database, object storage and backups are encrypted with Google-managed keys. The database accepts encrypted connections only and has no public IP address.
How do export and deletion work?
Export: a ZIP of your memories, projects, thinking sequences and document text from your personal projects; memories saved into a team’s project belong to the team. Export is made available for you to take; ask at privacy@recallium.ai from your account address. Delete: sign-in and local access are revoked, your data is scheduled for permanent erasure with a cancel link in the email, and backups rotate out behind it. Recallium is GDPR compliant.
Who are your subprocessors?
Google Cloud (hosting, database, storage), OpenRouter with Nebius and DeepInfra for model inference and embeddings, WorkOS (sign-in), Resend (email), Vercel (web hosting) and Stripe (payments). Under the DPA, a new subprocessor is announced no less than 30 days ahead.
How are security incidents communicated?
Under the DPA, Recallium notifies the customer without undue delay after becoming aware of a data incident and cooperates in resolving it.
Can we deploy inside our own cloud, or bring our own model?
Recallium Cloud is the managed service today. If you need a dedicated environment, a private deployment or your own model provider, talk to us about what we can support for your organization.
Do you hold a SOC 2 report?
Not yet. The controls on this page are implemented; a SOC 2 audit is a separate program. We will say so here when a report exists, not before.
Privacy inquiries: privacy@recallium.ai. Support: support@recallium.ai or the Recallium Discord.
