Version 1.0.0 · Last updated September 22, 2026
Privacy Policy
The short version: TotalRecalls never sees your chats. It runs entirely on your Windows PC, talks directly to the AI providers you already use, and sends us nothing. This page explains exactly what the app does — and doesn't — do with your data.
1. What we never collect
TotalRecalls does not collect, store, host, or transmit any of the following:
- Your AI conversations or downloaded chat content
- Your login credentials or passwords
- Your session tokens or provider cookies (they are stored only on your PC, encrypted)
- Your downloaded Markdown and JSON files
- Telemetry, usage analytics, crash reports, or tracking pixels of any kind
We have no server, no account system, and no database that holds your data. There is no version of TotalRecalls that phones home with your content.
2. How downloads work (and why your data stays yours)
When you download from a provider, the app signs in using a small embedded browser window on your machine — the same way you would in a normal browser. It then reads the conversations visible in your account, using your session, directly from the provider's servers.
- All traffic goes between your PC and the provider (ChatGPT, Claude, Perplexity, Gemini, Grok, DeepSeek, Mistral, or Qwen). TotalRecalls is never a relay.
- We cannot intercept what you download — the data never touches our infrastructure.
- The downloaded files are written straight to a folder you choose. They are yours, in open formats you can grep, version, or move anywhere.
3. What the app stores locally (on your PC only)
The app keeps a small amount of local state in a per-user folder on your machine —
on Windows, C:/Users/ (a historical folder name we kept
so existing sessions keep working). Nothing in that folder ever leaves your PC:
- Session files — the provider session data the app uses to download, encrypted with Windows DPAPI. DPAPI ties the encryption to your Windows user account: the files are unreadable on any other machine or by any other user of your PC.
- License file — your Pro entitlement and its local record, also DPAPI-encrypted.
- Diagnostic log — technical entries such as connection status, HTTP status codes, error messages, and timing, used to troubleshoot failed downloads. It does not contain your downloaded conversations; the one exception is that a failed request may log a short excerpt (up to 200 characters) of the error response the provider's server returned. You can open or delete the log at any time; deleting it has no effect on the app.
To delete everything: close the app and delete the folder above. Your downloaded chat archives are separate — they live in the folders you chose, and deleting them is up to you.
4. The only external service the app talks to: license verification
TotalRecalls is a one-time purchase sold through Paddle, our merchant of record, and verified by our own license server. The license check below is the only outbound connection the app makes that has anything to do with us:
- When you enter your license key, and periodically afterwards (at most once per hour, best-effort), the app sends your license key and a pseudonymous machine identifier (an opaque hash like
TR-…) to our license server at totalrecalls.app. - The identifier is derived from hardware plus a per-install random salt. It is not your name, email, IP, or hardware serial — our server can only use it to enforce the 3-activation limit.
- If your PC is offline, the app does not check and your Pro entitlement is not revoked. Verification is best-effort and never blocks downloads.
- No conversation content, no file names, no account details, and no usage data are ever part of these requests.
5. Third-party services
- Paddle — our merchant of record. Paddle processes your payment and issues your receipt and invoice; your card and billing details go to Paddle, never to us. See Paddle's own privacy policy for their data practices.
- Microsoft Edge WebView2 — the browser engine that powers the embedded sign-in windows. When you sign in to a provider, that provider's own privacy policy governs the sign-in. See Microsoft's WebView2 documentation for the engine's data practices.
- The AI providers — when you download from ChatGPT, Claude, or any other provider, that provider's servers receive requests authenticated with your session. Your use of your provider account remains governed by that provider's terms and privacy policy.
- Cloudflare — hosts this website. Like any website, it keeps standard server logs (IP address, requested page, timestamp). It does not receive any data from the app.
6. This website
- No cookies are set by totalrecalls.app.
- No analytics, tracking pixels, or advertising scripts run on it.
- Downloads are served directly from the site; the ZIP contains only the app and its README.
7. Data retention
Because we hold no data, we retain none. Retention is entirely under your control:
- Local state (sessions, license, log) — kept until you delete the folder, which you can do at any time.
- Your downloaded archives — kept for as long as you want; we have no copy.
- Payment and license records — held by Paddle as the merchant of record, per their policy and as required for tax and chargeback purposes. To request access to or deletion of your purchase data, contact Paddle (or email us and we will relay the request). To free one of your 3 activation slots (for example, after replacing a PC), email us and we will release it for you.
8. Your rights
Depending on where you live (including under Quebec Law 25, Canada's PIPEDA, and the GDPR if you are in the EU), you have rights to access, correct, or delete personal information held about you. Since TotalRecalls holds no personal information about you, most of these rights are already satisfied by design. For the small amount of purchase data held by Paddle, email us and we will help you exercise your rights with them. You can also remove your local entitlement record at any time by deleting the app's state folder (Section 3).
9. Children
TotalRecalls is not intended for children under 13, and we do not knowingly collect anyone's data through it.
10. Changes to this policy
If we change how the app handles data, we will update this page and the version date above, and note the change in the Release Notes. The architecture is deliberately minimal, so we do not expect frequent changes — and any change that would increase data collection would be called out prominently.
11. Contact
Questions about privacy or data requests: [email protected]. For legal matters, see our Terms of Service.
