Privacy Policy — chat-recall
Last updated: 2026-08-20
chat-recall ("we", "the service") is a search and intelligence service for AI-coding session history, operated by MUNMUN SOLUTIONS S.R.L. ("MunHQ"), reachable at [email protected]. This policy describes what we store, why, and your rights.
What we collect
Content you sync. The chat-recall CLI reads the session transcripts your AI coding tools (Claude Code, Gemini CLI, OpenCode, Codex) already store on your machine and uploads them to your workspace. This includes prompts, assistant responses, file paths (hashed by default; cleartext only if you opt in), edit metadata, and derived data (summaries, search indexes, extracted facts).
Secrets are redacted before upload. The CLI runs a redaction pass on your machine — API keys, passwords, tokens and other credential-shaped values are replaced with [REDACTED:…] sentinels before anything leaves your device. Redaction is pattern-based and cannot be perfect; treat the service as a place where near-miss secrets may land, and rotate anything our Security dashboard flags. We store masked previews (last 4 characters) of detected secrets so you can identify and rotate them — never the full value.
Account data. Email and identity from our sign-in provider (Keycloak), team membership, device names you assign to sync tokens.
Billing data. Handled by Stripe. We store your subscription status and plan; we never see or store card numbers.
Operational data. Request logs (IP, route, status, latency) retained for 30 days for abuse prevention and debugging; aggregate usage metrics.
How we use it
To provide the product: indexing, search, summaries (generated by AI models running on our infrastructure), analytics, secret-leak detection and alerting for your own workspace. We do not sell your data, use it to train models, or share it with third parties beyond the processors below.
Processors
- Stripe — payments.
- OVHcloud — hosting (EU region: Gravelines, France) and encrypted backups.
- AI inference for summaries/embeddings runs on infrastructure we operate; your
content is not sent to third-party AI APIs unless the operator has explicitly configured one. No such third-party AI API is configured today.
Tenant isolation
Every row of your data is scoped to your workspace and enforced with database-level row security. Team members you invite see the team workspace; nobody else does.
Retention & deletion
- Your data persists while your workspace exists.
chat-recall delete <session>purges a session everywhere and tombstones it
so no device can re-sync it.
- Deleting your workspace (or emailing [email protected]) removes all content
within 30 days, including from backups as they rotate (90-day backup cycle).
- Revoking a device token stops that machine's sync immediately.
Your rights
Access, export, correction, deletion — email [email protected]. If you are in the EU/EEA, you additionally have GDPR rights (portability, restriction, complaint to a supervisory authority). Data is hosted in the EU.
Changes
We'll notify account emails of material changes 14 days before they take effect.