Skip to main content

Trust center

Data practices

Current as of August 18, 2026

This is a plain-language description of how the RecaPod service, operated by Famplified LLC, handles your data today. Our Privacy Policy explains the legal privacy terms.

What RecaPod stores and why

CategoryExamplesWhy we keep itCurrent retention
Account dataEmail, Cognito account ID, and authentication stateSign-in, ownership, account security, and supportWhile your account is active and as needed for security, legal, and operational purposes
Pod and timeline dataPod names, structured checkpoint summaries, tags, artifacts, and timestampsOrganize history and build continuation contextUntil deleted, the account is removed, or an operational or legal period ends
Raw checkpoint sourcesOriginal submission bodyShort-term provenance, recovery, and reliable reprocessingUp to 365 days under the production raw-object lifecycle
Operational logsRequest ID, route, status, latency, source IP, and errorsReliability, troubleshooting, abuse prevention, and securityGenerally 30 days in production
Context access historyRecall time, channel, outcome, source IP, filters, and number of entries returnedLet owners detect and investigate use of read capabilities without storing recalled content90 days
Optional security alertsVerified account email, alert preference, last-send time, and access metadataNotify an owner of context access without including checkpoint content or secretsUntil alerts are disabled or the account is removed; delivery logs may follow operational retention
Capability metadataCryptographic hash, permission type, status, creation, and rotation timeVerify links without retaining raw secretsWhile the related pod or capability record is retained
Optional website analyticsPage path without query strings, device/browser details, and page viewsUnderstand website usage and improve RecaPod when a visitor opts inAccording to the active Google Analytics property retention settings

How capability links work

  • A write link can add a checkpoint but cannot read the pod history.
  • A continuation link can read the structured context needed to resume work.
  • The raw secret is shown when a link is created. RecaPod stores a one-way cryptographic hash for verification, not the raw secret.

Treat every capability URL like a password. Share only the permission needed, and rotate a link if it reaches the wrong person, agent, log, or conversation.

In the current prompt-based workflow, the AI provider receives any capability URL you paste and may retain it under that provider's terms. The reusable save prompt contains only the write-only link. On-demand retrieval uses a separate read-only link that expires after 24 hours and is not credential-isolated. For secure retrieval, Connected Access (MCP + OAuth) is recommended: it keeps its short-lived credential outside the conversation for supported agents and supports per-client revocation. New connections start save-only. Read scope and a separate owner-controlled recall switch must both be enabled before retrieval; keep your client's tool-approval setting enabled because RecaPod cannot observe the conversation. Retrieved context still enters the conversation when you ask for it.

AI and model training

RecaPod does not use customer content to train AI models. The core service stores and retrieves the structured content submitted to it; it does not require a language model to generate checkpoint summaries or continuation context. If you connect an AI agent or another third-party service, that service may process the content under its own terms and privacy practices.

Access and sharing

Pod content can be accessed by the authenticated owner, anyone holding a valid continuation capability, and authorized personnel or service providers when needed to operate, secure, or support the Service. RecaPod currently relies on Amazon Web Services for cloud infrastructure and authentication. We do not sell customer data or use it for targeted advertising.

Security controls

  • encryption in transit and at rest;
  • private, encrypted, and versioned source-object storage;
  • one-way hashing for capability secrets;
  • account and capability-based access boundaries; and
  • logs designed to exclude request bodies, cookies, authorization headers, and capability secrets.

These controls reduce risk but cannot eliminate it. Avoid storing secrets or regulated data unless you have independently determined that RecaPod is appropriate for your use case.

Deletion and exports

Deleting a timeline item removes its active database record and every stored version of its raw and normalized source objects, so it no longer appears in the timeline or continuation context. Archiving a RecaPod removes it from active work while keeping it reviewable, exportable, and restorable in the dashboard. From the archived RecaPod, the owner can permanently delete the RecaPod and its stored entries. Large erasures and account deletion are fulfilled through a verified support request. Exports and copies sent to an agent, browser, local file, or third-party service are outside RecaPod’s control.

Current history limits

RecaPod currently supports complete synchronous export and immediate self-service deletion for histories containing up to 500 entries. Recall and content search scan at most 500 entries and report when results are truncated. Larger exports, large-pod erasure, and account-wide deletion are handled through a verified support request while resumable self-service workflows are being developed.

Questions and requests

For data questions, deletion or access requests, or security concerns, email info@email.famplified.com.