Microsoft really said “we heard your feedback” and then shipped the same feature again.
Quick version
Windows Recall takes screenshots of your screen every few seconds and feeds them to an AI so you can search for anything you’ve ever seen on your computer. Microsoft announced it in 2024, got dragged across the internet for building a keylogger with extra steps, delayed it, and has now brought it back with some security changes.
The feature is opt-in now. That’s the headline improvement. Last time it was on by default, which was genuinely insane for something that screenshots your banking sessions.
What actually changed
They added filters. You can exclude specific apps and websites from being recorded. Sensitive content detection is supposed to catch things like credit card numbers and blur them out before they’re stored. Everything stays on-device and is encrypted with Windows Hello.
These are real improvements. The original version stored screenshots in a plain SQLite database that any malware with file access could read. That was bad. That was “security researcher finds it in twenty minutes at a conference” bad.
What didn’t change
It still takes screenshots of everything else. Your messages, your documents, your browsing, your email — all of it gets captured, processed by a local AI model, and indexed so you can search through it later.
Microsoft’s position is that this is a productivity tool. You saw a recipe three weeks ago and can’t remember where. You had a document open but forgot the file name. Recall finds it.
The question nobody at Microsoft seems willing to answer directly: what happens when someone with physical access to your laptop — a partner, a coworker, border security — asks to see your Recall history? The data is on-device, which Microsoft frames as a privacy win, but “on-device” also means “on the device someone is holding.”
The actual concern
Every security feature Microsoft added assumes the threat is remote hackers. Encryption at rest, Windows Hello authentication, on-device processing — these all protect against someone breaking in over the network.
They don’t protect against the person sitting next to you. They don’t protect against a workplace policy that requires you to enable Recall. They don’t protect against a subpoena for your Recall database, which is now a searchable archive of everything you’ve done on your computer.
The filters help. Being able to exclude your banking app and your messaging apps is genuinely useful. But filters only work if you remember to set them up, and the default is to capture everything.
What to do
If you’re on Windows 11, Recall is opt-in. You can just not turn it on and nothing changes. If you do want the search-your-history feature, go into settings and exclude anything you wouldn’t want screenshotted: banking, messaging, medical portals, anything personal.
If your workplace enables it through group policy, that’s a conversation with your IT department, and possibly with a lawyer. A complete searchable visual history of an employee’s computer use is an HR discovery tool whether anyone intended it to be or not.