Windows Recall & Copilot

AI Assistant Reviewed
These are reasonable defaults - not the only right choices. If your current settings work for you, there is no pressure to change anything.

What the default settings do

Recall is a feature exclusive to Copilot+ PCs, the hardware class of Windows machines with a neural processing unit fast enough (Microsoft specifies 40 TOPS) to run its on-device AI features. Recall periodically takes screenshots of your activity, analyzes them locally, and builds a searchable timeline so you can later ask things like “find that spreadsheet I had open last Tuesday.” After the 2024 backlash over an earlier version that shipped enabled, Microsoft rebuilt Recall and now ships it off by default on both consumer devices and managed business devices: saving snapshots requires you to explicitly opt in, either during setup or later in Settings.

When Recall is on, snapshots and the data derived from them stay entirely on your device. Microsoft states they are never uploaded to its servers. They are encrypted, and the encryption keys are tied to your Windows Hello biometric sign-in through your device’s Trusted Platform Module, so decryption happens only in a protected enclave when you are authenticated. A separate “sensitive information filtering” setting, on by default whenever Recall is enabled, tries to detect and skip saving snapshots containing things like passwords or credit card numbers, using an on-device classifier rather than sending anything off-device to make that judgment.

In the European Economic Area, Recall also lets you export your snapshots. During setup you are shown a Recall export code once; it is needed to decrypt anything you export, and Microsoft cannot recover it for you. Snapshots you export to a folder, or share with another app or website, are outside Recall’s protection: resetting Recall does not remove those copies.

Copilot, the assistant built into Windows, is a distinct feature from Recall and has its own defaults. When you sign in with a Microsoft account, Copilot can use your Microsoft activity for personalization, keeps your conversation history for 18 months unless you delete it, and can use your text and voice conversations to help train its models unless you turn that off. Signed-in adults can also be shown personalized ads in Copilot, and unless you turn off Copilot’s personalization, your conversation history can be used to further tailor them. Opting out of training does not stop your conversations from being used for advertising, safety, and other purposes described in Microsoft’s privacy statement; ads have their own settings.

People can see some of what you upload. In September 2026, 404 Media reported that contractors working for Microsoft review some Copilot image-editing requests, including the photos users uploaded, and one worker said faces were not blurred. Microsoft said it uses customer data under its terms to improve products and enforce its code of conduct. Avoid uploading photos of yourself or others to Copilot that you would not want a stranger to see.

A reasonable privacy baseline

Recall settings are found in Settings → Privacy & security → Recall & snapshots. Copilot’s own privacy settings are inside the Copilot app itself, under its profile menu. Ad settings for Copilot live in your Microsoft account, not in the app.

Recall

Settings → Privacy & security → Recall & snapshots → Save snapshots → Off (off by default)

This is the master toggle. If you never opted in during setup, it should already read Off; visiting this page is the way to confirm that rather than assume it. If you have a Copilot+ PC and don't specifically want Recall's timeline feature, leaving this off means no snapshots are ever taken.

Settings → Privacy & security → Recall & snapshots → view or delete existing snapshots → Review if you ever enabled it in the past

If you turned Recall on at some point and later off, previously saved snapshots may still exist locally. This same settings page lets you browse and bulk-delete them, and set a retention window (Microsoft documents options in a range from 30 days up to unlimited) or a storage cap for any future snapshots.

Sensitive information filtering → Leave On if you use Recall at all (on by default)

This on-device filter tries to skip saving snapshots that contain passwords, card numbers, or similar sensitive text. Microsoft notes it only works reliably in supported browsers, and that content like an unfocused background tab, embedded media, or history in an unsupported browser may not be filtered. Treat it as a helpful reduction in risk, not a guarantee.

Full removal

"Turn Windows features on or off" → uncheck Recall → Restart

Beyond turning the toggle off, Recall can be removed as an optional Windows component entirely. Search the Start menu for "Turn Windows features on or off," find the Recall entry, uncheck it, and restart. This uninstalls the feature rather than just disabling it, which is the more thorough option if you don't want it present on the device at all.

Copilot in Windows

Copilot app → profile icon → Settings → Privacy → Training on conversation activity → Off

Controls whether your text conversations with Copilot can be used to help train Microsoft's generative AI models. Opting out applies to future conversations only.

Copilot app → profile icon → Settings → Privacy → Training on voice conversations → Off

The matching switch for voice. If you talk to Copilot out loud, turn this off as well; the text setting above does not cover it. On copilot.com the same two toggles are under your profile name, then Privacy, and in the mobile app under Account, then Privacy.

Copilot app → profile icon → profile name → Memory → Microsoft usage data → Review and disable if you don't want cross-service personalization

This controls whether Copilot draws on your broader Microsoft account activity, such as Bing, Edge, or MSN usage, to personalize responses. It's separate from conversation history within Copilot itself.

Copilot conversation history → Review and delete periodically

Copilot keeps your conversation history for 18 months unless you delete it. You can delete single items or your whole history in the app at any time. If you don't want a long-running record of your assistant conversations, clearing it periodically, or after sensitive sessions, is the practical approach.

account.microsoft.com/privacy/ad-settings → See ads that interest you → Off

Turns off personalized ads in Copilot and other Microsoft services for your Microsoft account. You will still see ads, but they won't be based on your activity. If you keep personalized ads on, Microsoft says you can separately stop your Copilot conversation history from shaping them by turning off Memory → Personalization and memory in Copilot, which also makes Copilot forget what it has remembered about you.

Uploading photos to Copilot → Think twice about pictures of faces, documents, or children

Human reviewers can see some uploaded images and the edit requests that go with them, and there is no setting that keeps a specific upload out of review. Treat anything you upload as something a person might look at.

Trade-offs

  • Leaving Recall off means you lose its main selling point, the ability to search back through anything you’ve seen or done on the PC, which some people find genuinely useful for recovering lost context.
  • Even with sensitive information filtering on, Microsoft’s own documentation acknowledges gaps, particularly with unsupported browsers or background windows, so anyone using Recall should still be deliberate about what stays visible on screen.
  • Turning off Copilot’s conversation and voice training means your interactions don’t contribute to improving the assistant, a trade-off similar to opting out of training with any AI assistant. It does not stop your conversations being used for ads or safety review.
  • Turning off personalized ads does not reduce how many ads you see in Copilot or elsewhere in Microsoft’s services, only how tailored they are.
  • Disabling Microsoft usage data personalization can make Copilot’s answers feel more generic, since it will rely only on what you type in the conversation itself rather than your broader account activity.
  • Fully uninstalling Recall via Windows Features means re-enabling it later requires going through setup again rather than a single toggle.
  • In the EEA, exporting Recall snapshots is useful for keeping your own records, but exported copies are no longer covered by Recall’s reset and delete controls, and losing your export code means resetting Recall, which deletes your snapshots, to get a new one.

Who should not change these settings

  • If you frequently lose track of what you were working on and want a searchable record of your own screen activity, Recall’s local-only, encrypted design is a reasonable trade to accept, especially if you also keep filtering on and are mindful of what’s on screen.
  • If you work primarily in a supported browser and rarely handle sensitive documents on this device, the default filtering combined with local encryption addresses most of the practical risk.
  • If you rely on Copilot remembering context across sessions for ongoing projects, keeping conversation history, personalization and memory, and Microsoft usage data enabled supports that continuity; clearing it constantly would undercut the feature’s purpose. Turning off personalized ads in your Microsoft account is a way to keep memory without it shaping your ads.
  • If your device is managed by an employer, Recall’s default state and available toggles may be controlled by IT policy rather than by you individually, and that’s expected in a business context rather than a gap to fix yourself.