Bank-grade privacy and security for your engineering memory.

Your memories hold architecture, incidents, constraints and the reasoning behind your code. We treat them as the sensitive infrastructure they are. We do not train AI models on them. We do not sell your data. Period. Here is how Recallium Cloud is built, what leaves your machine, who can see what, and how you take it all back.

We do not train on your memories

Your memories, notes, files and the outputs generated from them are never used to train AI models. Not ours, not anyone’s.

We do not sell your data

Your data is not sold, not shared for advertising, and not combined with data from other sources. It exists to serve your team.

Isolated by default

Every tenant is separated by row-level security in the database. Sharing follows the repository, and a memory stays personal until you share it.

GDPR

Yours to take back

GDPR compliant. Export everything as a ZIP, made available for you to take. Delete your account and your data is purged on a schedule you can cancel, with backups rotating out behind it.

Built like a vault to hold sensitive information

Institutional engineering memory should not live in database files scattered across laptops. Recallium Cloud is centralized infrastructure with authorization, isolation and governance built into the platform. These are the controls in production today.

  • Encrypted in transit. TLS on every connection: browser, CLI, MCP client and local software to the API.
  • Encrypted at rest. Database, storage and backups are encrypted at rest with Google-managed keys on Google Cloud.
  • Private database. The database sits on a private network with no public IP address. Encrypted connections only; plaintext is refused.
  • Row-level tenant isolation. Row-level security enforces who can read each row. Isolation is in the database, not only in application code.
  • Sign-in and sessions. Sign-in through WorkOS. MCP clients use OAuth 2.1. Logout revokes the session server-side.
  • Credentials that expire. Credentials for the local software expire after 90 days without use and can be revoked at any time from your account.
  • 30 daily backups. The 30 most recent daily backups are kept. When you delete your account, they rotate out one per day.
  • No trackers in the API. No third-party analytics or error-tracking service runs inside the API. Public access to storage is prevented at the bucket level.
  • Infrastructure access logged. Administrative access to the cloud infrastructure is audit-logged. Hosted on Google Cloud, us-central1, United States.

What leaves your machine

Two things reach Recallium: the memories your agents save deliberately, and a record of which files changed, kept for audit. Not what is inside them. Nothing else.

Sent

What your agents save on purpose, plus which files changed, for audit.

  • Memories and documents that your agents, or you, choose to store.
  • Which files were touched. Edited or read, as repository-relative paths with counts. Paths, never contents.
  • Branch and commit that the work happened on.
  • Hashes of the project path and the hostname, so the same machine and repository can be recognized without naming either.
  • Agent, model name and token counts for each session.
  • When Recallium ran.

Never sent

Stays on your machine. The server has no column that could hold any of it.

  • Source code. No file contents, no diffs, no snippets.
  • Chats. Your prompts and the assistant’s responses stay on your machine.
  • Memory contents. Your agent’s memory, rules and notes files on disk. Recallium sees that a file changed, never what is in it.
  • Secrets. API keys, credentials, environment files and anything else in your working tree.

Search query text is kept for 30 days to improve retrieval, then deleted. Verify what is connected on your own machine with npx -y recallium status.

Who can see what

Authorization is decided on the server with role-based access control (RBAC): by organization, team, project and role, enforced by row-level security in the database. Sharing follows the repository, not the person, and roles can follow the groups in your enterprise identity provider.

Your organization            roles mapped from your IdP groups through SSO
  ├── Admin                  manages members, roles and projects
  └── Team: Platform         members and roles, on Recallium Cloud
      ├── Member: Priya      her agent reads and writes the team's projects
      └── Projects           one per repository the team connects, shared by every teammate's agent

Priya's personal space       hers by default, no team involved
  └── Personal projects      repositories only Priya connects, hers until she shares them

One person, end to end: Priya is an engineer on the Platform team. Her agent reads and writes every project her team connected. Any repository only she connects lands in her personal space, visible only to her until she promotes it to the team. Her role comes from the group she belongs to in her company's identity provider, and an admin can change it without touching the data.

Personal until you share itA project only you connect lands in your personal space and is visible only to you. Promote it to the team when it is ready.
Shared by repositoryOn Cloud Pro, a repository the team connects is shared by the team. On Cloud Free nothing is shared.
RBAC, controlled by your enterprise IdPPart of Recallium Cloud. Roles decide who reads and who administers, and the server enforces both. Sign in through SSO and roles can be mapped from your identity provider’s groups, Entra ID, Okta or Active Directory among them, so access follows your directory.
Enforced in the databaseRow-level security filters every query by tenant, so a bug in application code cannot widen access.

What touches your memory text

Encrypted end to end in transit, and at rest. This is the path a memory's text takes, and what sits at each stop.

To tag, summarize and embed a memory, the service reads its text and sends it to a model. Content goes to a provider only as needed to process that request, and we use providers that do not retain it after the request completes. Embeddings run on providers we pin, not on whichever host is cheapest that minute.

What the service will never do with that text is train a model or sell it.

How you leave, in full

ExportA ZIP of your memories, projects, thinking sequences and document text from your personal projects, made available for you to take. Memories saved into a team's project belong to the team and stay with it. Ask at privacy@recallium.ai from your account address.
DeleteSign-in and local access are revoked. Your data is scheduled for permanent erasure, with a cancel link in the email, and backups rotate out behind it.
Limit what is trackedRecallium only tracks which files changed, for audit, never their contents. Narrow that further with the ignore settings, or uninstall the local software, which removes everything it stored on the machine.
Your rightsAccess, correction or deletion of personal information on request, verified against your account address, and no different treatment for asking.

Questions security teams ask

Do you train AI models on our data?

No. We do not train AI models on your memories, notes, files or the outputs generated from them, and we do not sell your data.

Who can see a team’s memory?

Sharing follows the repository, not the person. On Cloud Free nothing is shared. On Cloud Pro, the memory of a repository your team connects is read and written by every teammate’s agent, while a repository only you connect stays yours. A memory stays personal until you share it. Roles (RBAC) decide who reads and who administers, can be mapped from your enterprise identity provider’s groups through SSO, and row-level security in the database enforces the result on every read.

Does the local software send our source code?

No. Recallium only tracks which files changed, for audit, not what is inside them: repository-relative paths with counts, the branch and commit, hashes of the project path and hostname, and when Recallium ran. It never sends file contents, prompts, assistant responses or secrets, and the server has no column to store them. What agents save as memories is what they save deliberately.

Which AI providers see our content?

Memory text is sent to a model to tag, summarize and embed it. Content goes to a provider only as needed to process your request, and we use providers that do not retain it after the request completes.

How is data encrypted?

TLS in transit on every connection. At rest, the database, object storage and backups are encrypted with Google-managed keys. The database accepts encrypted connections only and has no public IP address.

How do export and deletion work?

Export: a ZIP of your memories, projects, thinking sequences and document text from your personal projects; memories saved into a team’s project belong to the team. Export is made available for you to take; ask at privacy@recallium.ai from your account address. Delete: sign-in and local access are revoked, your data is scheduled for permanent erasure with a cancel link in the email, and backups rotate out behind it. Recallium is GDPR compliant.

Who are your subprocessors?

Google Cloud (hosting, database, storage), OpenRouter with Nebius and DeepInfra for model inference and embeddings, WorkOS (sign-in), Resend (email), Vercel (web hosting) and Stripe (payments). Under the DPA, a new subprocessor is announced no less than 30 days ahead.

How are security incidents communicated?

Under the DPA, Recallium notifies the customer without undue delay after becoming aware of a data incident and cooperates in resolving it.

Can we deploy inside our own cloud, or bring our own model?

Recallium Cloud is the managed service today. If you need a dedicated environment, a private deployment or your own model provider, talk to us about what we can support for your organization.

Do you hold a SOC 2 report?

Not yet. The controls on this page are implemented; a SOC 2 audit is a separate program. We will say so here when a report exists, not before.

Talk to us about security →

Privacy inquiries: privacy@recallium.ai. Support: support@recallium.ai or the Recallium Discord.