Skip to main content

Recall, Copilot and Click to Do: What’s Collecting Data and How to Turn It Off

Media Recall, Copilot and Click to Do What’s Collecting Data and How to Turn It Off

Windows 11 now includes several AI features with similar names but very different privacy behaviours.

Recall can save regular snapshots of what appears on your screen. Click to Do analyses the screen when you deliberately activate it and suggests actions for visible text or images. Copilot is an online AI assistant that processes prompts, uploaded files and selected content to produce a response.

These features are often discussed as though they all continuously record the same information. They do not.

However, some actions remain entirely on the device, while others send information to Microsoft services, Bing, Microsoft 365 or another application. Understanding that boundary is essential before enabling the features on a computer that handles customer records, financial information, passwords or other confidential data.

This guide explains what each feature processes, what it stores and how to disable or remove it where supported.

The Three Features Are Not the Same

A useful way to separate them is:

Recall

Creates a searchable history from screen snapshots saved locally on an eligible Copilot+ PC.

Click to Do

Temporarily analyses what is currently visible on the screen after you activate it, then offers relevant actions.

Copilot

Processes questions, prompts, selected text, images and uploaded files through an AI service. Its privacy behaviour depends on whether you use personal Microsoft Copilot or an organisation-protected Microsoft 365 Copilot experience.

The practical privacy question is therefore not simply:

“Is AI enabled?”

It is:

“What content is being processed, where is it processed, how long is it retained and which account or organisational policy governs it?”

Part One: Windows Recall

What Does Recall Do?

Recall is available on eligible Copilot+ PCs. When a user opts in, Windows periodically takes snapshots of the screen and creates a searchable local history.

This can help you return to:

  • A document you edited
  • A website you viewed
  • An application screen
  • A message or presentation
  • Something you saw but cannot remember where it was

Microsoft states that Recall snapshots are saved and analysed locally on the device. Saving snapshots is an opt-in choice for each Windows user; when the user does not opt in, snapshot saving remains off. 

Is Recall Always Recording?

No.

Recall can only build its history while Save snapshots is enabled.

Windows displays a Recall icon in the notification area when snapshots are being saved, paused or filtered. Users can pause snapshot saving temporarily or turn it off completely from Windows Settings. 

Recall is different from a conventional video recording. It saves periodic images rather than a continuous video stream, then indexes information visible in those images so it can be searched.

Where Are Recall Snapshots Stored?

Microsoft says Recall saves and processes its snapshots locally on the Copilot+ PC rather than automatically uploading the snapshot database to Microsoft’s cloud service. Access to Recall settings and saved information is protected through Windows Hello. 

Local storage does not mean the content is risk-free.

The snapshot database may still contain information that appeared on the screen, including:

  • Internal documents
  • Customer records
  • Email
  • Messages
  • Meeting content
  • Personal photographs
  • Application dashboards
  • Financial information
  • Information copied from remote systems

Anyone assessing Recall should consider what users routinely display, not only where the database is located.

Does Recall Capture Passwords and Payment Information?

Recall includes Sensitive information filtering, which Microsoft enables by default. It is designed to avoid saving snapshots when potentially sensitive information such as passwords or credit-card details is detected. Users can also exclude selected applications and websites. 

This should be treated as a protective control rather than a guarantee that every sensitive screen will always be recognised.

Possible concerns include:

  • Specialist applications that are not identified correctly
  • Information displayed in unexpected formats
  • Confidential data that is sensitive to the business but does not resemble a password or card number
  • Remote desktop and virtual application sessions
  • Screens shown before a filter is configured

Businesses should test filtering against their actual applications and data.

Does Private Browsing Automatically Protect You?

Recall’s filtering behaviour depends on the browser and feature support.

Microsoft provides controls to exclude websites and applications. Users should not assume that every private or incognito window in every browser will automatically be excluded in the same way.

Where sensitive browsing must never appear in snapshots, add the relevant browser or website to the Recall filtering list and test the result.

How to See Whether Recall Is Saving Snapshots

Open:

Settings > Privacy & security > Recall & snapshots

Check:

  • Save snapshots
  • Storage allocation
  • Snapshot retention
  • Apps to filter
  • Websites to filter
  • Sensitive information filtering
  • Customised Recall homepage settings

You can also check the Recall icon in the system tray.

If Recall & snapshots does not appear, the device may not be an eligible Copilot+ PC, Recall may have been removed or an administrator may have disabled it.

How to Pause Recall

Select the Recall icon in the notification area and choose the pause option.

This is useful before:

  • Opening confidential records
  • Conducting a sensitive meeting
  • Using an administrative portal
  • Entering financial information
  • Providing remote support
  • Viewing another person’s data

Pausing is temporary. Confirm that snapshot saving has not resumed before continuing sensitive work.

How to Turn Recall Snapshot Saving Off

Open:

Settings > Privacy & security > Recall & snapshots

Set:

Save snapshots > Off

Microsoft states that users can enable or disable saving at any time, with Windows Hello confirmation required when changing protected Recall settings. 

Turning this option off prevents new snapshots from being saved. It does not necessarily delete snapshots already stored on the computer.

How to Delete Existing Recall Snapshots

Open:

Settings > Privacy & security > Recall & snapshots

Expand:

Delete snapshots

You can remove:

  • The past hour
  • The past 24 hours
  • The past seven days
  • The past 30 days
  • All snapshots

Microsoft documents both time-based deletion and a Delete all option. 

After deletion, confirm that Save snapshots is off when you do not want Recall to begin creating a new history.

How to Remove Recall Completely

Search the Start menu for:

Turn Windows features on or off

Then:

  1. Find Recall.
  2. Untick it.
  3. Select OK.
  4. Restart Windows.

Microsoft states that Recall is an optional Windows feature and that removing it deletes previously saved snapshots. 

This is more comprehensive than merely switching off snapshot saving.

Recall on Business-Managed Devices

Microsoft states that Recall is disabled and removed by default on managed devices. Administrators can allow users to choose whether to use it, but cannot silently start saving snapshots on behalf of the user. 

Administrators can use policy to:

  • Disable Recall
  • Remove Recall
  • Allow users to opt in
  • Limit storage consumption
  • Set maximum retention
  • Filter applications and websites
  • Apply data-loss-prevention protections

Businesses should define their Recall position before deploying Copilot+ PCs rather than leaving every user to make an individual decision.

Part Two: Click to Do

What Is Click to Do?

Click to Do recognises text and images currently visible on the screen and offers actions that may be useful.

Depending on the selected content and installed applications, actions can include:

  • Copying text or an image
  • Opening text in another application
  • Opening a website
  • Searching the web
  • Summarising selected text
  • Rewriting text
  • Creating a bulleted list
  • Opening an email
  • Sending content to Word, Paint or Photos
  • Asking Copilot about the selection

Microsoft says Click to Do begins analysing the screen only after the user deliberately activates it and stops when the user exits. It analyses the current visible screen and does not inspect minimised applications that are not displayed. 

Does Click to Do Continuously Capture the Screen?

No.

Click to Do is enabled by default on supported Copilot+ PCs, but its active screen analysis begins only when you invoke it—for example, with:

Windows key + Q

or:

Windows key + mouse click

Microsoft states that it cannot take screenshots while it is closed. 

That is an important difference from Recall, which can save snapshots periodically while its snapshot setting is enabled.

Is Click to Do Processing Local?

The initial screenshot analysis is performed locally on the device.

Click to Do uses on-device recognition to identify text and image regions. Its intelligent text actions—such as summarising or rewriting selected text—can use Microsoft’s Phi Silica model locally through the Copilot+ PC’s NPU. 

This means selecting Rewrite does not necessarily send the text to a cloud service.

However, the selected content can leave the device when you choose an action that requires an online provider.

When Does Click to Do Send Data Online?

Content is shared when you deliberately choose an online action.

Examples include:

  • Search the web: Selected text is sent to Bing through Microsoft Edge.
  • Visual search with Bing: The selected image or content is sent to Bing’s visual-search service.
  • Ask Copilot: The selection is handed to Copilot as part of the prompt.
  • Draft with Copilot in Word: The selected text is sent to the Copilot service used by Word.
  • Ask Microsoft 365 Copilot: The selected content is processed through the organisation’s Microsoft 365 Copilot environment.

Microsoft states that its local analysis does not itself share screen content, but online actions send the selected information to the chosen service provider. 

The menu item matters. Copy and a local rewrite are not equivalent to Ask Copilot or Search the web.

Does Click to Do Store Screenshots?

Microsoft says Click to Do does not retain screen content after the requested action is complete.

It may temporarily create a file under:

C:\Users\YourName\AppData\Local\Temp

when transferring content to another application such as Paint. Temporary files may also be produced when submitting feedback. Click to Do also collects some diagnostic information needed for security, maintenance and reliability. 

Temporary storage should still be considered when working with highly sensitive screenshots.

Is Click to Do Part of Recall?

The features can interact, but they are separately manageable.

Click to Do can operate against the current screen and can also be used from Recall. Microsoft notes that the policy used to disable the ordinary Click to Do component does not automatically disable Click to Do inside Recall. 

For a complete business restriction, administrators must review both:

  • Click to Do policy
  • Recall policy

Disabling one should not be assumed to disable every entry point for the other.

How to Turn Click to Do Off

Open:

Settings > Privacy & security > Click to Do

Set:

Click to Do > Off

When disabled, the usual keyboard, mouse and touch entry points should no longer open the feature. Microsoft states that Click to Do cannot currently be removed as a component, but it can be disabled. 

How Businesses Can Disable Click to Do

Microsoft provides both Group Policy and MDM controls.

The Group Policy location is:

Computer Configuration > Administrative Templates > Windows Components > Windows AI > Disable Click to Do

A corresponding user policy is also available under:

User Configuration > Administrative Templates > Windows Components > Windows AI > Disable Click to Do

Microsoft Intune can deploy the Windows AI policy through its Windows configuration settings. When the disable policy is enabled, the component and its normal entry points are unavailable to users. 

Remember that this separate policy does not disable Click to Do inside Recall.

Part Three: Microsoft Copilot

Which Copilot Are You Using?

“Copilot” can refer to several different products:

  • The personal Microsoft Copilot app
  • Copilot on the web
  • Copilot in Edge
  • Microsoft 365 Copilot Chat
  • Licensed Microsoft 365 Copilot
  • Copilot features inside Word, Excel, PowerPoint, Outlook and OneNote
  • Copilot features supplied by another Microsoft or third-party application

The account shown in the application is crucial.

A personal Microsoft account and a company Microsoft 365 account may provide different data protections, retention arrangements and administrator controls.

What Does Personal Microsoft Copilot Collect?

When you use personal Microsoft Copilot, the service processes content you deliberately provide, such as:

  • Typed prompts
  • Voice conversations
  • Uploaded images
  • Uploaded documents
  • Content handed over by Click to Do
  • Feedback
  • Conversation history
  • Memory or personalisation information, when enabled
  • Browsing data, when related Copilot browser features are enabled

Microsoft’s current Copilot privacy controls allow signed-in users to manage memory, personalisation, conversation training, voice training and other privacy settings. 

Are Personal Copilot Conversations Used for AI Training?

Signed-in personal Copilot users can control whether future conversation and voice activity is used for model training.

In Copilot for Windows:

  1. Select your profile icon.
  2. Open Settings.
  3. Select Privacy.
  4. Turn off Training on conversation activity.
  5. Turn off Training on voice conversations, where applicable.

Microsoft says opting out excludes future conversation activity from training its AI models. It notes that the setting does not exclude data from every other product, security, advertising, compliance or system-improvement purpose described in its privacy statement. 

Turning training off is not the same as deleting existing conversation history.

How Long Is Personal Copilot History Stored?

Microsoft’s privacy FAQ currently states that Copilot conversation activity is stored for 18 months by default, although users can delete individual conversations or their complete conversation history. 

Retention and available settings can vary by account, product, region and administrator policy.

Copilot Memory Is Separate From History

Copilot can store inferred or deliberately provided information as memory to personalise future responses.

Turning personalisation off does not necessarily remove memories that already exist.

To review or remove memory:

  1. Open Copilot.
  2. Select your profile.
  3. Open Memory.
  4. Review Personalization and memory.
  5. Delete individual memories or choose Delete all Memory.

Microsoft notes that deleting all memory does not automatically delete the conversation history. 

To remove both, clear memory and conversation history separately.

How to Delete Personal Copilot Conversation History

For a personal Microsoft account, use the Microsoft privacy dashboard.

Open the Copilot activity-history section and choose:

  • Export activity history
  • Delete all activity history

Microsoft also allows individual conversations to be removed from the Copilot interface. 

Deleting history does not necessarily remove information saved separately in Copilot Memory.

Copilot for Windows Can Have Browser Data

The Windows Copilot app includes browser-related settings.

Depending on the user’s choices, it can:

  • Store browsing history
  • Store cookies
  • Save passwords
  • Synchronise browsing data
  • Import site data from Microsoft Edge

Microsoft states that the Windows app can import Edge cookies on launch when the user has allowed that setting. Browser data can be reviewed or cleared from Copilot’s browsing settings. 

To review these controls:

Copilot > Profile > Settings > Browsing settings

Check:

  • Sync and import
  • Bring over your site data from Microsoft Edge
  • Clear browsing data
  • Cookies
  • Saved passwords
  • Browsing history
  • Site permissions

These controls are separate from AI conversation training.

How to Turn Off or Remove the Copilot App

To remove the standalone personal Microsoft Copilot app:

  1. Open Settings.
  2. Select Apps > Installed apps.
  3. Find Microsoft Copilot.
  4. Open its menu.
  5. Select Uninstall.

Microsoft documents uninstalling the consumer Copilot app as a supported option, including for enterprise users. 

Removing the standalone app does not automatically turn off:

  • Copilot in Microsoft 365 applications
  • Microsoft 365 Copilot Chat
  • Click to Do’s on-device actions
  • Recall
  • Copilot functions embedded in other applications

Each component must be managed separately.

Part Four: Microsoft 365 Copilot

How Is Work Copilot Different?

When signed in with an eligible work or school account, Microsoft 365 Copilot and Copilot Chat operate within the organisation’s Microsoft 365 environment.

Depending on licensing and permissions, Copilot may use information the user is already authorised to access, such as:

  • Email
  • Teams messages
  • Calendar
  • Word documents
  • SharePoint content
  • OneDrive files
  • Meeting information
  • Microsoft Graph data

This does not mean Copilot grants access to everything in the business. It operates within the signed-in user’s existing permission boundaries.

It does mean that excessive SharePoint, Teams and OneDrive permissions can become more visible and easier to search.

Is Business Copilot Data Used to Train Foundation Models?

Microsoft states that prompts, responses and data accessed through Microsoft Graph by Microsoft 365 Copilot are not used to train its foundation language models. The same enterprise protection applies to Microsoft 365 Copilot Chat prompts and responses. 

This is an important distinction from personal Copilot, where users are given a training preference.

However, “not used to train foundation models” does not mean that no data is processed or retained. Prompts and responses still pass through the Microsoft 365 service and may be subject to organisational retention, eDiscovery, auditing, compliance and administrator policies.

Can Users Delete Microsoft 365 Copilot History?

Users can request deletion of their Microsoft 365 Copilot activity history through their work or school account:

  1. Sign in to the My Account portal.
  2. Open Settings & Privacy.
  3. Select Privacy > Data options.
  4. Open Copilot activity history.
  5. Select Delete history.
  6. Select Microsoft 365 Copilot.
  7. Submit the deletion request.

Microsoft documents this process, although organisational retention or compliance requirements may affect what can ultimately be removed. 

How to Turn Copilot Off in Word, Excel, PowerPoint and OneNote

In a supported desktop Microsoft 365 application:

  1. Open the application.
  2. Select File > Options > Copilot.
  3. Clear Enable Copilot.
  4. Select OK.
  5. Restart the application.

The setting is per application and per device. Disabling it in Word does not automatically disable it in Excel, and the change may need to be repeated on every computer. 

How to Turn Copilot Off in New Outlook

In new Outlook:

  1. Open Settings.
  2. Select Copilot.
  3. Turn Turn on Copilot off.

Microsoft states that the Outlook preference follows the signed-in account across supported Outlook platforms. The equivalent toggle is not currently available in classic Outlook for Windows. 

Turning Off Connected Experiences

When an application does not provide a dedicated Copilot toggle, users can disable connected experiences that analyse content.

In a Microsoft 365 desktop application:

  1. Open File > Account.
  2. Select Account Privacy > Manage Settings.
  3. Under Connected experiences, turn off Experiences that analyse your content.
  4. Restart the applications.

This disables Copilot, but it may also disable unrelated Microsoft 365 features, including text predictions, suggested replies, PowerPoint Designer and automatic alternative text. 

Use the dedicated Enable Copilot control where available to avoid unnecessary loss of other functionality.

What Is Collected When Click to Do Hands Content to Copilot?

Suppose you use Click to Do to select a paragraph on the screen and choose Ask Copilot.

The sequence is:

  1. Click to Do locally analyses the screen.
  2. You select a visible text or image region.
  3. Click to Do places that selected content into a Copilot prompt.
  4. Copilot becomes the provider for the requested action.
  5. The selected content is processed under the privacy terms of the Copilot account currently in use.

Microsoft explicitly describes this as a handoff from Click to Do to Copilot. 

Therefore:

  • The initial screen analysis remains local.
  • The selected content is sent online after you choose the Copilot action.
  • A personal account follows personal Copilot controls.
  • A work account may receive Microsoft 365 enterprise data protection.

Check the account before submitting business content.

What Is Collecting Data Even When These Features Are Off?

Disabling Recall, Click to Do and Copilot does not disable all Windows data collection.

Windows may still collect diagnostic and service information according to:

  • Diagnostic data settings
  • Microsoft Store activity
  • Windows Update
  • Microsoft Defender
  • Browser settings
  • Microsoft 365 connected experiences
  • Application telemetry
  • Organisational management tools
  • Endpoint security products

Review:

Settings > Privacy & security

This section contains the wider Windows privacy controls for diagnostics, activity, advertising, location, speech, camera, microphone and application permissions. 

Do not assume that removing one AI application makes the computer entirely offline or telemetry-free.

A Five-Minute Privacy Check

For a personal Copilot+ PC, review these settings:

Recall

Settings > Privacy & security > Recall & snapshots

  • Turn off Save snapshots.
  • Delete existing snapshots.
  • Review filtered apps and websites.
  • Remove Recall through Windows Features when it is not required.

Click to Do

Settings > Privacy & security > Click to Do

  • Set Click to Do to Off when it is not wanted.

Personal Copilot

Copilot > Profile > Settings > Privacy

  • Turn off conversation training.
  • Turn off voice-conversation training.
  • Review memory and personalisation.
  • Delete unwanted memories.
  • Delete conversation history.

Copilot browser data

Copilot > Settings > Browsing settings

  • Review Edge data import.
  • Review synchronisation.
  • Clear browsing data.
  • Review saved passwords and cookies.

Microsoft 365 applications

In Word, Excel, PowerPoint and OneNote:

File > Options > Copilot

  • Clear Enable Copilot.

In new Outlook:

Settings > Copilot

  • Turn Copilot off.

Recommended Business Controls

Businesses should manage these tools as part of data governance rather than treating them as optional user-interface features.

A sensible process includes:

  1. Decide whether Recall is permitted.
  2. Disable Recall by policy where its business case has not been approved.
  3. Configure application and website filters where Recall is allowed.
  4. Apply Purview data-loss-prevention controls where appropriate.
  5. Decide whether Click to Do is allowed.
  6. Disable both standard Click to Do and Recall-related access where required.
  7. Remove the personal Copilot app from managed devices where it is not approved.
  8. Direct staff towards Microsoft 365 Copilot Chat with enterprise data protection for authorised business use.
  9. Review SharePoint, Teams and OneDrive permissions before broad Copilot adoption.
  10. Train employees not to submit customer or business data through personal accounts.
  11. Configure retention, auditing, eDiscovery and sensitivity labels.
  12. Maintain a written AI acceptable-use policy.

Why Permissions Matter More With Copilot

Copilot can make existing information easier to find.

If a user already has excessive access to old SharePoint sites, Teams channels or broadly shared OneDrive folders, Copilot may surface that content more efficiently.

Before deployment, review:

  • Everyone and company-wide sharing groups
  • Old project sites
  • Links accessible to anyone
  • Former employee access
  • Overly broad Teams membership
  • Sensitive files without labels
  • Duplicate and abandoned SharePoint sites

Copilot does not fix poor access control. It can make its consequences more obvious.

Common Misunderstandings

“Recall uploads screenshots to Microsoft”

Microsoft states that Recall’s snapshot database is saved and analysed locally on the eligible device. 

However, content from a snapshot can still be sent online when the user deliberately hands it to another service.

“Click to Do is always scanning everything”

Click to Do’s analysis begins only when the user activates it and stops when they exit. It analyses the visible screen, not hidden minimised applications. 

“Everything Click to Do does is local”

Its screen detection and some intelligent text actions are local. Search, visual search, Copilot actions and other online providers can receive selected content. 

“Turning Copilot training off deletes my history”

It does not. Training, memory and history are separate controls.

“Uninstalling Copilot disables Recall”

It does not. Recall is a separate optional Windows feature.

“Microsoft 365 Copilot trains on our company files”

Microsoft states that prompts, responses and Graph data are not used to train foundation models under its enterprise protections. 

“Turning off Copilot in Word turns it off everywhere”

The dedicated application setting is normally per application and per device. 

What Not to Do

Avoid:

  • Assuming a local AI action and a cloud Copilot action have the same privacy behaviour
  • Using personal Copilot accounts for confidential business information
  • Leaving Recall enabled without reviewing the snapshot filters
  • Assuming sensitive-information filtering will catch every business secret
  • Turning off all Microsoft 365 connected experiences without checking which other tools will stop working
  • Deleting temporary folders indiscriminately
  • Sharing screenshots containing passwords or customer records
  • Treating local storage as a substitute for access control
  • Deploying Copilot before reviewing Microsoft 365 permissions
  • Allowing staff to decide individually which AI services are approved for company data
  • Assuming removal of the taskbar icon disables the underlying feature

How Hamilton Group Can Help

AI features can improve productivity, but businesses need to understand what is processed locally, what is sent to the cloud and which controls apply to personal and organisational accounts.

Hamilton Group can help with:

  • Windows Recall assessments
  • Recall and Click to Do policy configuration
  • Microsoft Intune Windows AI settings
  • Group Policy controls
  • Microsoft Copilot application management
  • Microsoft 365 Copilot deployment
  • SharePoint and OneDrive permission reviews
  • Microsoft Purview data-loss prevention
  • Sensitivity labels and retention
  • AI acceptable-use policies
  • Copilot readiness assessments
  • Staff awareness training
  • Microsoft 365 security and compliance

We can help your organisation use approved AI features without losing control of confidential information.

Keep the Useful Features—Turn Off the Ones You Do Not Need

Recall, Click to Do and Copilot should not be treated as one single data-collection feature.

Recall can create a local visual history when users opt in. Click to Do performs temporary local screen analysis but can send selected content to an online provider when the user chooses an online action. Copilot processes the information submitted to it under either personal-account privacy controls or Microsoft 365 enterprise protections.

Review each feature separately, delete information already stored where appropriate and apply central policies on managed business devices.

For help reviewing Windows AI privacy settings or deploying Microsoft 365 Copilot safely, call Hamilton Group on 0330 043 0069 or book a call with one of our experts today.