plus
PRIVACY POLICY
EFFECTIVE 2026-10-05 · XHINOLA

Privacy Policy

dot+ records and analyzes your meetings. This policy explains what data the app handles, what leaves your device, and what stays on it. Transcription and speaker labeling run on your device or with our transcription provider (AssemblyAI); audio and transcript then go to Google (via Firebase) for one enhancement pass.

Summary
What we process, and where

Stays on your device

  • Audio recordings of your meetings.
  • On-device transcripts produced by Apple Speech or Apple's SpeechAnalyzer.
  • Speaker diarization (who spoke when), computed on-device — unless cloud transcription is enabled for your app version, in which case AssemblyAI performs it (see below).
  • Your knowledge base of processed meetings, stored encrypted on the device.
  • Contacts you import or create — used to label speakers and invite people. Kept on your device, and in your own iCloud if you turn on iCloud Sync. Participants' names can be sent as described below (Ask); contacts are never sold or shared for advertising.
  • Voiceprints (optional, off unless you turn them on) — used to suggest who is speaking. Computed on the device, encrypted, and stored only on that device; not synced to other devices, included in backups, or sent to any server, including our providers.
  • Location (optional) — an approximate location tag stored with the meeting on your device.

Sent off your device

  • Audio + working transcript + your notes → Google Vertex AI (Gemini). Sent so Gemini can generate the summary, key points, action items, and knowledge document. Your notes are the lines you type in the notepad while recording, sent only when you write them, so Gemini can enhance them. Processed to return your results under Google Cloud's data-processing terms; used only to provide the app's functionality.
  • Your question + the notes of relevant meetings → Google Vertex AI (Gemini), when you use Ask. When you ask dot+ a question about your meetings, the question and the notes of the meetings it needs to answer are sent to Gemini to write the answer, under the same terms.
  • Your tasks, calendar events and meeting summaries → Google Vertex AI (Gemini), for suggestions and Siri answers. To write the short suggestions on Home, before an event and on a contact, and to answer when you ask Siri about your meetings, dot+ sends text only: your open tasks (title, owner, due date), today's calendar events (title, time, attendee names), and the title, date, summary and decisions of related past meetings. Never audio or transcripts; meetings in the Health category, their tasks, and calendar events linked to them are never included. Processed under Google Cloud's data-processing terms; the suggestions are kept only on your device.
  • Spoken replies → Google Cloud Text-to-Speech, when you use voice chat (beta). When dot+ reads an answer aloud in voice chat, the text of that answer (already written by Gemini) is sent sentence by sentence, through a proxy we operate, to Google Cloud Text-to-Speech, which returns the audio. Processed only to produce the voice, under Google Cloud's data-processing terms; nothing else from your meetings is sent. If it is unavailable, your device's own voice reads the answer.
  • Your question + your meetings' titles and short descriptions → TypeSafe (Jev), when you use Ask (beta). To pick which meetings can answer your question, the question and a one-line catalog entry per meeting — date, title, participants' names, a short description of up to 160 characters, and tags — are sent, through a proxy we operate, to TypeSafe, which returns only a relevance score for each meeting. Full notes, transcripts and audio are never sent to TypeSafe, and meetings in the Health category are never included. Processed under TypeSafe's data-processing terms (standard contractual clauses; no sale; no training on your inputs). If it is unavailable, dot+ picks the meetings itself and nothing is sent to TypeSafe.
  • Audio → AssemblyAI (cloud transcription and speaker labeling), when enabled. On app versions where we have turned cloud transcription on, the recording's audio is sent — through a proxy we operate on Cloudflare, so our provider key is never in the app — to AssemblyAI in the United States, which returns the transcript and speaker labels. Processed only to return your transcript, under AssemblyAI's data-processing terms; never for advertising or tracking. When cloud transcription is off, this step happens entirely on your device and no audio is sent to AssemblyAI.
  • Usage records → Cloudflare. The proxies we operate run on Cloudflare Workers, so what is sent through them passes through Cloudflare's network. To enforce plan limits and stop abuse, the transcription proxy keeps usage records there: your account identifier, hours transcribed and job identifiers, subscription transaction identifiers, and a hash of your IP address that changes every day (never the address itself). No audio, transcripts or meeting content are stored there.
  • Meetings, notes, contacts & recordings → your iCloud account (Apple), when you turn on iCloud Sync. Off by default, and set separately on each device (Settings → iCloud). When it is on, dot+ keeps your library in the private database of your own iCloud account, so the same meetings appear on your iPhone and your Mac. Apple handles it under Apple's iCloud terms; we have no access to it, and it is not shared with Google, AssemblyAI, or anyone else. Recordings count against your iCloud storage. Deleting a meeting on one device deletes it on the others.
  • Tasks you send → your Jira site (Atlassian), when you connect Jira. Off until you connect your Atlassian account (Settings → Jira), separately on each device. Then, only when you tap “Send to Jira” on a task, dot+ creates an issue in the Jira project you choose with that task’s title, owner and due date and the meeting’s title and date. Marking the task done in dot+ moves the issue to Done. Never audio, transcripts or notes. To show where you can send tasks, dot+ reads the Jira sites you granted, their projects and your Atlassian account name. These calls go straight from your device to Atlassian. When you connect, and each time access is renewed, your Jira sign-in passes through a service we operate on Cloudflare: it holds our Atlassian app secret, so that secret is never in the app, and exchanges your sign-in for new access without storing or logging it. The renewal key kept on your device is encrypted by our service on Cloudflare and works only for your dot+ account. Your Jira access stays in that device’s keychain, never synced to other devices, until you disconnect; the issue’s link is saved with the task (and syncs with iCloud Sync on). Once created, the issue belongs to your Jira site under your organization’s Atlassian terms: anyone with access to that project sees the task’s title, its owner’s name and the meeting’s title, and deleting the meeting in dot+ does not delete the issue. Disconnect in Settings → Jira to delete your Jira access from that device; revoke dot+ fully at id.atlassian.com → Connected apps.
  • App integrity & identity → Firebase (Google). App Check attests requests come from a genuine copy of the app; Authentication issues an account identifier (with your name and email, as Sign in with Apple shares them).
  • Crash & performance diagnostics → Sentry. When the app crashes, freezes, or hits an error, Sentry receives a technical report: device model, OS and app version, the code path that failed, and timing measurements. It is configured to exclude your content — audio, transcripts, meeting titles, and file names are removed before anything is sent — and reports are not linked to your account identifier. Screen recording (session replay) is never enabled.

We do not run analytics or advertising SDKs, and the app's analytics collection is disabled. The crash and performance diagnostics described above are the only telemetry the app sends.

Sign in with Apple

If you sign in with Apple, Apple may share your name and email with the app so it can create your account. You can choose to hide your email (Apple relays it). You can also sign in with Google (see below).

Google Calendar and Google sign-in

Connecting a Google account is optional. If you connect one, dot+ asks Google for these permissions:

What dot+ reads

The list of your calendars, and for each event: title, time, location, description, guests (names and emails), the Meet link, and whether it repeats.

Where it is stored

On your device only. Your Google sign-in tokens are kept in the device Keychain. Calendars and events are kept in memory while the app runs and are not written to disk. dot+ has no server that stores them, and calendar events are not stored or synced by iCloud Sync.

Who else sees it

No one, with two exceptions you control. First, when you save a recording made during a calendar event, dot+ suggests the event's title as the meeting's title; if you keep it, that title is part of the meeting and goes to Google Vertex AI (Gemini) with the meeting's notes, and in the meeting's one-line catalog entry to TypeSafe (beta), when you use Ask. Second, when an AI helper is on, the title, time and attendee names of the event it works on are sent to Google Vertex AI (Gemini), as text only, to write a short suggestion; events linked to Health meetings are never included. Descriptions, locations and meeting links are not sent. Google calendar data is not used for advertising, not sold, and not used to train any AI model.

How to disconnect

In dot+, open Calendars and choose Disconnect. This deletes the tokens and clears the calendar data held in memory. You can also remove dot+'s access at any time at myaccount.google.com/permissions.

Limited Use

dot+'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data protection (Google user data)

This section describes how we protect the data we receive from Google APIs: your Google calendars and events, and, if you use Continue with Google, your name, email address and profile picture.

Questions about how your data is protected: [email protected].

Permissions

You can change or revoke any of these in iOS Settings.

Data retention & deletion

Your data lives on your device — dot+ has no server that stores your meetings. If you turn on iCloud Sync, a copy also lives in your own iCloud account; turning the toggle off stops further syncing, and deletions — a single meeting or Delete User — travel to iCloud and to your other devices. Deleting a meeting removes its recording, transcript, and knowledge document. Delete User (Settings → Edit Profile) permanently erases all meetings, recordings, contacts, knowledge base, and account credentials from the device. Audio sent to Google for a given analysis is processed to return your results and is subject to Google Cloud's retention terms; we do not retain it on a server of our own. Audio and transcripts at AssemblyAI, on versions where cloud transcription is enabled, are deleted from our transcription provider within 24 hours: we delete each one about an hour after your device collects it, and our account removes anything left after one day. Text sent to Google Cloud Text-to-Speech and to TypeSafe is processed to return the voice or the relevance scores and is subject to their retention terms; we do not keep it on a server of our own. Crash and performance reports are held by Sentry under its retention terms; because they contain no meeting content and are not linked to your account, deleting your data in the app does not remove them.

Age requirement

dot+ is not intended for anyone under 16. We do not knowingly collect data from users under 16. Where your region sets a higher minimum age for consent to data processing, that age applies.

Changes

We may update this policy as the app evolves. Material changes will be reflected here with a new effective date.

QUESTIONS ABOUT THIS POLICY OR YOUR DATA · [email protected]