The Promise Was Simple
In 2022, a startup called Rewind AI launched with an audacious pitch: record everything you see on your screen and hear around you, then make all of it searchable with AI. Your meetings, your browser tabs, your conversations — turned into a permanent, queryable memory.
The obvious privacy concern had an obvious answer: it all stays on your device. The data never leaves your Mac. No server-side processing. You are the only one who can search it.
That promise ended quietly in late 2025.
From Rewind to Limitless
In April 2024, Rewind AI rebranded as Limitless. The product evolved alongside the name. Rather than just recording your screen, Limitless introduced a $99 wearable pendant — a small microphone that clips to your shirt and records every conversation you have throughout the day.
The privacy pitch stayed central to the marketing. Limitless positioned itself as a professional AI assistant that makes you sharper by never forgetting anything. It would transcribe your meetings, summarize your calls, and surface relevant memories when you needed them. The pendant would whisper-record your ambient working life.
In December 2025, Meta acquired Limitless.
What the Acquisition Changed Immediately
Within weeks, the original Rewind Mac app was sunset. Screen and audio capture features were disabled. All remaining users — people who had trusted Rewind’s on-device privacy promise for years — were automatically transitioned to a free plan under Meta’s Terms of Service and Privacy Policy.
The irony is stark. Rewind’s founding principle was that your data stays on your device. After the acquisition, it belonged to Meta: a company whose entire business model is built on converting personal behavioral data into advertising revenue.
Limitless’s own infrastructure had already shifted during the product’s evolution toward the pendant model. The pendant must send audio to servers to transcribe it. As Meta absorbed the company, that audio processing infrastructure became Meta’s infrastructure. Users who had worn the pendant through private conversations — job negotiations, medical discussions, difficult family calls, confidential business meetings — had no meaningful path to delete that data from systems they no longer controlled.
Why Personal Memory Data Is Different
The concern with an app acquiring access to your photos or documents is real, but it has limits. Photos show moments. Documents contain specific information. Memory data captured over months is different in kind, not just degree.
A system that records your ambient audio continuously builds something closer to a behavioral simulation than a document archive. It captures not just what was said, but how you sound when you are stressed, who you speak to most, what topics appear in your private conversations, and how your communication patterns shift over time.
This is the data category that makes privacy researchers most alarmed. It does not describe you. At sufficient resolution, it reconstructs you — with fidelity that no purchase history, no photo library, and no survey can match. Advertisers and influence operations both understand this. It is why ambient recording data commands a category-level premium in the data brokerage ecosystem.
The Limitless pendant, worn daily by professionals who trusted its privacy positioning, generated exactly this category of data. And Meta now holds it.
The Acquisition Pattern in Personal AI
The Limitless story is not isolated. It follows a pattern that has repeated consistently in the personal AI and productivity space.
Companies launch with strong privacy promises because that is the only credible way to persuade users to share highly sensitive behavioral data. Early adopters trust the pitch and provide months or years of intimate recordings, journal entries, or behavioral logs. Growth slows or funding runs out. A large platform acquires the company, absorbing both the product and the accumulated data.
The original users almost never receive meaningful advance notice. The transition happens through a Terms of Service update buried in an email that most people do not read carefully enough to understand what they are agreeing to.
The acquisitions of Moves (step tracking app) by Facebook in 2014, Waze by Google in 2013, and Nest by Google in 2014 established this playbook for general apps. The Limitless acquisition represents the same playbook applied to personal AI memory — a category that is inherently more sensitive than fitness data or navigation history.
What the Meta Ownership Means in Practice
Meta has not published specific statements about what it intends to do with the Limitless dataset. What is publicly understood is how Meta’s business model operates across every property it owns.
Instagram users receive advertising targeted based on behavior patterns learned across Facebook, WhatsApp, and third-party web activity. WhatsApp metadata — who you message, at what times, with what frequency — feeds Meta’s advertising intelligence even though message content is end-to-end encrypted. Oculus users are tracked behaviorally inside virtual environments. Meta’s data practices are not hypothetical. They are documented in regulatory filings, enforcement actions, and the company’s own advertising documentation.
There is no structural reason to believe that ambient audio recordings and meeting transcripts, once inside Meta’s infrastructure, would be treated differently from any other behavioral signal the company acquires through its other products.
If you were a Limitless or Rewind user, you are now, in practical terms, a Meta data subject. The legal protections available to you depend on your jurisdiction.
What You Can Actually Do Now
If you used Limitless or Rewind, your practical options are limited but not zero.
Submit a formal data deletion request. Under GDPR (if you are in the EU or UK) or CCPA (if you are in California), you have a right to request deletion of your personal data. Both regulations require a company to respond and confirm what has been erased. The GDPR deadline is one month. The CCPA deadline is 45 days.
Understand what deletion may not cover. Cloud audio and transcription data often exists across multiple systems: inference pipelines, backup storage, analytics databases, and model training datasets. A front-end account deletion does not always propagate to all of them. If you receive a confirmation of deletion that seems incomplete or generic, you have grounds to escalate to your national data protection authority (in the EU) or to file a complaint with your state attorney general’s office (in the US).
Review your data rights under relevant law. GDPR gives EU residents the right to a copy of their data, the right to know how it is processed, and the right to object to processing for marketing purposes. CCPA gives California residents similar rights. Both are worth exercising proactively.
Audit what you currently trust. If you use other personal AI tools — AI journaling apps, AI meeting assistants, AI voice memo apps — review their terms of service now, while the company is still independent. Pay particular attention to clauses governing what happens to your data in the event of a merger, acquisition, or bankruptcy.
What to Look for Before Trusting Any Memory App
The Limitless story makes clear what questions matter before you give any personal AI tool access to your conversations, documents, or life logs.
Where does processing happen? On-device processing means your data never leaves your hardware. Cloud processing means it does, regardless of what the marketing copy says. Look for specific technical documentation, not general promises.
What is the company’s acquisition policy? Almost no startup can make binding commitments about what a future acquirer will do. But a company with a genuine privacy commitment will at minimum have a specific data deletion mechanism that works before and during any ownership change.
Is the business model sustainable on subscriptions alone? A subscription business can survive on revenue. A business that offers an intimate personal AI tool for free has a structural pressure to monetize data, because the data is the only other asset of value.
What does deletion actually mean? Broad deletion promises — “we will delete your account when you request it” — are not the same as time-bounded, scope-specific, confirmed deletion. Look for specifics: what data is deleted, from which systems, within what timeframe, and what confirmation is provided.
The Trust Architecture Problem
The deepest issue with cloud-based personal memory tools is not any single company’s decisions. It is structural.
When you store personal memories, behavioral logs, or ambient recordings in a cloud service, you are not just trusting the current company. You are trusting every future owner, every future restructuring, and every Terms of Service change that will happen over the lifetime of that data — which is potentially forever, because cloud data does not age out on its own.
Rewind users trusted a company that made a specific, sincere promise about privacy. That promise did not survive first contact with an acquisition offer. Not because the founders were dishonest, but because legal structures governing acquisitions and data do not require the promise to survive.
Any personal memory tool that stores data in someone else’s infrastructure carries this structural vulnerability. The only data you can be confident will not end up in a different company’s hands is data you control yourself.
For anyone who stores journals, voice memos, personal notes, or life logs and wants genuine permanence of privacy — including the ability to delete data irreversibly, on their own schedule, without waiting for corporate compliance teams — the question is not whether to trust a cloud company. It is whether to store that data in a cloud at all.