Recall Personal Information Collection List
Hushan Hushan (Shenzhen) Technology Co., Ltd.
Last updated: August 1, 2026
To ensure that Recall can provide core features, keep accounts secure, improve product quality, and comply with applicable laws and platform requirements, we may collect and use personal information as described below. Actual collection depends on the features you use, your authorization choices, your device, app version, and distribution channel.
This document applies to the macOS version of Recall. Downloads, updates, account services, payments, refunds, permission prompts, or system capabilities may be provided by the HSHS Tech website, the in-app email account service, Paddle checkout and customer portal, or the operating system, and may also be governed by their official terms, privacy policies, and on-screen notices.
| Scenario | Personal information | Purpose |
|---|---|---|
| Local workspaces | Display identifiers, window app, window title or Accessibility identifier, position, size, and match results | Save, update, preflight, and restore workspaces you confirm locally on your Mac |
| Account and entitlement | Verified email, in-app account identifier, app identifier, session, and subscription state | Login, session renewal, and app-isolated subscription entitlement |
| Order and payment information | Paddle Customer, Subscription, and Transaction identifiers plus product, amount, currency, and payment status | Checkout, renewal, refund, entitlement restoration, and support verification |
| Feedback information | Feedback text, contact details, and attachments that you actively submit | Issue handling, responses, and troubleshooting |
| Update-check information | App version, update channel, and basic connection information produced by the network request | Check, download, and verify Recall updates from the HSHS Tech update source; Sparkle anonymous system profiling is not enabled |
| First-party product usage data | App ID, QUA, version/build, platform, preferred language, a random app-scoped installation identifier, session identifier, event time and name, success state, duration or latency, stable result or error code, a small set of low-cardinality context labels, and a derived User-Agent hash; the in-app account number may be included when signed in | Measure important features and real operation results to improve Recall. This analytics is enabled by default without a first-launch permission prompt and can be turned off under Application Settings > Privacy. Turning it off stops new reports and removes the pending queue and analytics installation identifier. Failed events may be retried in a bounded local queue and raw server-side events are retained for no more than 30 days. This system does not collect workspace, window, or display content, user input, diagnostic logs, payment details, or crash reports; crash reporting is a separate capability |
| Crash diagnostic information | App ID, QUA, version/build, version_code, CFBundleVersion, macOS version and architecture, device model, process and crashed thread, exception or signal, module UUID and offset, redacted stack, occurrence time, and foreground state; KSCrash may include the in-app account number captured at crash time, while MetricKit is always anonymous; a redacted diagnostic ZIP covering two hours before and after the crash may be attached only when the current account matches | Automatically identify and fix fatal Recall crashes. KSCrash locally captures Mach exceptions, fatal signals, C++ exceptions, and NSExceptions, with Apple MetricKit as a system-side supplement; hangs, deadlocks, and SIGTERM are not monitored. Reports are normalized on-device with an allowlist and sent automatically to the HSHS Tech backend without a toggle or per-report confirmation, independently of the product analytics setting. Raw reports, the MetricKit inbox, and the pending queue each retain at most 20 owner-only items, with persisted backoff after failures. Registers, memory contents, full paths, console output, signposts, virtual-memory regions, tokens, and user content are excluded; redacted stacks are limited to 64 KiB, and diagnostic-ZIP failure does not block the crash event |
Permission-Related Information
- Use Accessibility permission to inspect and move windows that you explicitly choose to save or restore
- Read public display and running-app information to match and preflight local workspaces
- Access the network for email login, subscription purchase and management, entitlement refresh, update checks, feedback you initiate, first-party product analytics that is enabled by default and can be turned off in Application Settings, and automatic crash diagnostics that operate independently of the analytics setting
Data Minimization and Local Processing
We follow data minimization. Files, photos, videos, albums, or other content that you actively select or authorize are normally processed locally on your device. Unless a feature clearly states that network submission is required, we do not upload that content to our servers.
Account, order, log, and device information is used only for necessary purposes such as login, VIP entitlement, payment verification, customer support, stability analysis, security risk control, and legal compliance.
Local Processing Triggers and Frequency
| Capability/Component | Purpose | Information Processed | Processing Method | Frequency/Background Behavior |
|---|---|---|---|---|
| macOS Accessibility, display, and local workspace storage | Recognize displays and windows, store workspaces locally, and restore a layout after your confirmation | Display identifiers, app bundle IDs, window identifiers, titles, positions, sizes, match results, and local workspace files | Read through macOS system capabilities and processed in Recall's local database only when you save, update, preflight, or restore a workspace | Processed for user actions and display-connection changes; workspace content is not uploaded on a fixed schedule |
| KSCrash and Apple MetricKit local crash processing | Capture, normalize, deduplicate, and automatically replay fatal Recall crashes | App and system version, architecture, device, process and thread, exception or signal, module UUID and offset, redacted stack, time, and foreground state; KSCrash may include the account number at crash time, MetricKit is anonymous, and redacted logs covering two hours before and after may be attached only for a matching account | KSCrash is installed before AppKit/UI creation and leaves raw reports on-device; MetricKit diagnostics are delivered by macOS on a best-effort basis. Recall allowlist-normalizes and one-to-one deduplicates both sources before automatic delivery to the HSHS Tech backend. Tokens are not stored and no data is sent to KSCrash contributors | Processed only for supported fatal crashes or when macOS delivers a MetricKit diagnostic. Small-batch replay runs after restart and app activation; each of the three local queues is capped at 20 items. Hangs, deadlocks, and SIGTERM are not monitored |
Withdrawal and Management
You may disable permissions in macOS System Settings, log out, delete your account, or clear cache in the app. Disabling permissions, withdrawing authorization, or deleting information may make related features unavailable. For requests that cannot be completed by yourself, such as access, correction, deletion, account deletion, or explanation requests, contact feedback@hshstech.com.