Is Your New Laptop Screenshotting Everything? Windows Recall, Checked and Turned Off
September 30, 2026
The honest answer for most people is "your computer does not have this" — but if you are buying a laptop this autumn, it might, and the settings that matter are not the ones the headlines argue about.
Every few months somebody puts a laptop on our counter and asks, in a slightly lowered voice, whether it has been recording them. The feature they are thinking of is called Recall, it is real, and it does roughly what they fear: when it is switched on it saves a picture of your screen every few seconds, reads the text in those pictures, and lets you search back through them in plain English.
It is also, for the overwhelming majority of the computers we see, simply not there. Recall runs only on a narrow class of new machine, it arrives switched off, and nobody can switch it on for you. That combination gets lost in the arguing, and the result is that the people who worry about it usually do not have it, while the people who just bought the laptop that does have it have never heard of it.
So this is the practical version. How to find out in twenty seconds whether your PC has Recall at all; what it does and does not capture when it is on; the one filter setting people trust far more than they should; the disk-space bill nobody mentions in the reviews; and how to turn it down, turn it off, or take it off the machine entirely. Everything here is checked against Microsoft's own documentation as it stood on September 30, 2026, and where the wording matters we quote it.
First: the odds are good that your computer cannot run it
Recall is not a Windows 11 feature. It is a Copilot+ PC feature, and Copilot+ PC is a hardware category with a specific bar. Microsoft's support page lists the requirements plainly: a Copilot+ PC that meets the Secured-core standard, a "40 TOPs NPU (neural processing unit)", 16 GB of RAM and 256 GB of storage capacity.
An NPU is a third processor alongside the main chip and the graphics chip, built to run AI work on the machine rather than in a data centre, and TOPS is how its speed is quoted. The 40 TOPS bar is the whole gate. A perfectly good laptop from 2022 with a fast processor and plenty of memory does not clear it, because it does not have an NPU at all.
The category itself is recent. Microsoft announced Copilot+ PCs on May 20, 2024 — "a new category of Windows PCs designed for AI" with "powerful new silicon capable of an incredible 40+ TOPS" — with pre-orders that day and, in its own words, "availability starting on June 18", at prices "starting at $999". So no computer bought before the summer of 2024 is a Copilot+ PC, and plenty bought since are not either, because the category covers one slice of the range rather than all of it.
That is the first and largest piece of reassurance, and it is worth saying clearly because no amount of settings advice helps someone who is anxious about a feature their machine has never had. If your PC is a few years old, Recall is not on it, was never on it, and cannot be put on it.
How to check yours in twenty seconds
Three ways, any of which settles it. The fastest is the Start menu: click Start and type Recall. If a Recall app appears, the feature is on the machine. If nothing comes up, it is not.
The second is the settings page it lives on. Go to Settings > Privacy & security and look for an entry called Recall & snapshots. On a PC that does not support Recall, that entry does not exist — there is nothing to open and nothing to switch. On a PC that does, everything in this article is on that one page.
The third is the keyboard shortcut. Microsoft's documented shortcut to open Recall is the Windows key plus J. On a machine without the feature, nothing happens.
One more tell worth knowing, because it answers the question people are really asking: when Recall is actively saving snapshots, it puts an icon in the system tray, down by the clock. Microsoft says "the system tray icon is absent if the Save snapshots option is set to Off in Recall & snapshots settings", and that the icon "will change its appearance when snapshots are being saved, paused, or when filtering is occurring". So on a machine that has the feature, the tray tells you the state at a glance, without opening anything.
What it actually does when it is switched on
Microsoft's description of the mechanism is not coy: "If you opt in to the feature, then as you use your PC, a snapshot of your active screen will be saved every few seconds and when the content of your active window changes." Those snapshots are stored on the drive, and the text in them is read by optical character recognition running locally on the PC so that you can search it later.
The search is the point of the thing. You describe what you half-remember — Microsoft's own example is typing "thin crust pizza" to find a recipe you saw earlier — and it returns both text matches and visual matches, sorted by closeness, with an option to jump back into the page or document the snapshot came from. There is a timeline view as well, broken into segments of the periods you were actually using the machine.
It is worth being equally precise about what it does not do, because this is where fear outruns the facts. Microsoft states that "Recall doesn't record audio or save continuous video", and that "it also doesn't save game video when Game Mode is active on platforms that support it". It is not a microphone and it is not a screen recorder. It is a still photograph of the foreground, repeated.
One limitation that will matter to some households here: Microsoft notes that "Recall is optimized for select languages: English, Chinese (simplified), French, German, Japanese, and Spanish." If the screen you want searched is mostly in a language outside that list, the search half of the feature is working at a disadvantage even when the snapshots are being saved.
It is off until you turn it on, and that is per person
This is the fact that most of the early coverage was written before, and it has stuck around as folklore long after it stopped being true. Recall does not come switched on. Microsoft's wording is that "by default, saving snapshots for Recall aren't enabled" and "you need to opt in to saving snapshots", and that "for each new user on the device, the user can opt in to saving snapshots using Recall. If you don't choose to opt in, it will be off by default and snapshots will not be saved."
The per-user part is the piece worth holding on to, because it is what makes a shared family PC survivable. If four people sign in to the same laptop with four accounts, each of them decides separately, and Microsoft is explicit that snapshots are not "shared between different Windows users on the same device". One person opting in does not opt in the household.
And if the machine belongs to an employer or is enrolled in something an IT company manages, the default runs the other way: Microsoft says of a machine an IT company looks after: "It's removed by default unless IT sets the policy to enable Recall." Even then, an administrator cannot flip it on over your head. Microsoft answers that question directly — "An IT admin can't, on their own, enable saving snapshots on devices that are managed by an organization or school. IT admins can only give you the option to enable snapshots."
The case that does not get that protection is the one we see constantly in small businesses: a laptop that belongs to the business, is used for the business, and is managed by nobody. On those, Microsoft's own guidance says "for unmanaged Copilot+ PC devices, Recall is available by default but a user has to opt in to save snapshots." Nothing stops a member of staff from turning it on, and nothing tells you they have.
Who you are actually trusting, and it is not Microsoft
The instinctive worry is that the screenshots go somewhere. They do not. Microsoft's position on this is stated in several places and is unusually unhedged: "No internet or cloud connections are required or used to save and analyze snapshots. Snapshots and associated data are stored locally on the device. Recall does not share snapshots or associated data with Microsoft or third parties". Elsewhere on the same page: "Microsoft can't access or view the snapshots."
The protection underneath that is real engineering rather than a promise. Snapshots and the search database are encrypted; the keys are held in the TPM, tied to your Windows Hello identity, and used inside what Microsoft calls a Virtualization-based Security Enclave; and decryption happens just in time, when you authenticate. Device encryption or BitLocker has to be on. Every time you open Recall or change its settings, it asks you to prove who you are with Windows Hello.
There is a hard requirement hiding in that sentence which trips people up, so here it is in Microsoft's words: "At least one biometric sign-in option must be enabled for Windows Hello, either facial recognition or a fingerprint, to launch and use Recall." A PIN on its own is not enough to get the feature going — you have to enrol a face or a fingerprint first. Afterwards, Microsoft notes, "Recall supports Windows Hello sign-in with your face, fingerprint, or PIN".
Which lands the actual risk in a very ordinary place. The thing standing between your snapshot history and another person is not Microsoft's server policy or the encryption; it is whether that person can pass Windows Hello on your account. On a family laptop where everybody knows everybody's PIN, that is not much of a wall. If you are going to use Recall, the useful security measure is a PIN nobody else has, not a setting.
The filter people trust most is the one that deserves it least
On the Recall settings page there is a switch called Sensitive information filtering. It is on by default, and Microsoft says that when it is on, "snapshots won't be saved when potentially sensitive information is detected". Most people read that, decide the important things are covered, and move on. That reading is the single biggest mistake available here, and you can prove it yourself in about a minute.
Microsoft publishes the list. The filter runs on the NPU using the Microsoft Classification Engine — "the same technology leveraged by Microsoft Purview for detecting and labeling sensitive information" — and there is a reference page enumerating exactly what it looks for. We read the whole thing on September 30, 2026. It contains 166 entries, and every single one of them is a kind of number or credential with a recognisable format.
It is a global compliance catalogue, not a list of private subjects. Most of the 166 are national identity and tax and driving-licence numbers for countries that are not this one: Argentina's CUIT/CUIL, Croatia's OIB, Finland's national ID, Thailand's citizen ID, the UAE identity card. The entries that would actually fire on an American screen are a short list: U.S. Social Security Number, U.S. Individual Taxpayer Identification Number (ITIN), U.S. Bank Account Number, U.S. Driver's License Number, ABA Routing Number, Credit Card Number and General Password.
Now the part that made us want to write this section. The list includes the U.K. NHS Number. There is no American health identifier on it anywhere — no medical record number, no health plan number, no Medicare number. So on a Copilot+ PC in California, a patient portal open on screen is not a category the filter knows about. The only thing that would stop that snapshot is a number on the page that happens to look like a bank account or a Social Security number.
Generalise it and you have the honest description: sensitive information filtering is a number detector, not a topic detector. It has no concept of a private message, a difficult email, a solicitor's letter, a diagnosis, a photograph, a spreadsheet of staff salaries or a document marked confidential. None of those are "types". If what you want kept out of the history is a subject rather than a string of digits, this switch does not do it, and the way to keep it out is the app and website filters instead.
The website filter has gaps, and Microsoft documents them
You can tell Recall to skip specific websites — your bank, your payroll portal, the patient records system — by adding them under Websites to filter. It works, and it is the right tool. But it works less completely than the word "filter" suggests, and to Microsoft's credit the holes are written down rather than discovered.
Three of them. Content from a filtered site can still be captured "when content from a filtered website is embedded into another website, like when social media posts or videos appear inside a news article". The site's name can still appear "when the browser tab is opened, but not currently in focus" — that is, in the strip of tabs along the top. And it can appear again "when your browser's history is opened". Microsoft's summary line is that "website filtering only impacts whether the content of foreground tabs may appear in Recall."
It also depends on which browser you are in. Microsoft lists Edge, Firefox, Opera and Chrome as filtering both specified websites and private browsing; other Chromium-based browsers from version 124 onwards filter private browsing only and do not filter specific sites. If you use something off that list, site filtering is not happening.
There is a practical move buried in all that, and it is the one we would actually recommend: instead of listing sites, add the whole browser as a filtered app. Microsoft points at it directly — "you always have the option to filter out all browsing activity by adding an app filter for a browser." It is blunt, it costs you the ability to search back through web pages, and it removes the entire class of leak in one action.
Worth knowing alongside that: private browsing windows are not saved in the supported browsers, material protected by digital rights management is not stored, and remote desktop sessions through Remote Desktop Connection (mstsc.exe), VMConnect.exe, Azure Virtual Desktop and RAIL windows are filtered out. And if you realise afterwards that something was captured, the search results have a Delete all option that removes every snapshot containing that app or website in one go, and tells you how many it is about to delete.
Microsoft's own security note is more candid than the marketing
Tucked into the administrator documentation, in the section on staff using their own machines, is a sentence we think consumers deserve to see too: "Like numerous available applications for screen recording and snapshots, Recall uses general Windows screenshot APIs. It's a general security risk to allow screenshots of content that you want to prevent from being exfiltrated."
That is the vendor saying the quiet part in its own voice, and it frames the decision correctly. The question is not whether Recall is a cloud-spying tool — it is not, and the architecture backs that up. The question is whether you want a searchable, on-disk history of everything that has been on your screen to exist at all, because once it exists it is one more thing that can be got at by anyone who gets at your account.
One consequence for software you rely on: applications are able to exclude their own windows from screenshots, and therefore from Recall, using a flag Windows provides for the purpose. Some do. Many do not. You cannot assume that because an app handles money or medical data it has bothered — which is another argument for filtering the app yourself rather than hoping.
And one small trap in the feedback button. If you report a problem with Recall from inside Recall, Microsoft warns that "filing feedback will send data from Recall to Microsoft, including any screenshots that you attach to the feedback." It is the one route by which a snapshot leaves the machine, and it only happens if you send it.
The disk-space bill nobody mentions in the reviews
Here is the part that brings people to us, usually without them knowing Recall is involved: it takes a serious bite out of the drive, and on the cheapest qualifying laptops the bite is enormous relative to what they have.
Microsoft publishes the allocation table. On a 256 GB device, Recall's options are 25 GB by default or 10 GB. On a 512 GB device, 75 GB by default, or 50 or 25. On 1 TB or more, 150 GB by default, with 100, 75, 50 and 25 available. Read the first row again: 256 GB is the minimum storage a Copilot+ PC is allowed to have, and the default allocation on such a machine is 25 GB — close to a tenth of the entire drive, before Windows and Office and your photographs.
There are two more numbers that explain a support call we now expect to start getting. "To enable Recall, you'll need at least 50 GB of storage space free". And: "Saving snapshots automatically pauses once the device has less than 25 GB of storage space". So on a 256 GB laptop that has been in use for a year, the feature may refuse to start for want of 50 GB of headroom, and on a machine that fills up gradually it will quietly stop saving and not make a fuss about it.
If you want it but not at that price, both dials are on the same settings page. Maximum storage for snapshots takes the allocation down to the floor for your drive size. Maximum storage duration is the better dial in our view — you can set snapshots to be deleted after 30, 60, 90 or 180 days rather than kept indefinitely, and Microsoft notes that without it, "snapshots aren't deleted until the Maximum storage for snapshots limit is reached, and then the oldest snapshots are deleted first". A 30-day window is usually all anyone actually uses, and it caps both the storage and the exposure.
If your drive is already full and you are hunting for space, Recall is now a thing worth looking at on a new laptop, alongside all the usual suspects — we have a longer guide to reclaiming space on a Windows drive safely, and the Recall settings page has its own View system storage link that shows snapshots against everything else.
Pause is not off, and off is not gone
Three different states get muddled here, and the difference matters if you think you have dealt with it.
Pause is temporary and it un-pauses itself. From the system tray icon you can choose Pause until tomorrow, and Microsoft's description of what happens next is precise: "Snapshots will be paused until they automatically resume at 12:00 AM." That is a useful thing for an afternoon of sensitive work and a useless thing as a privacy decision, because it expires at midnight without telling you.
Off is the toggle. Settings > Privacy & security > Recall & snapshots, and set Save snapshots to Off. Nothing new gets captured and the tray icon disappears. What it does not do is delete what is already there — that is the separate Delete snapshots control on the same page, which offers Delete all, or the last hour, 24 hours, 7 days or 30 days. There is also a Reset Recall option under Advanced settings that deletes every snapshot and puts the settings back to factory.
Gone is a third thing, and it is the one most people actually want. Recall is an optional Windows component and it can be removed. Microsoft's instructions: "To remove Recall, type Turn Windows features on or off in the search box on your taskbar. Uncheck Recall from the dialog and restart your PC. Any snapshots that were previously saved will be deleted when Recall is removed." It is reversible — the same dialog puts it back — and the removal takes the stored snapshots with it, which the toggle does not.
That last option is the one we set for customers who want the question closed rather than managed. It is two clicks and a restart, it is Microsoft's own documented route rather than a registry hack off a forum, and there is nothing left running to change its mind at midnight.
The small-business version of this question
If a Copilot+ laptop is used for the business and nobody manages it — which describes most of the small offices, shops and practices we look after — then the feature is present, available, and one opt-in away, on an account that probably also sees customer records.
Think about what is routinely on the screen in a small business: card terminals and payment portals, patient or client files, staff payroll, supplier invoices, the password manager, the scan of somebody's driving licence that came in by email. A searchable history of all of it, sitting on a laptop that goes home in a bag, is a different object from a laptop that does not have one. We are not saying do not use it. We are saying decide, rather than find out.
Three things worth doing on a business machine, in order. Decide per account, and write down what you decided, because Recall is opted into per person and a new starter's account starts fresh. If it is on, filter the apps that hold other people's information — the whole browser if the work lives in a browser, plus the practice software, the accounts package and the password manager. And set a maximum storage duration so the history has an end, because an unbounded record of customer data on a portable device is the version of this that would actually be awkward to explain.
The one place the answer is easy: if the machine handles medical information, remember the filter list from earlier. There is no American health identifier among the 166 types it detects. Do not rely on the automatic filter for that; filter the application.
So should you use it?
We are not in the camp that treats this as spyware, and the reading we have done for this article moved us slightly towards the feature rather than away from it. It is off until you choose it, it is per person, it stays on the machine, the encryption is tied to hardware, an employer cannot switch it on for you, and it can be removed entirely through a normal Windows dialog. Those are not the design choices of something trying to be sneaky.
We are also not in the camp that finds it harmless. It creates a durable, searchable record of everything you looked at, on a device that gets lost and shared and repaired, and the safety of that record reduces to how good your PIN is and who else knows it. The filter most people will assume covers their private life is a detector for 166 formats of number.
So the honest split is by what the machine is for. A personal laptop, one user, a PIN nobody else knows, banking and health sites filtered by adding the browser as a filtered app, a 30-day duration limit — that is a reasonable place to use a genuinely clever feature, and people who work across a lot of documents do find it useful. A machine shared with family, or used for anyone else's personal data, or carried around a lot: leave it off, or take it off, and lose nothing you will miss.
Whichever you pick, pick it deliberately on a new PC rather than clicking through the setup screens. The twenty seconds in Settings > Privacy & security > Recall & snapshots is the whole job.
How we can help
Most of this is a settings page and a decision, and if you have read this far you can do it yourself. Where people ask us to step in is the new-computer handover: you have bought the laptop, it is one of the machines that has this, and you would rather someone went through the privacy and account settings once, properly, than discover the defaults in six months. We do that as part of setting up a new PC, along with moving your files across and making sure a real backup exists.
The other call is the one that does not mention Recall at all — a newish laptop that is mysteriously short of space. If it is a Copilot+ machine with a 256 GB drive, the snapshot allocation is one of the first places we now look, and it is often tens of gigabytes that can come back without deleting anything you care about.
And for small businesses: if you are not sure which of your machines are Copilot+ PCs, whether anyone has switched this on, or what is being captured alongside your customers' information, that is a short audit rather than a project. We will tell you what is there, set the filters and limits that make sense for the work you do, and remove the feature on the machines where the answer is simply no.
Keep reading
- C Drive Full or "Low Disk Space" in Windows? How to Free Up Space Safely
- Got a New Windows PC? How to Move Everything Over from Your Old Computer
- Windows Hello Fingerprint or Face Sign-In Not Working? (Windows 11)
- Windows 11 Won't Let You Skip the Microsoft Account. Here's How to Use a Local One — and What It Costs You
- BitLocker: Great for Protecting Your Data — Until It Locks You Out
- Gaming, Office, or Everyday? Match the Computer to What You Actually Do
- Which Version of Windows 11 Do You Have? 24H2 Stops Getting Updates on October 13, 2026
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020