Privacy Policy
The short version
recall runs on your machine. No data ever leaves your server — not your code, not your queries, not what you build. The index is a local SQLite file; the dashboard is loopback-only. The only thing we ever check is your license / account. We genuinely do not know what you do with it.
What we collect
- Account data — your email address and, for password accounts, a salted password hash (never the password itself); for social sign-in, the provider's stable account id. Plus your plan and trial date. We use this solely to operate your account and issue your license; we delete it when you delete your account, except where law requires us to retain billing records.
- License / entitlement checks — when the tool verifies a license it checks a signed offline token; issuing or renewing that token sends your account session to our server and nothing else. We log security-relevant account events (sign-up, sign-in, license issue/revocation) in an audit trail.
- Never collected — your repository contents, recall queries, the index, or any source code.
Website analytics
- Vercel Web Analytics (Vercel Inc.) — cookieless, aggregated page-view and performance statistics. No cookies, no cross-site profiles, no persistent identifiers; data is processed for us under Vercel's data processing agreement. Legal basis: our legitimate interest in understanding site usage (Art. 6 (1) lit. f GDPR).
- Google Analytics 4 (Google Ireland Ltd. / Google LLC) — runs only with your consent via the cookie banner (Art. 6 (1) lit. a GDPR). It sets cookies and processes usage data with IP anonymization enabled; data may be transferred to Google LLC in the USA under the EU-US Data Privacy Framework. You can withdraw your consent at any time via “Cookie settings” in the footer. See Google's privacy policy.
Cookies
Strictly necessary cookies only, by default: the session cookie that keeps you signed in, the short-lived sign-in state cookie, and your cookie-banner choice itself. Google Analytics cookies are set only after you consent.
Payment data
Payments are processed by Stripe, Inc. We never see or store your card number; Stripe shares with us only what is needed to fulfil the purchase (plan, billing status, a customer reference). See Stripe's privacy policy and data processing agreement.
Your rights (GDPR / DSGVO)
You have the right to access, rectify, erase and receive (portability) your personal data, to restrict or object to its processing, and to withdraw any consent at any time. Deleting your account from the account page exercises erasure directly. For anything else, email us at the address below — we answer within the statutory period. You also have the right to lodge a complaint with a supervisory authority; for us that is the Bavarian Data Protection Authority (BayLDA), Ansbach, Germany.
Contact / Controller
Kathrin Mc Cain — McCain Digital, Holderweg 1, 86869 Oberostendorf, Germany. Email: info@mccain-digital.com. whatever-recall is a product and service of McCain Digital; all official email (support, info, payment) comes from @mccain-digital.com addresses.