Support

Security & Trust

Last updated: October 2, 2026

Recall24 holds your email only as long as it needs to, and only for the people you sent it to. This page explains how we protect it and what Recall24 can and can’t do.

How we protect your emails

  • Encrypted connections. All connections to Recall24 use HTTPS/TLS.

  • Encrypted storage. Data at rest is encrypted by our database provider.

  • Private links. Each recipient’s link is a long random code. Files can be downloaded only while the email is live, and only through that link.

  • Short retention. The text of an email is deleted when you recall it or when its 24-hour window ends. A cleanup job runs every hour to make sure of this. Files uploaded but never sent are deleted after 2 hours.

  • Limited access. Access to production data is limited to the people who run Recall24.

What Recall24 reads

The Gmail extension and the Outlook add-in read the email you are writing only when you send it with Recall24. In a sent email, the Outlook add-in reads only that email’s text, to find its Recall24 link and show you its status. Neither reads your inbox, contacts or other emails.

Sign-in

You sign in with your Google or Microsoft account. From that sign-in we receive only your name, email address and account ID. The web app keeps you signed in with one strictly necessary cookie that lasts 7 days. The extension and add-in keep a sign-in token on your device for 30 days, or until you disconnect.

Where your data is processed

Provider

What it does for Recall24

Location

Supabase

Database for accounts, emails and files

EU (Stockholm, Sweden)

Netlify

Hosts the web app and runs its server code

United States

Resend

Delivers Recall24 notification emails

United States

Google

Sign-in with Google

Global

Microsoft

Sign-in with Microsoft; the Outlook add-in runs in Outlook

Global

Zoho

Our own mailboxes

EU

Framer

Hosts the website revokemail.com

—

Where a provider processes data outside the European Economic Area, the transfer relies on the EU–U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses.

What we don’t do

  • We don’t sell personal data.

  • We don’t show ads or build advertising profiles.

  • We don’t use the content of emails to train AI models.

  • Recall24’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The honest limits

Once a recipient has opened an email or downloaded a file, they may have read, copied or saved it. Recalling the email stops further access through Recall24. It can’t remove what the recipient already saved. Recall24 is not a security platform, and it doesn’t replace encryption tools for highly sensitive information.

If something goes wrong

If a personal data breach puts your rights at risk, we will notify the data protection authority within 72 hours and inform you without undue delay.

Report a security issue

If you think you’ve found a security problem in Recall24, write to hello@revokemail.com with “Security” in the subject. Please give us a reasonable time to fix it before sharing it publicly.

More detail is in our Privacy Policy.