Remly
Start for free

Security

How Remly protects your work

Remly is built so your files stay yours. Here’s how we protect them, what we access, and what we don’t.

Security principles

Encrypted in transit and at rest

Encrypted in transit over TLS. Everything stored in our cloud is encrypted at rest, and sensitive tokens get an extra layer of application-level encryption. The index on your Mac is protected by your Mac’s own disk security when FileVault is enabled; we don’t yet add a separate encryption layer on top of it there.

Permission-aware search

Results are filtered against the access information Remly imported from each source. That snapshot refreshes on the next sync, so a permission change at the source can take until then to appear here.

We don’t train on your data

Your content is never used to train AI models – ours or our provider’s. There is no setting to turn on.

You control your local files

Your files stay in place on your Mac – we don’t keep copies. Text extracted from them is sent to our API to build the index, and you choose per folder whether that index syncs to our cloud.

Read-only connectors

Remly reads the sources you connect. It never creates, edits, moves, sends, or deletes your content. Some connectors register a webhook with the provider so Remly learns when something changes.

Restricted internal access

Production access is limited to incident debugging, and we’re putting access logging in place to record it. We don’t browse your files.

What we don’t do

  • We don’t sell your data.
  • We don’t train AI on your data.
  • We don’t browse your files or conversations.
  • We don’t run ads or cross-context behavioral tracking.

Storage and retention

Storage
Cloud-indexed content from the sources you connect is stored encrypted in our database. Slack is the exception – it is searched live and is never indexed. Your Mac files stay in place; we store the index built from them, not the files.
Retention
If you cancel, you keep access through the period you’ve paid for. Your account is then frozen and the indexed data is scheduled for deletion 30 days later.
Deletion & export
Deleting your account ends access at once; the account and its content are held for 30 days, restorable by signing back in, then permanently deleted. Cloud deletion does not erase the index on your Mac – remove ~/Library/Application Support/Remly/ for that. Data export is coming soon.
Certifications
We don’t yet hold SOC 2 or ISO 27001 – SOC 2 is on our roadmap.
Health data
Remly is not HIPAA compliant and shouldn’t be used for protected health information.

Want the full detail?

Read the complete security and privacy documentation, or reach us directly.