fluidrecall.com · privacy
Privacy
Fluid Recall is a small, free system of record. This page says plainly what it stores and how to get it back or remove it. There is no advertising, no tracking pixel, and no third-party analytics on API traffic.
Last updated 2026-09-30.
What we store
- Study records. The decks, cards, prompts, answers, and review ratings you or your agent send to the API. The scheduler derives a
dueAtfrom each rating and stores it on the card. - API tokens. Personal API tokens are stored as SHA-256 hashes. We do not keep the plaintext token after the one time we return it to you.
- OAuth tokens and codes. Authorization codes and OAuth access/refresh tokens for the ChatGPT plugin are also stored hashed, not in the clear.
- Email on claimed mailboxes. For a claimed
*@fluidrecall.commailbox, we store message metadata and the message body so the mailbox can be read and replied to through the API. Only the person who claimed that address can read it. - Aggregate operator counters. We keep aggregate traffic counters to run the service. They are counts, not per-person profiles, and they are not sold or shared.
What we do not do
No third-party analytics on API traffic. No ad networks. No selling or renting data. The scheduler does not call a model, and your prompts and answers are treated as data, not as instructions. A personal API token is the tenant: calls do not carry a user id, and you should keep the token private.
Export and delete
Your records are yours. With your personal API token you can export everything through the API: GET /api/v1/export/manifest first, then GET /api/v1/export. Paginate cards and reviews with nextCursor until complete is true. The dump is your tenant only and includes answers.
To stop a token, use POST /api/v1/tokens/revoke (or POST /api/v1/tokens/rotate to replace it). An operator can revoke a token from the admin page. Deleting a tenant deletes its decks, cards, reviews, and stored mail. If you want the whole record removed, export it first, then ask the operator to revoke and delete it.
Contact
Questions about this policy or a deletion request can go through the FAQ page. The service is provided as-is; see the terms.