← all articles

is microsoft recall safe in 2026?

safer than it was, and still not a fit for every machine. that is the honest answer, and it deserves more than the two takes usually on offer.

microsoft rebuilt recall after one of the worst security receptions of the decade. the 2026 version is genuinely different from the one announced in may 2024. it is also still an archive of everything you have looked at, sitting on a laptop, and that fact does not get engineered away. here is what changed, what did not, and how to decide.

what recall actually is

recall takes periodic snapshots of your screen on a copilot+ pc and makes them searchable. it does not run on older windows hardware, which is why most windows users have never seen it.

the pitch is the same one this entire category runs on. you looked at something, you cannot find it again, and file search cannot help because it was never a file. recall indexes the pixels so you can search what you saw.

the demand behind it is real and measurable. per the anthropic economic index for may 2026, searching electronic sources for information is the single most common work task in ai conversations at 4.95%, and searching reference materials is second at 3.74%.

meanwhile the topics that would need a personal archive stay tiny: knowledge retrieval and enterprise search at 3.61%, personal ai assistant at 2.86%, conversation and meeting intelligence at 0.26%. recall is microsoft's attempt to close exactly that gap on windows.

when microsoft announced it in may 2024 the reaction was severe enough to pause the rollout in june 2024. it returned to windows insiders in october, and has been rolling out gradually since.

what microsoft actually fixed

the rebuild is substantial, and dismissing it is as lazy as trusting it blindly.

concern in 2024where it stands in 2026
on by defaultoff by default; opt in during setup
no authentication to openwindows hello biometric match required
snapshots stored unencryptedencrypted on device, decrypted only on biometric match
index readable by any local processisolated in a vbs enclave
stays unlocked once openedautomatic timeout after 15 minutes of inactivity, adjustable
no way to exclude anythingapp and site exclusion lists, plus filtering for some sensitive fields

the enclave is the serious piece. vbs enclaves use the same hypervisor isolation that sits under hyper-v and azure confidential computing, and microsoft's windows hello for business documentation covers the authentication half. the biometric gate and the surrounding fixes were a direct answer to the 2024 backlash, and they answered it on the merits.

so why do security researchers still object?

because the protections guard the archive rather than questioning whether it should exist.

that is the whole disagreement in one sentence. assessments through 2026 keep landing in the same place: the enclave itself is well built, and the pressure moves to the boundary around it. an archive is only as isolated as the moment it hands data to something that displays it, and researchers have kept probing exactly there.

three objections survive the rebuild, and none are hysterical.

  1. it concentrates risk. one store now holds every screen you have seen. anything that compromises the account inherits months of context in a single place, which is a materially different prize from a folder of documents. a 90 day archive of a working laptop is closer to 100% of your professional context than to a backup.
  2. filtering is best effort. microsoft filters some sensitive fields and private browsing. a filter that recognises a password box does not recognise the confidential paragraph in a customer email.
  3. consent is one sided. the other people in your slack threads, your video calls and your shared documents never agreed to be in your snapshot store. this one is not a bug and has no technical fix.

windows recall privacy: who should leave it off

the decision is mostly about whose data is on the machine, not about how much you trust microsoft.

probably fine: a personal laptop, your own data, no client work, biometric hardware working, and you would find the search genuinely useful.

leave it off: any machine holding client confidential material, regulated data, source code under nda, or health, legal and financial records belonging to other people. also any shared or family machine, where the biometric gate protects one account and the household uses one login.

check first: a corporate device, where your it team may already have a policy, and enabling it yourself may breach it.

if you land on leave it off, the path to turn off microsoft recall is settings, then privacy and security, then recall and snapshots. disable snapshots, delete the existing store, and add your sensitive apps and sites to the exclusion list while you are there. it ships off by default, so for most people this is a 30 second confirmation rather than a change.

that framing matters more than any feature table, and it applies just as much to the alternatives, ours included.

the microsoft recall security question nobody asks

where does the archive go when the product changes?

this category has an unusually bad record here. rewind built the mac original, spent 2 years telling users the archive was private and theirs, and in december 2025 meta acquired the company and shipped an update that disabled all capture on december 19, 2025. users got 14 days. 7 markets including the eu and uk lost access immediately.

recall is unlikely to be acquired. it is very likely to change. an on device feature that ships with an operating system gets its terms rewritten by whoever runs that operating system, on their schedule, and the archive stays where it is. we set out the general pattern in what happens to your data when an ai app shuts down.

so the durable question is not whether the encryption is good today. it is whether you can get your archive out, in a format something else can read, on a day of your choosing.

a recall alternative for mac

there is no apple built equivalent, which surprises people.

macos has spotlight and live text, so text inside images you deliberately saved is searchable. neither indexes what merely passed across your display. so the mac options are third party, and the comparison worth making is the storage and export one rather than the feature one.

remynd is the one we build. capture, ocr and storage stay on your mac by default, you can exclude specific apps or sites from capture entirely, and it captures the focused window rather than every pixel on every display. sign in and the cloud agent do reach the network, which we state on the security page instead of claiming that nothing ever leaves the machine. there is a direct feature by feature read in remynd vs microsoft recall.

apply the same three tests to us that you would to recall. where is the archive, can you exclude things, and can you get it out.

the fair verdict

recall in 2026 is a competently secured version of an idea that remains inherently sensitive.

microsoft did the engineering work: off by default, biometric gated, encrypted, enclave isolated, timed out, excludable. that answers the 2024 criticism honestly. what it cannot answer is that a searchable record of everything you have seen is a concentrated, high value target no matter how well the safe is built, and that the people in your calls never consented to being in it.

if you would find that archive useful, and the machine holds only your own data, turn it on and set your exclusions carefully. if the machine holds anyone else's confidential material, the encryption quality is not the deciding factor. more on how to think about the storage question in private ai on your mac.

download remynd for mac if the machine you actually work on is a mac.

common questions

is microsoft recall safe to turn on? +
for a personal machine with no client data on it, the 2026 version is defensible. it is off by default, requires a windows hello biometric match to open, encrypts snapshots on device and times out after inactivity. for a machine holding other people's confidential data, the answer is still no, because the protections guard the archive rather than preventing it from existing.
how do i turn off microsoft recall? +
it ships off by default on copilot+ pcs, so the more common question is whether it was ever switched on. check settings, privacy and security, then recall and snapshots. from there you can disable snapshots entirely, delete the existing store, and add specific apps or sites to the exclusion list.
does recall send my screenshots to microsoft? +
microsoft's stated design keeps snapshots and the index on the device, encrypted, decryptable only with a biometric match. the objection from security researchers is not that the data is silently uploaded, it is that a local archive of everything you have seen is a high value target for anything that gains a foothold on the machine.
is there a microsoft recall equivalent for mac? +
there is no apple built equivalent. rewind was the mac original and meta acquired it, disabling capture on december 19, 2025. the remaining options are third party, and the thing worth comparing is where the archive is stored and whether you can export it, not the feature list.
what does recall not capture? +
microsoft has added filtering for things like private browsing windows and some sensitive fields, but filtering is best effort rather than a guarantee. anything visible on screen that the filter does not recognise is a candidate for the snapshot store, which is why the exclusion list matters more than the filter.