Support
Security & Trust
Last updated: October 2, 2026
Recall24 holds your email only as long as it needs to, and only for the people you sent it to. This page explains how we protect it and what Recall24 can and can’t do.
How we protect your emails
Encrypted connections. All connections to Recall24 use HTTPS/TLS.
Encrypted storage. Data at rest is encrypted by our database provider.
Private links. Each recipient’s link is a long random code. Files can be downloaded only while the email is live, and only through that link.
Short retention. The text of an email is deleted when you recall it or when its 24-hour window ends. A cleanup job runs every hour to make sure of this. Files uploaded but never sent are deleted after 2 hours.
Limited access. Access to production data is limited to the people who run Recall24.
What Recall24 reads
The Gmail extension and the Outlook add-in read the email you are writing only when you send it with Recall24. In a sent email, the Outlook add-in reads only that email’s text, to find its Recall24 link and show you its status. Neither reads your inbox, contacts or other emails.
Sign-in
You sign in with your Google or Microsoft account. From that sign-in we receive only your name, email address and account ID. The web app keeps you signed in with one strictly necessary cookie that lasts 7 days. The extension and add-in keep a sign-in token on your device for 30 days, or until you disconnect.
Where your data is processed
Provider | What it does for Recall24 | Location |
|---|---|---|
Supabase | Database for accounts, emails and files | EU (Stockholm, Sweden) |
Netlify | Hosts the web app and runs its server code | United States |
Resend | Delivers Recall24 notification emails | United States |
Sign-in with Google | Global | |
Microsoft | Sign-in with Microsoft; the Outlook add-in runs in Outlook | Global |
Zoho | Our own mailboxes | EU |
Framer | Hosts the website revokemail.com | — |
Where a provider processes data outside the European Economic Area, the transfer relies on the EU–U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses.
What we don’t do
We don’t sell personal data.
We don’t show ads or build advertising profiles.
We don’t use the content of emails to train AI models.
Recall24’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The honest limits
Once a recipient has opened an email or downloaded a file, they may have read, copied or saved it. Recalling the email stops further access through Recall24. It can’t remove what the recipient already saved. Recall24 is not a security platform, and it doesn’t replace encryption tools for highly sensitive information.
If something goes wrong
If a personal data breach puts your rights at risk, we will notify the data protection authority within 72 hours and inform you without undue delay.
Report a security issue
If you think you’ve found a security problem in Recall24, write to hello@revokemail.com with “Security” in the subject. Please give us a reasonable time to fix it before sharing it publicly.
More detail is in our Privacy Policy.