Zero retention. Total privacy.
We process your data in place, scrub credentials automatically, and forward the rest without keeping a single copy.
Note 1 — reporting a problem
Email security@chatrecall.dev. A real person reads it.
The boundary, part by part
Fig. 1 — redactor, section
Nothing has been sent yet
We detect all standard cloud keys, auth tokens, private keys, and connection strings. Using custom internal formats? Send them our way and we'll add custom rules to keep them covered.
Whitelist or blacklist files with precision
| Command | What it does |
|---|---|
| chat-recall exclude project ~/work/client | Nothing under that path syncs again — no sessions, no findings, no metadata. |
| chat-recall exclude tool cursor | That tool's transcripts stop leaving the machine. This is also how you handle tools that file under a hash instead of a project folder. |
| chat-recall sync-only add git:github.com/me/app | Flips it into an allowlist: only what you list ships anywhere. chat-recall projects prints the ids you need. |
| chat-recall sources decline ~/.claude-work | For a folder we found that you don't want synced. Add --delete-remote to pull back what it already sent. |
| chat-recall delete <session> | Wiped from every server, with a tombstone so it can't come back. Your own local transcript stays untouched. |
| chat-recall exclude list | Every rule currently in force. The dashboard's fleet-wide rules stack on top of these, never replace them. |
Your data never leaves your machine without your permission—manage it all via the CLI, with rule updates applying immediately on the next sync.