Dot

Dot Privacy Policy

Effective 30 August 2026. Rewritten because the product changed. Dot no longer controls your keyboard and mouse, its browser and shell now run on a machine we operate rather than on your Mac, it now requires an account, it now has a mailbox whose contents we store, and your conversation with it is now kept with your account rather than only on one Mac. Each of those is a change in what leaves your Mac, so each of them is in here.

Dot is an assistant for macOS operated by Provable, a sole proprietorship ("we", "us"). Dot works out of sight, on a computer of its own, and can look at your screen when a request needs it, so this policy explains what leaves your Mac, what is held elsewhere, when, why, and to whom. It applies to the Dot application, use-dot.com, and related services (together, the "Service").

By installing or using Dot you agree to this policy. If you do not agree, do not use Dot.


1. In short


2. Information we process

Request content. What you type, together with the replies produced, so your request can be carried out.

Screen information, when a request needs it. Dot can take a screenshot and read it, which is how it looks at anything a page or a file cannot tell it: a chart, a frame of video, an application of yours. It is one path and it is explicit. Nothing is captured until a request asks for it, nothing is captured between requests, and Dot does not sample, monitor or index your screen at any other time.

This used to be the whole of how Dot worked: it watched your screen and moved your pointer. That version is gone. Dot now works on its own computer and only looks at yours when the thing you asked about is there.

Mail sent to and from Dot's address. Your account is given an address of its own. Messages sent from it, and messages received at it, are stored on our servers, because a mailbox that only existed on one laptop would lose everything the moment you opened a second one. We hold what any mail provider holds: who it was from and to, the subject, the body, and when it arrived. Dot reads that mailbox when you ask it something about your mail, and what it reads goes to the model with that request, on the same terms as everything else in this section.

A note Dot writes to itself. Dot keeps one file, at ~/Library/Application Support/Dot/Files/memory.md, that it writes for its own use and reads before everything it does, so its contents are sent with every request it makes. What goes in it is Dot's decision, so it may hold anything from what you have asked it, up to and including personal information. You can read and edit it in Dot's window at any time, and delete anything you would rather it did not carry.

Files Dot keeps for itself. Dot has two folders inside your own macOS user account, both under ~/Library/Application Support/Dot. Files holds the note above. Tasks holds one folder per task, and whatever that task made goes in it. What it puts there is Dot's decision, not ours: we give it the folders and no instructions about what belongs in them, so they may contain anything from a request you made, up to and including personal information.

Being clear about what this does and does not mean:

Web pages Dot opens, and the sites you sign into there. Dot has a browser of its own, which it uses to open and read pages without taking over your screen. That browser runs on a machine we operate rather than on your Mac, so that a task can carry on while your laptop is shut. Three things follow from that.

A record of each task, so you can find it again. Every task keeps a small file in its own folder, holding what you asked for in the words you typed it in, what Dot did about it, and what it said back. It is what the list in Dot's window is showing you, and it is why a task is still there tomorrow and why one that was running when you quit comes back rather than being lost. It stays until you clear that task, which deletes the record and the folder with it. Nothing about it is uploaded.

The conversation Dot has with the model is not part of it and is not kept anywhere. What is written down is the exchange as you can see it.

Device identifier. A random token generated on first launch and stored in your Keychain. It contains no information about you or your device and exists solely to apply usage limits and prevent abuse.

Service and diagnostic data. Technical information necessarily generated by using an internet service, including IP address, request timestamps, counts, model and version identifiers, and error conditions.

Information you choose to provide. If you contact support, subscribe to updates, request a feature, or report a problem, we process what you send us, including any contact details and any material you attach.

Subscription information, if you buy a plan. Dot is free to use and needs no account. If you choose a paid plan, checkout happens on Stripe, and we process what Stripe tells us: that a subscription exists, which plan it is, and which device it belongs to. Your card details are entered on Stripe's pages, are handled by Stripe, and never reach us. Stripe also holds the email and billing address you give it, under its own policy, and that email is how you sign in to manage or cancel the subscription.

Optional diagnostics and analytics, where you enable them. If we offer crash reporting or product analytics and you opt in, we process the resulting technical reports and usage events.


3. What we do not process


4. Why we process it

We process the information above to:

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use your request content or screen information to train machine learning models.


5. Who we share it with

Service providers. We use third parties to provide the Service, currently including model inference, application hosting, database, and payment providers, and in future potentially including support, email, error reporting, and analytics providers. Payments are processed by Stripe. They may process the information described above only to provide services to us and under contractual obligations.

Our model inference providers are Anthropic and OpenAI. Which of them receives a given request is determined by which model Dot picks for it, which it decides from what you have asked for and changes as the work goes on: a small model reads pages and searches your note, and a larger one does the work. Both state in their published terms for API use that they do not train their models on what is submitted through their APIs, and we do not train on it either. What they do is theirs to change, so what is described here is their position as we understand it, and their own terms govern it rather than this policy.

Legal and protective disclosure. We may disclose information where we believe in good faith it is required by law, legal process, or a governmental request, or where necessary to investigate suspected fraud or abuse, to enforce our terms, or to protect the rights, property, or safety of any person.

Business transfer. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, information may be transferred as part of that transaction. This policy will continue to apply, or you will be notified of any replacement policy.

With your direction. Where you ask Dot to perform an action, that action takes place in the applications and services you direct it to, and information may reach them as a consequence of what you asked for.


6. Retention

Screen information and the contents of pages Dot reads are processed to fulfil your request and are not retained by us afterwards. Our servers do not log the contents of requests.

Your conversation is the exception, and it is deliberate. What you type to Dot and what Dot says back are stored on our servers, under your account, so that they survive reinstalling Dot, replacing your Mac, or anything that removes ~/Library/Application Support. It is stored as one document per account and is retained until you clear the conversation in Dot or close your account, at which point it is deleted. Clearing the conversation deletes it from our servers as well as from your Mac, in the same action.

Two things this is not. It is not used to train models. And it is not the record of what Dot *did*: the per-task record described in section 2, the tool calls and their results, is written by Dot, kept on your Mac, and retained until you clear that task. The note and the task folders are likewise kept on your Mac and retained until you delete them.

The cookies of any site you sign into in Dot's browser are kept on the machine Dot works on, in your own instance of it, for as long as that machine exists. Ask Dot to sign you out of a site to remove them, or write to us and we will destroy the profile.

Mail sent from and received at your Dot's address is stored on our servers and retained until you delete it or close your account, at which point it is deleted with the account. Usage counters are keyed to a device identifier, contain no content, and expire automatically.

Service and diagnostic data, support correspondence, and account and transaction records are retained for as long as needed for the purposes in section 4 and to meet legal, accounting, and security obligations, after which they are deleted or anonymised.

Our service providers retain data under their own policies. A model inference provider may retain API data for a limited period for abuse monitoring.


7. Security

We protect information using measures appropriate to its sensitivity, including encryption in transit, storage of credentials in your system Keychain, and server credentials held only in our server environment and never distributed in the application.

Dot also enforces protections in software rather than relying on model behaviour. Two protections hold at every setting: it will not type or click while a password field has focus, and it refuses to operate password managers. A third, read-only mode, disables input control entirely when you switch it on.

How much Dot checks with you before acting is a setting, and the default is the middle one. On the default, Dot asks before acting inside a terminal or System Settings, and before acting on a screen that appears to be issuing instructions to it; ordinary work, including sending and deleting, proceeds without a question. The careful setting also asks whenever the model itself flags a step as consequential. The unrestricted setting never asks, and the two protections above still hold.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


8. Legal bases (EEA and UK)

Where the UK or EU GDPR applies, we rely on: performance of a contract, to provide the Service you have requested; legitimate interests, to secure, maintain, and improve the Service and prevent abuse; consent, where you opt in to optional features such as analytics or marketing, which you may withdraw at any time; and legal obligation, where the law requires it.


9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal information, to withdraw consent, and to appeal a refusal. California residents may request disclosure of the categories of personal information collected and the purposes of collection, may request deletion or correction, and may not be discriminated against for exercising these rights.

Because Dot does not require an account and request content is not retained by us, we may hold little or no information identifying you. Where we cannot verify a request against information we hold, we may be unable to act on it, and we will tell you so.

You can exercise your own control at any time: open ~/Library/Application Support/Dot/Files in Finder and read, edit, or delete what Dot has written there; withdraw Screen Recording or Accessibility permission in System Settings, which stops Dot seeing or touching anything; enable read-only mode; tap Right Option or press Escape to stop an action in progress; quit Dot to stop all processing; or delete the com.use-dot.dot Keychain entry to discard your device identifier.

To make a request, contact us at admin@provableintelligence.com. EEA and UK users may also complain to their local supervisory authority.


10. International transfers

We operate in the United States and use providers located there. If you use Dot from outside the United States, your information will be transferred to and processed in the United States and other countries whose data protection laws may differ from your own. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.


11. Children

Dot is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.


12. Third-party services

Dot acts within applications and websites you direct it to, and our website may link to third-party sites. Their handling of your information is governed by their own policies, not this one, and we are not responsible for their practices.


13. Changes

We may update this policy as the Service changes. The effective date above will be revised, and the current version will always be available at use-dot.com/privacy. Where a change materially affects what leaves your device or how it is used, we will provide notice in the application or by other reasonable means before it takes effect. Continued use after a change takes effect constitutes acceptance.


14. Contact

admin@provableintelligence.com

Provable, a sole proprietorship, United States.