Recallbase / Privacy & Compliance
Privacy & Compliance
Most AI memory services are US cloud SaaS. Recallbase is not: self-hosted-first, runnable in the EU, tenant isolation as a database law. For everyone who cannot put their knowledge into someone else's cloud.
Your data stays where you want it
Recallbase is self-hosted-first: run it on your own server or as an EU instance. No obligation to put project knowledge into a US cloud – the decisive difference for law firms, newsrooms, healthcare and financial companies.
Tenant isolation as a database law
Separation between organizations is not a matter of coding discipline – it's enforced by PostgreSQL Row Level Security (RLS) in the database, fail-closed: without a set identity, every query returns zero rows. A coding mistake never becomes a data leak.
- RLS with FORCE on every tenant-scoped table
- API keys stored only as SHA-256 hashes, passwords with bcrypt
- Transport via TLS, webhook signatures HMAC-verified
- Rate limits against brute-force on login and signup
Data processing agreement (DPA)
For enterprise use we provide a data processing agreement (DPA) under Art. 28 GDPR. It covers the subject and duration of processing, data categories, technical and organizational measures, sub-processors and deletion. Request a DPA →
Sub-processors & data transfer
Recallbase uses few, clearly named processors – including Stripe (payments, EU) and OpenAI (embeddings for semantic search; EU contracting entity, US transfer safeguarded by EU Standard Contractual Clauses). Details in the privacy policy. For setups with special requirements (own infrastructure, different processors), talk to us.
Your rights: export, deletion, no lock-in
- Export: your sessions, summaries and knowledge graph are yours and available via the API.
- Deletion: account and data are deletable; self-hosted means fully in your hands anyway.
- No lock-in: open client, MCP standard, self-host option – you're not trapped.
Honest: certification status
Recallbase is GDPR-oriented, self-hosted and EU-runnable. Formal certifications like SOC 2 or ISO 27001 we do not (yet) have – we'd rather say so openly than market with it. If your compliance process needs a specific document or assurance, ask us – we'll find a way.
Request an EU instance or DPA
Self-hosted or as an EU instance, with a DPA under Art. 28 GDPR. Start for free or ask for compliance details.
Start for free