Recallbase / Privacy & Compliance

Privacy & Compliance

Most AI memory services are US cloud SaaS. Recallbase is not: self-hosted-first, runnable in the EU, tenant isolation as a database law. For everyone who cannot put their knowledge into someone else's cloud.

Brand-colored knowledge graph – a symbol for secure, isolated data

Your data stays where you want it

Recallbase is self-hosted-first: run it on your own server or as an EU instance. No obligation to put project knowledge into a US cloud – the decisive difference for law firms, newsrooms, healthcare and financial companies.

Tenant isolation as a database law

Separation between organizations is not a matter of coding discipline – it's enforced by PostgreSQL Row Level Security (RLS) in the database, fail-closed: without a set identity, every query returns zero rows. A coding mistake never becomes a data leak.

Data processing agreement (DPA)

For enterprise use we provide a data processing agreement (DPA) under Art. 28 GDPR. It covers the subject and duration of processing, data categories, technical and organizational measures, sub-processors and deletion. Request a DPA →

Sub-processors & data transfer

Recallbase uses few, clearly named processors – including Stripe (payments, EU) and OpenAI (embeddings for semantic search; EU contracting entity, US transfer safeguarded by EU Standard Contractual Clauses). Details in the privacy policy. For setups with special requirements (own infrastructure, different processors), talk to us.

Your rights: export, deletion, no lock-in

Honest: certification status

Recallbase is GDPR-oriented, self-hosted and EU-runnable. Formal certifications like SOC 2 or ISO 27001 we do not (yet) have – we'd rather say so openly than market with it. If your compliance process needs a specific document or assurance, ask us – we'll find a way.

Request an EU instance or DPA

Self-hosted or as an EU instance, with a DPA under Art. 28 GDPR. Start for free or ask for compliance details.

Start for free