plus
PRIVACY POLICY
EFFECTIVE 2026-09-11 · XHINOLA

Privacy Policy

dot+ records and analyzes your meetings. This policy explains what data the app handles, what leaves your device, and what stays on it — most processing happens on your device.

Summary
What we process, and where

Stays on your device

  • Audio recordings of your meetings.
  • On-device transcripts produced by Apple Speech or Apple's SpeechAnalyzer.
  • Speaker diarization (who spoke when), computed on-device — unless cloud transcription is enabled for your app version, in which case AssemblyAI performs it (see below).
  • Your knowledge base of processed meetings, stored encrypted on the device.
  • Contacts you import or create — used only to label speakers; not transmitted off the device.
  • Location (optional) — an approximate location tag stored with the meeting on your device.

Sent off your device

  • Audio + working transcript → Google Vertex AI (Gemini). Sent so Gemini can generate the summary, key points, action items, and knowledge document. Processed to return your results under Google Cloud's data-processing terms; used only to provide the app's functionality.
  • Audio → AssemblyAI (cloud transcription and speaker labeling), when enabled. On app versions where we have turned cloud transcription on, the recording's audio is sent — through a proxy we operate, so our provider key is never in the app — to AssemblyAI in the United States, which returns the transcript and speaker labels. Processed only to return your transcript, under AssemblyAI's data-processing terms; never for advertising or tracking. When cloud transcription is off, this step happens entirely on your device and no audio is sent to AssemblyAI.
  • Meetings, notes, contacts & recordings → your iCloud account (Apple), when you turn on iCloud Sync. Off by default, and set separately on each device (Settings → iCloud). When it is on, dot+ keeps your library in the private database of your own iCloud account, so the same meetings appear on your iPhone and your Mac. Apple handles it under Apple's iCloud terms; we have no access to it, and it is not shared with Google, AssemblyAI, or anyone else. Recordings count against your iCloud storage. Deleting a meeting on one device deletes it on the others.
  • App integrity & identity → Firebase (Google). App Check attests requests come from a genuine copy of the app; Authentication issues an account identifier (anonymous by default; your name and email if you use Sign in with Apple).
  • Crash & performance diagnostics → Sentry. When the app crashes, freezes, or hits an error, Sentry receives a technical report: device model, OS and app version, the code path that failed, and timing measurements. It is configured to exclude your content — audio, transcripts, meeting titles, and file names are removed before anything is sent — and reports are not linked to your account identifier. Screen recording (session replay) is never enabled.

We do not run analytics or advertising SDKs, and the app's analytics collection is disabled. The crash and performance diagnostics described above are the only telemetry the app sends.

Sign in with Apple

If you sign in with Apple, Apple may share your name and email with the app so it can create your account. You can choose to hide your email (Apple relays it). Sign in with Apple is the only way to sign in.

Permissions

You can change or revoke any of these in iOS Settings.

Data retention & deletion

Your data lives on your device — dot+ has no server that stores your meetings. If you turn on iCloud Sync, a copy also lives in your own iCloud account; turning the toggle off stops further syncing, and deletions — a single meeting or Delete User — travel to iCloud and to your other devices. Deleting a meeting removes its recording, transcript, and knowledge document. Delete User (Settings → Edit Profile) permanently erases all meetings, recordings, contacts, knowledge base, and account credentials from the device. Audio sent to Google for a given analysis is processed to return your results and is subject to Google Cloud's retention terms; we do not retain it on a server of our own. Audio sent to AssemblyAI for transcription, on versions where cloud transcription is enabled, is likewise processed to return your transcript and is subject to AssemblyAI's retention terms. Crash and performance reports are held by Sentry under its retention terms; because they contain no meeting content and are not linked to your account, deleting your data in the app does not remove them.

Age requirement

dot+ is not intended for anyone under 16. We do not knowingly collect data from users under 16. Where your region sets a higher minimum age for consent to data processing, that age applies.

Changes

We may update this policy as the app evolves. Material changes will be reflected here with a new effective date.

QUESTIONS ABOUT THIS POLICY OR YOUR DATA · [email protected]