The whole drama around with how Recall store data is misguided. The problem is not how this data is stored, it is more fundamental i.e how windows doesn't have a proper app sand boxing. MS App store apps have sandboxing and permission model but most of other apps on windows are still just bunch of DLLs and EXEs that run with all the permissions that the current user have. Until MS solves this problem there is no way…
There is Windows S Mode where you can only run Windows Store apps and only use Microsoft Edge. That should qualify for "proper sandboxing", shouldn't it? Then again, no one who needs an actually useful computer runs Windows in S mode.
That's because of all useful apps for Windows are not sandboxed. This is where the apps vendor have to do the required work but they are too lazy to do that.