Local-first privacy boundary

RecallBase keeps AI conversation capture and export workflows on the user's device by default. Website account, billing, and plan checks do not need raw conversation text.

What the website receives

The website handles account, subscription, Billing Portal, extension token metadata, and plan status. It does not need prompt text, answer text, local file paths, export filenames, raw DOM, cookies, tokens, or sensitive screenshots.

What stays local

Browser captures and exported files stay in the browser or on the user’s device unless the user explicitly sends an export to another destination.

Local workflow boundary

RecallBase should not be described as a cloud upload path for raw conversations. Any local bridge or desktop workflow must follow the same privacy boundary: account and billing systems do not receive conversation content.

  1. 1

    Save or export only from a supported conversation page.

  2. 2

    Keep exported files in a folder you control.

  3. 3

    Send content to Notion, Obsidian, clipboard, or another app only when you choose that destination.

  4. 4

    Do not include raw chats, tokens, cookies, or local files in support requests.

Practical support boundary

If something fails, support should be able to help from the symptom, browser, extension version, export type, and account state. Do not send raw AI conversations, prompt text, answer text, cookies, access tokens, local database files, raw DOM dumps, or screenshots that reveal sensitive work. When a screenshot is genuinely necessary, crop it to the RecallBase control or error message before sharing.

Where exports go

Exports go to the destination selected by the user: a browser download, clipboard, browser PDF dialog, Notion, Obsidian, or another local workflow. RecallBase should describe those destinations plainly and avoid implying that exported chats are backed up by a RecallBase cloud account.