Privacy policy

Local-first means local by default.

Effective August 13, 2026. This policy explains how the DevRecall Chrome extension handles information.

Short version: curated search, saved items, snippets, settings, learning state, and AI history are stored on your device. DevRecall does not sell personal information. Content is sent outside the device only when you explicitly use a cloud AI model and confirm the disclosure.

Information stored locally

DevRecall uses browser-local extension storage for preferences, favorites, search history, snippets, notes, folders, locally generated AI history, selected Ollama endpoint, and model name. This information remains in the browser profile unless you export it, clear it, remove the extension, or enable a future synchronization feature.

AI processing

Local Ollama models

When the selected Ollama model runs locally, DevRecall sends the prompt to the configured local endpoint, normally http://localhost:11434. DevRecall does not relay that request through a Built by Kris server.

Ollama cloud models

Models marked Cloud may be processed by Ollama outside your device, even when accessed through the local Ollama endpoint. DevRecall displays a confirmation before each cloud request. Ollama’s terms, privacy practices, account limits, and charges apply.

Future Pro providers

Claude, OpenAI, and OpenRouter are not active in this release. Before activation, DevRecall will publish updated provider disclosures and require user configuration or entitlement.

Prompt-injection safeguards

Pasted HTML, errors, code, and reference content are marked as untrusted data in AI prompts. Models are instructed to ignore embedded instructions that attempt to change behavior, reveal hidden prompts, obtain credentials, contact networks, execute commands, or weaken safety. Generated extractor scripts are checked for prohibited execution, networking, storage, navigation, clicks, form submissions, and DOM mutation. These safeguards reduce risk but cannot guarantee that every AI response is correct; users should review generated output.

Permissions

Data collection and sale

This release does not include advertising SDKs, cross-site tracking, remote analytics, or sale of personal information. DevRecall does not collect browsing history. Context-menu text is processed only after the user selects a DevRecall action.

Retention and deletion

Local data remains until the user deletes individual items, clears history, clears extension storage, or uninstalls the extension. AI history can be cleared from Settings. Removing DevRecall through Chrome normally removes its extension storage.

Children

DevRecall is a professional developer tool and is not directed to children under 13.

Changes

Material changes will be reflected in this policy and, when appropriate, communicated through extension release notes.

Contact

Questions, privacy requests, and support requests can be sent to support@builtbykris.com.