Privacy Policy

Your captures, your decision

Effective August 16, 2026. This policy explains how the Recallens website, Chrome extension, local features, and optional Pro services handle data.

Scope and contact

This policy applies to the official Recallens website, extension, and Pro services. For privacy, access, deletion, or security requests, email support@yogocoju.com. Before paid service launches, the site must publish the legal operator name and address that match Paddle, the settlement account, and the Terms. Until then, the service has not completed every commercial-launch requirement.

Data that stays on your device

By default, Recallens stores captures, thumbnails, source URLs, page titles, capture times, visible page text, local OCR, merged text, titles, summaries, categories, tags, favorites, processing state, repositories, timeline, and saved outputs in the current Chrome profile. Local requires no account. Installing, signing in, or subscribing does not automatically upload this content.

Local processing

Recallens first checks whether selected content can be read from the page DOM. It reads ordinary page text directly and skips OCR. Images, Canvas, scanned PDFs, and unreadable pages use the packaged Tesseract.js, WebAssembly, and language models on your device. Text cleanup, merging, deduplication, classification, and search also run locally. Recallens does not load executable extension code from remote servers.

Optional system screenshot folder

Pro users can explicitly select one local folder so Recallens can add new PNG, JPEG, or WebP screenshots. This feature is off by default, does not scan unselected locations, and does not upload folder contents. Turning it off or signing out stops checks and removes the saved folder permission.

Website storage and essential cookies

The website uses browser storage for language preference, Google/Supabase sessions, and temporary state required for secure authentication returns. Paddle Checkout may set cookies or similar identifiers needed for fraud prevention, payment, and subscriptions. Recallens does not set cross-site advertising cookies or use these identifiers for behavioral advertising.

Google sign-in and Supabase

Sign-in is only required for Pro trials, membership, and AI allowances. Google authenticates you. Through Supabase, Recallens receives an account identifier, email, necessary public profile data, sign-in timestamps, and a secure session, and stores trial eligibility, membership status, validity, AI usage, and request-cost ledgers. Recallens never receives your Google password and does not request access to Gmail, Drive, or contacts.

Optional Recallens Pro AI

Recallens does not call AI automatically after capture. Only when an eligible user selects 1–5 captures, chooses a processing task, and starts it does the extension send the user instruction, size-limited selected images, up to 3,000 characters of local OCR/DOM text for each image, and the active repository view category. It does not send source URLs, browsing history, cookies, capture titles, capture times, local capture IDs, the complete library, or unselected images.

Vercel Serverless temporarily relays the request to OpenRouter and the configured multimodal model provider. Recallens application code does not persist originals, OCR, instructions, or model responses in its database; returned Markdown is saved by the extension to local Outputs. Requests require zero-data-retention routing, deny provider data collection, and disable fallback to unapproved providers. Network transmission and third-party processing remain subject to Vercel, OpenRouter, and the selected model provider's security and service terms.

Paddle payments

Paddle acts as Merchant of Record and handles checkout, payment methods, billing addresses, applicable taxes, refunds, and subscriptions. Recallens receives order, customer, and subscription identifiers and the state needed to activate access. It does not receive or store full card numbers, security codes, or payment passwords. Paddle may retain transaction records for tax, fraud-prevention, and financial obligations.

Extension permissions

activeTab and scripting are used only after a click or shortcut to capture, select a region, extract visible text, and restore a page after full-page scrolling. storage, alarms, and offscreen support local settings, explicitly selected folder checks, and recoverable OCR. identity is used only for user-initiated Google sign-in. unlimitedStorage stores captures the user created or explicitly authorized. The extension does not request permanent access to every website.

Optional product analytics

Help Improve Recallens is off by default. If enabled, the extension shares daily numeric totals for capture success or failure, capture mode, library opens, searches and whether they returned results, exports, Pro-gate views, and completed outputs, plus extension version and Chinese/English locale group. It does not collect captures, image features, OCR, page text, queries, URLs, titles, tags, filenames, AI instructions or results, email, Google identity, or browsing history.

The extension creates a random installation identifier. The server HMAC-pseudonymizes it with a deployment secret and stores daily totals for at most 90 days, with no raw event stream. Turning the setting off stops counting, clears local totals, and requests deletion of server records, retrying after an offline period. When the browser enables Global Privacy Control, Recallens prevents opt-in, disables prior consent, and requests deletion.

Infrastructure logs

When you visit the site or API, Vercel, network, and security infrastructure may process basic request metadata such as IP address, User-Agent, request time, path, status, region, and failure identifiers for delivery, security, abuse prevention, and troubleshooting. Recallens application code does not intentionally write captures, OCR, searches, AI instructions, model output, or email to operational logs. Error logs contain only redacted request identifiers, status, model, image count, and size diagnostics.

Retention

Local data remains until you delete it, clear extension data, or uninstall; export important material first. Pro AI inputs are used for the current request and are not persisted by the Recallens application database. Product analytics remain for at most 90 days. Account, membership, allowance, and necessary ledger data remain until an account-deletion request is completed and required security or dispute periods end. Paddle keeps transaction records under its legal obligations. Infrastructure-log retention follows deployment settings and provider policies and should be limited to operational security and troubleshooting needs.

Your choices and data rights

You can use Local without signing in, turn off analytics and the system screenshot folder, and edit, export, or delete local data. Permanent deletion removes the related record and image; Outputs can be deleted separately. To access, correct, or delete online account, membership, and AI-usage data, or withdraw prior consent, email support@yogocoju.com from the account email. Recallens may require reasonable verification to prevent impersonation. Cancelling a subscription and deleting an account are separate actions.

No sale or cross-site advertising

Recallens does not sell personal data, provide it to data brokers, or use captures, OCR, searches, or AI content to build cross-site advertising profiles. Necessary transfers to Supabase, Vercel, OpenRouter, model providers, and Paddle provide authentication, hosting, AI, and payment services; they are not permission to use the data for advertising.

International processing

These service providers and model nodes may process data outside your country or region. Using Pro online services requires those transfers; Local captures and OCR do not leave your device as a result. Before commercial launch, the operator must complete the data-processing agreements, transfer basis, and provider disclosures applicable to target markets.

Children

Recallens is not directed to children below the age at which they can independently consent to digital services in their location. A guardian who learns that a child created an online account without appropriate consent may contact us to verify and delete online data. Local device data must be deleted by the device user in the extension.

Security and incident response

Recallens uses HTTPS, server-only secrets, an exact extension-origin allowlist, request-size limits, entitlement checks, security headers, least privilege, and content-free error logs to reduce risk. No system can guarantee absolute security. After confirming an incident that affects user rights, the operator will investigate, contain it, and notify affected users through the site, in-product messages, or account email as required.

Policy changes

If data purposes, providers, or user rights materially change, Recallens will update the effective date and provide reasonable notice on the site or in the product. A policy update alone will not turn locally stored data into automatic uploads.

Contact

For privacy requests or security reports, email support@yogocoju.com. Do not email capture originals, passwords, full card numbers, or API keys.