Legal

Privacy Policy

Last updated June 12, 2026

This policy explains what data Recl (“Recl”, “we”, “us”) collects, why we collect it, where it is stored, who processes it, how long we keep it, and the rights you have over it. It applies to the Recl web app (app.recl.app), the public library (library.recl.app), the marketing site (recl.app), the Recl mobile app for Android, the Recl Chrome extension, and the Recl Telegram and Discord bots.
Summary: Recl collects only what it needs to run your private memory library. We do not sell personal data. We do not use your saved content for advertising. You can export your content, delete items, or delete your entire account — including all saved content — at any time from Settings.

1. Who is responsible for your data

The data controller for all personal data processed by Recl is the Recl operator, reachable at hello@recl.app. We respond to all privacy requests within 30 days.

2. Data we collect

CategoryExamplesSourceWhy
Account dataEmail address, display name, avatar URL, Google/Apple account IDGoogle or Apple sign-in (OAuth)Create and authenticate your account
Saved contentYouTube URLs, page URLs, notes, quotes, transcripts, AI summaries, quiz answers, recall reviews, folders, topicsYou (saving content)Provide the core product: your personal knowledge library
Messaging identifiersTelegram chat ID, Discord user IDYou (connecting a channel)Deliver recall nudges to the channel you chose
Device & session dataSession tokens, extension tokens, mobile push tokens, IP-derived coarse region, user-agentYour devicesAuthentication, security, abuse prevention
Usage & diagnosticsFeature usage counters, error logs, performance metrics, feed interaction signals (likes, reads, dwell time)AutomaticReliability, quota enforcement, and ranking your own feed
Billing dataSubscription state, plan, billing interval, payment provider customer IDPayment providersOperate paid plans. Card numbers never touch Recl servers.

We do not collect: precise location, contacts, photos (other than images you explicitly save), microphone or camera data, advertising identifiers, or data from third-party data brokers.

3. Why we process your data (legal bases)

PurposeLegal basis (GDPR)
Providing the service you signed up for — saving, summarizing, searching, graphing, and recalling your contentContract (Art. 6(1)(b))
Generating AI summaries and quizzes from content you saveContract (Art. 6(1)(b))
Sending recall nudges to a messaging channel or push notifications you explicitly connectedContract / Consent (Art. 6(1)(a)–(b)) — disconnect any time
Security, fraud and abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Billing, invoicing, accounting recordsLegal obligation (Art. 6(1)(c))
Service diagnostics and reliability monitoringLegitimate interest (Art. 6(1)(f))

4. How AI processing works

  • When you save content, the transcript or text is sent to our AI provider (OpenRouter) to generate summaries, topics, quiz questions, and category labels.
  • AI requests are scoped to the single piece of content being processed. Your library as a whole is never used to train AI models — neither by us nor, per their terms, by our AI provider.
  • Semantic search uses vector embeddings of your saved content, stored in our own database, scoped to your account.
  • AI outputs can be wrong. They are labeled as generated content and are never represented as professional advice.

5. Where your data lives

  • Primary database and application servers: a dedicated server hosted with DigitalOcean (Bangalore region).
  • Encrypted backups and uploaded images: Cloudflare R2 object storage.
  • All traffic is encrypted in transit (TLS 1.2+). Backups of secrets are GPG-encrypted at rest.
  • Access to production systems is limited to the operator, via key-based SSH.

6. Who we share data with

We share data only with the subprocessors needed to run the service — never for advertising, and never by selling it. The current list, with purposes and regions, is maintained on the Subprocessors page. We may also disclose data if required by law, or to protect the rights, safety, and security of Recl and its users.

7. How long we keep data

Retention periods per data category are documented on the Data retention page. In short: your content stays as long as your account exists; deleting your account deletes your content; operational logs rotate within weeks; billing records are kept as long as tax law requires.

8. Your rights

Depending on where you live (GDPR in the EU/EEA/UK, CCPA/CPRA in California, and similar laws elsewhere), you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data (most profile data is editable in Settings).
  • Erasure — delete your account and all associated content (self-serve in Settings → Danger zone, or by email).
  • Portability — receive your saved content in a machine-readable format.
  • Restriction & objection — limit or object to specific processing.
  • Withdraw consent — disconnect messaging channels or disable push notifications at any time.
  • Complain — lodge a complaint with your local data-protection authority.

To exercise any right that isn't self-serve, email hello@recl.app. We verify requests against your signed-in account email and respond within 30 days. See GDPR & EU users for the full process.

9. Children

Recl is not directed at children under 16 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

10. Cookies

Recl uses only strictly-necessary first-party cookies (session, CSRF protection). There are no advertising or cross-site tracking cookies. Details on the Cookie policy page.

11. Changes to this policy

We will update this page when our practices change and revise the “Last updated” date above. For material changes affecting your rights we will notify you in-app or by email before they take effect.

12. Contact

Privacy questions and requests: hello@recl.app.