Privacy Policy
dot+ records and analyzes your meetings. This policy explains what data the app
handles, what leaves your device, and what stays on it. Transcription and speaker labeling run on your
device or with our transcription provider (AssemblyAI); audio and transcript then go to Google (via Firebase)
for one enhancement pass.
Summary
- Your recordings are captured and stored on your device.
- To produce summaries, action items, and notes, each recording's audio is sent to
Google's Vertex AI (Gemini) for analysis.
- Transcription and speaker labeling run on your device, or — on app versions
where we have enabled cloud transcription — with our transcription provider
AssemblyAI, which receives the recording's audio and returns the transcript.
- We use Firebase for app integrity (App Check) and to give each install an
account identifier when you sign in with Apple.
- Google Calendar is optional. If you connect it, your calendars and events stay on your
device; they are not sent to our AI or transcription providers and never used to train AI models
(see Google Calendar and Google sign-in).
- We use Sentry for crash and performance diagnostics. It receives no meeting
content — no audio, transcripts, or meeting titles — and its reports are not linked to your account.
- iCloud sync is optional and off by default. If you turn it on, your meetings,
notes, contacts, and recordings are copied to your own iCloud account so they appear
on your other Apple devices. They go to Apple, not to us.
- We do not use analytics or advertising SDKs, track you across other apps or
websites, or sell or share your data with data brokers.
- You can delete everything from within the app at any time
(Settings → Edit Profile → Delete User).
What we process, and where
Stays on your device
- Audio recordings of your meetings.
- On-device transcripts produced by Apple Speech or Apple's SpeechAnalyzer.
- Speaker diarization (who spoke when), computed on-device — unless cloud
transcription is enabled for your app version, in which case AssemblyAI performs it (see below).
- Your knowledge base of processed meetings, stored encrypted on the device.
- Contacts you import or create — used to label speakers and invite people. Kept on your
device, and in your own iCloud if you turn on iCloud Sync. Participants' names can be sent as described below
(Ask); contacts are never sold or shared for advertising.
- Voiceprints (optional, off unless you turn them on) — used to suggest who is speaking.
Computed on the device, encrypted, and stored only on that device; not synced to other devices, included
in backups, or sent to any server, including our providers.
- Location (optional) — an approximate location tag stored with the meeting on your device.
Sent off your device
- Audio + working transcript + your notes → Google Vertex AI (Gemini). Sent so Gemini can
generate the summary, key points, action items, and knowledge document. Your notes are the lines you
type in the notepad while recording, sent only when you write them, so Gemini can enhance them. Processed to return your
results under Google Cloud's data-processing terms; used only to provide the app's functionality.
- Your question + the notes of relevant meetings → Google Vertex AI (Gemini), when you use Ask.
When you ask dot+ a question about your meetings, the question and the notes of the meetings it
needs to answer are sent to Gemini to write the answer, under the same terms.
- Your tasks, calendar events and meeting summaries → Google Vertex AI (Gemini), for suggestions and
Siri answers. To write the short suggestions on Home, before an event and on a contact, and to answer
when you ask Siri about your meetings, dot+ sends text only: your open tasks (title, owner, due date), today's
calendar events (title, time, attendee names), and the title, date, summary and decisions of related past
meetings. Never audio or transcripts; meetings in the Health category, their tasks, and calendar events linked
to them are never included. Processed under Google Cloud's data-processing terms; the suggestions are kept only
on your device.
- Spoken replies → Google Cloud Text-to-Speech, when you use voice chat (beta).
When dot+ reads an answer aloud in voice chat, the text of that answer (already written by Gemini)
is sent sentence by sentence, through a proxy we operate, to Google Cloud Text-to-Speech, which
returns the audio. Processed only to produce the voice, under Google Cloud's data-processing terms;
nothing else from your meetings is sent. If it is unavailable, your device's own voice reads the answer.
- Your question + your meetings' titles and short descriptions → TypeSafe (Jev), when you use
Ask (beta). To pick which meetings can answer your question, the question and a one-line
catalog entry per meeting — date, title, participants' names, a short description of up to 160
characters, and tags — are sent, through a proxy we operate, to TypeSafe, which returns only a
relevance score for each meeting. Full notes, transcripts and audio are never sent to TypeSafe, and
meetings in the Health category are never included. Processed under TypeSafe's data-processing terms
(standard contractual clauses; no sale; no training on your inputs). If it is unavailable, dot+ picks
the meetings itself and nothing is sent to TypeSafe.
- Audio → AssemblyAI (cloud transcription and speaker labeling), when enabled.
On app versions where we have turned cloud transcription on, the recording's audio is sent — through
a proxy we operate on Cloudflare, so our provider key is never in the app — to AssemblyAI in the
United States, which returns the transcript and speaker labels. Processed only to
return your transcript, under AssemblyAI's data-processing terms; never for advertising or tracking.
When cloud transcription is off, this step happens entirely on your device and no audio is sent to
AssemblyAI.
- Usage records → Cloudflare. The proxies we operate run on Cloudflare Workers, so
what is sent through them passes through Cloudflare's network. To enforce plan limits and stop abuse, the
transcription proxy keeps usage records there: your account identifier, hours transcribed and job
identifiers, subscription transaction identifiers, and a hash of your IP address that changes every day (never the address itself).
No audio, transcripts or meeting content are stored there.
- Meetings, notes, contacts & recordings → your iCloud account (Apple), when you turn
on iCloud Sync. Off by default, and set separately on each device (Settings → iCloud). When
it is on, dot+ keeps your library in the private database of your own iCloud account, so the same
meetings appear on your iPhone and your Mac. Apple handles it under Apple's iCloud terms; we have no
access to it, and it is not shared with Google, AssemblyAI, or anyone else. Recordings count against
your iCloud storage. Deleting a meeting on one device deletes it on the others.
- Tasks you send → your Jira site (Atlassian), when you connect Jira. Off until
you connect your Atlassian account (Settings → Jira), separately on each device. Then, only when
you tap “Send to Jira” on a task, dot+ creates an issue in the Jira project you choose with that
task’s title, owner and due date and the meeting’s title and date. Marking the task done in dot+
moves the issue to Done. Never audio, transcripts or notes. To show where you can send tasks,
dot+ reads the Jira sites you granted, their projects and your Atlassian account name. These
calls go straight from your device to Atlassian. When you connect, and each time access is
renewed, your Jira sign-in passes through a service we operate on Cloudflare: it holds our
Atlassian app secret, so that secret is never in the app, and exchanges your sign-in for new
access without storing or logging it. The renewal key kept on your device is encrypted by our
service on Cloudflare and works only for your dot+ account. Your Jira access stays in that
device’s keychain, never synced to other devices, until you disconnect; the issue’s link is
saved with the task (and syncs with iCloud Sync on). Once created, the issue belongs to your
Jira site under your organization’s Atlassian terms: anyone with access to that project sees the
task’s title, its owner’s name and the meeting’s title, and deleting the meeting in dot+ does
not delete the issue. Disconnect in Settings → Jira to delete your Jira access from that device;
revoke dot+ fully at id.atlassian.com → Connected apps.
- App integrity & identity → Firebase (Google). App Check attests requests come
from a genuine copy of the app; Authentication issues an account identifier (with
your name and email, as Sign in with Apple shares them).
- Crash & performance diagnostics → Sentry. When the app crashes, freezes, or
hits an error, Sentry receives a technical report: device model, OS and app version, the code path
that failed, and timing measurements. It is configured to exclude your content — audio, transcripts,
meeting titles, and file names are removed before anything is sent — and reports are not linked to
your account identifier. Screen recording (session replay) is never enabled.
We do not run analytics or advertising SDKs, and the app's analytics collection is disabled. The crash
and performance diagnostics described above are the only telemetry the app sends.
Sign in with Apple
If you sign in with Apple, Apple may share your name and email with the app so it can create your
account. You can choose to hide your email (Apple relays it). You can also sign in with Google (see
below).
Google Calendar and Google sign-in
Connecting a Google account is optional. If you connect one, dot+ asks Google for these permissions:
- See the list of your calendars (
calendar.calendarlist.readonly) — so you
can choose which ones dot+ shows.
- See and create events (
calendar.events) — to show your upcoming Google
events next to your device calendar, and, only when you tap to schedule a meeting from dot+, to create
the event with its guests and a Google Meet link in the calendar you pick. dot+ only deletes an event
when you ask it to.
- Your name, email, and profile picture (
openid, email,
profile) — only if you use Continue with Google to sign in, so dot+ can create your
account.
What dot+ reads
The list of your calendars, and for each event: title, time, location, description, guests (names and
emails), the Meet link, and whether it repeats.
Where it is stored
On your device only. Your Google sign-in tokens are kept in the device Keychain. Calendars and events are
kept in memory while the app runs and are not written to disk. dot+ has no server that stores them, and calendar
events are not stored or synced by iCloud Sync.
Who else sees it
No one, with two exceptions you control. First, when you save a recording made during a calendar event,
dot+ suggests the event's title as the meeting's title; if you keep it, that title is part of the meeting and
goes to Google Vertex AI (Gemini) with the meeting's notes, and in the meeting's one-line catalog entry to
TypeSafe (beta), when you use Ask. Second, when an AI helper is on, the title, time and attendee names of the
event it works on are sent to Google Vertex AI (Gemini), as text only, to write a short suggestion; events linked to
Health meetings are never included. Descriptions, locations and meeting links are not sent. Google calendar data
is not used for advertising, not sold, and not used to train any AI model.
How to disconnect
In dot+, open Calendars and choose Disconnect. This deletes the tokens and clears the calendar data held in memory. You can also remove dot+'s access at any time at
myaccount.google.com/permissions.
Limited Use
dot+'s use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data
Policy, including the Limited Use requirements.
Data protection (Google user data)
This section describes how we protect the data we receive from Google APIs: your Google calendars and
events, and, if you use Continue with Google, your name, email address and profile picture.
- Encryption in transit. dot+ talks to Google only over HTTPS (TLS). Nothing from your
Google account is sent over an unencrypted connection.
- Stored on your device, protected by it. Your Google sign-in tokens are kept in the
device Keychain, which iOS and macOS encrypt, and they are not synced to your other devices or to iCloud
Keychain. Calendars and events are kept in memory while the app runs and are not written to disk. Calendar
events are not stored or synced by iCloud Sync.
- No copy on our servers. dot+ has no server that stores your Google calendar data or
your Google tokens. Because we hold no copy, we and our staff cannot read your calendars or events.
- Access limits. Only the dot+ app on your device uses the Google data it receives, and
only for what is described above: showing your calendars and events, creating an event when you ask,
and signing you in. We ask Google only for the permissions listed above.
- No human reading. No person at dot+ reads your Google data. It is processed
automatically on your device. The only flows that leave it are the ones described under Who else sees it: an event
title you keep as a meeting's title, and the text of an AI helper you turn on.
- Retention and deletion. We keep Google data only while dot+ is connected. Disconnect
(Calendars in dot+) deletes the tokens and clears the calendar data held in memory. Delete User
(Settings, Edit Profile) removes the Google tokens from the Keychain. You can also remove dot+'s access at any time at
myaccount.google.com/permissions.
- No sale, no advertising. We do not sell Google user data, share it for advertising,
or use it for credit, lending or surveillance.
- No AI or ML model training. We do not use data obtained through Google Workspace APIs
to develop, improve or train generalized AI or machine-learning models, ours or anyone else's.
Where event text is sent to Google Vertex AI (Gemini) as described above, it is used only
to produce your own results, under Google Cloud's data-processing terms, and not to train models.
- Limited Use. Our use and transfer of information received from Google APIs adheres to
the Google API Services
User Data Policy, including the Limited Use requirements.
Questions about how your data is protected: [email protected].
Permissions
- Microphone — to record meetings.
- Speech Recognition — for on-device transcription.
- Contacts — to link speakers to people you know and invite people (see "Contacts" above).
- Location (optional) — to tag a recording's location.
- Calendars (optional) — to show and prepare for upcoming meetings.
- Google account (optional) — see Google Calendar and Google sign-in.
- Face ID / passcode (optional) — to lock the app.
You can change or revoke any of these in iOS Settings.
Data retention & deletion
Your data lives on your device — dot+ has no server that stores your meetings. If you turn on iCloud
Sync, a copy also lives in your own iCloud account; turning the toggle off stops further syncing, and
deletions — a single meeting or Delete User — travel to iCloud and to your other devices.
Deleting a meeting
removes its recording, transcript, and knowledge document. Delete User (Settings →
Edit Profile) permanently erases all meetings, recordings, contacts, knowledge base, and account
credentials from the device. Audio sent to Google for a given analysis is processed to return your
results and is subject to Google Cloud's retention terms; we do not retain it on a server of our own.
Audio and transcripts at AssemblyAI, on versions where cloud transcription is enabled, are deleted from our
transcription provider within 24 hours: we delete each one about an hour after your device collects it, and
our account removes anything left after one day.
Text sent to Google Cloud Text-to-Speech and to TypeSafe is processed to return the voice or the
relevance scores and is subject to their retention terms; we do not keep it on a server of our own.
Crash and performance reports are held by Sentry under its retention terms; because they contain no
meeting content and are not linked to your account, deleting your data in the app does not remove them.
Age requirement
dot+ is not intended for anyone under 16. We do not knowingly collect data from users under 16.
Where your region sets a higher minimum age for consent to data processing, that age applies.
Changes
We may update this policy as the app evolves. Material changes will be reflected here with a new effective date.