Windows 11 Recall Privacy and Security Safeguards

Windows 11 Recall is an AI-powered feature that captures snapshots of your active screen to help you search and retrieve past activities, documents, and conversations. Following initial security concerns, Microsoft redesigned the architecture with robust safeguards to ensure user data remains secure, private, and under the user’s complete control. This article breaks down the essential privacy and security measures implemented to protect users when using Recall.

Opt-In Experience by Default

Recall is entirely optional. During the initial Windows setup on Copilot+ PCs, users are presented with a clear choice to enable or decline the feature. It remains turned off by default until a user explicitly decides to turn it on, and it can be completely disabled or uninstalled at any time through Windows settings.

Windows Hello Protection and Just-In-Time Decryption

To prevent unauthorized physical access to your data, Recall requires Windows Hello authentication (facial recognition, fingerprint, or PIN) to view the timeline or search snapshots. The database and snapshot storage are encrypted and isolated using virtualization-based security (VBS). Decryption keys are protected by the Trusted Platform Module (TPM) chip, meaning snapshot data is only decrypted “just-in-time” when the authenticated user actively searches or accesses Recall.

100% On-Device Processing and Storage

All data processing and storage for Recall occurs entirely on your local device using the Neural Processing Unit (NPU). Snapshots, OCR (optical character recognition) text, and search indexes are never uploaded to the cloud, sent to Microsoft, or used to train AI models.

Automatic Filtering of Sensitive Content

Recall includes built-in safeguards to filter out private data: * Private Browsing: Snapshots are automatically paused during private browsing sessions in supported web browsers such as Microsoft Edge, Google Chrome, and Mozilla Firefox. * DRM Protection: Digital Rights Management (DRM) content, such as streaming movies or copyrighted media, is automatically blocked from being captured. * Sensitive Information Filtering: The system works to detect and exclude highly sensitive personal data, including passwords, credit card numbers, and national identification numbers.

Granular User Controls

Users have granular management tools to customize what gets captured and retained: * Exclusions: You can add specific applications or specific websites to an exclusion list to prevent them from ever being recorded. * Pause and Resume: Recall can be paused at any moment directly from the system tray. * Deletion Options: Users can view their snapshot history, delete specific time ranges, remove all snapshots from a specific app, or wipe the entire Recall database instantly. * Storage Limits: Users can set maximum disk space allocation for Recall; once the limit is reached, older snapshots are automatically deleted to make room for new ones.