Security
How Remly protects your work
Remly is built so your files stay yours. Here’s how we protect them, what we access, and what we don’t.
Security principles
Encrypted in transit and at rest
Encrypted in transit over TLS. Everything stored in our cloud is encrypted at rest, and sensitive tokens get an extra layer of application-level encryption. The index on your Mac is protected by your Mac’s own disk security when FileVault is enabled; we don’t yet add a separate encryption layer on top of it there.
Permission-aware search
Results are filtered against the access information Remly imported from each source. That snapshot refreshes on the next sync, so a permission change at the source can take until then to appear here.
We don’t train on your data
Your content is never used to train AI models – ours or our provider’s. There is no setting to turn on.
You control your local files
Your files stay in place on your Mac – we don’t keep copies. Text extracted from them is sent to our API to build the index, and you choose per folder whether that index syncs to our cloud.
Read-only connectors
Remly reads the sources you connect. It never creates, edits, moves, sends, or deletes your content. Some connectors register a webhook with the provider so Remly learns when something changes.
Restricted internal access
Production access is limited to incident debugging, and we’re putting access logging in place to record it. We don’t browse your files.
What we don’t do
- We don’t sell your data.
- We don’t train AI on your data.
- We don’t browse your files or conversations.
- We don’t run ads or cross-context behavioral tracking.
Storage and retention
- Storage
- Cloud-indexed content from the sources you connect is stored encrypted in our database. Slack is the exception – it is searched live and is never indexed. Your Mac files stay in place; we store the index built from them, not the files.
- Retention
- If you cancel, you keep access through the period you’ve paid for. Your account is then frozen and the indexed data is scheduled for deletion 30 days later.
- Deletion & export
- Deleting your account ends access at once; the account and its content are held for 30 days, restorable by signing back in, then permanently deleted. Cloud deletion does not erase the index on your Mac – remove ~/Library/Application Support/Remly/ for that. Data export is coming soon.
- Certifications
- We don’t yet hold SOC 2 or ISO 27001 – SOC 2 is on our roadmap.
- Health data
- Remly is not HIPAA compliant and shouldn’t be used for protected health information.
Want the full detail?
Read the complete security and privacy documentation, or reach us directly.