Dot Privacy Policy
Effective 30 August 2026. Rewritten because the product changed. Dot no longer controls your keyboard and mouse, its browser and shell now run on a machine we operate rather than on your Mac, it now requires an account, it now has a mailbox whose contents we store, and your conversation with it is now kept with your account rather than only on one Mac. Each of those is a change in what leaves your Mac, so each of them is in here.
Dot is an assistant for macOS operated by Provable, a sole proprietorship ("we", "us"). Dot works out of sight, on a computer of its own, and can look at your screen when a request needs it, so this policy explains what leaves your Mac, what is held elsewhere, when, why, and to whom. It applies to the Dot application, use-dot.com, and related services (together, the "Service").
By installing or using Dot you agree to this policy. If you do not agree, do not use Dot.
1. In short
- Nothing is transmitted while Dot is idle. Data leaves only when you type a request and send it.
- Dot has no microphone access and records no audio. An earlier version was spoken to; this one is not.
- Dot works out of sight, on a computer of its own. It does not take your pointer, raise windows, or type into your applications. Its browser and its shell run on a machine we operate, not on your Mac, unless a request is specifically about your own files or applications.
- It can look at your screen when a request needs it, by taking a screenshot and reading it. That is not continuous and not the normal case: nothing is captured unless a request asks for it.
- We do not sell your personal information, and we do not use your content to train models.
- Dot requires an account. An email address and a password, or a Google sign-in. This changed: earlier versions needed none.
- Dot has an email address of its own, and messages it sends and receives are stored on our servers so that they are there on your next computer.
- Your conversation with Dot is stored on our servers, for the same reason: so that it is still there after a reinstall, and on your next Mac. This changed: it used to be kept only in a file on the Mac you typed it on.
2. Information we process
Request content. What you type, together with the replies produced, so your request can be carried out.
Screen information, when a request needs it. Dot can take a screenshot and read it, which is how it looks at anything a page or a file cannot tell it: a chart, a frame of video, an application of yours. It is one path and it is explicit. Nothing is captured until a request asks for it, nothing is captured between requests, and Dot does not sample, monitor or index your screen at any other time.
This used to be the whole of how Dot worked: it watched your screen and moved your pointer. That version is gone. Dot now works on its own computer and only looks at yours when the thing you asked about is there.
Mail sent to and from Dot's address. Your account is given an address of its own. Messages sent from it, and messages received at it, are stored on our servers, because a mailbox that only existed on one laptop would lose everything the moment you opened a second one. We hold what any mail provider holds: who it was from and to, the subject, the body, and when it arrived. Dot reads that mailbox when you ask it something about your mail, and what it reads goes to the model with that request, on the same terms as everything else in this section.
A note Dot writes to itself. Dot keeps one file, at ~/Library/Application Support/Dot/Files/memory.md, that it writes for its own use and reads before everything it does, so its contents are sent with every request it makes. What goes in it is Dot's decision, so it may hold anything from what you have asked it, up to and including personal information. You can read and edit it in Dot's window at any time, and delete anything you would rather it did not carry.
Files Dot keeps for itself. Dot has two folders inside your own macOS user account, both under ~/Library/Application Support/Dot. Files holds the note above. Tasks holds one folder per task, and whatever that task made goes in it. What it puts there is Dot's decision, not ours: we give it the folders and no instructions about what belongs in them, so they may contain anything from a request you made, up to and including personal information.
Being clear about what this does and does not mean:
- The folder belongs to your macOS user account and is created readable and writable by that account only. Another account on the same Mac cannot open it. Anyone who can already act as you on your Mac, or who has administrator access to it, can.
- We do not upload it, sync it, or back it up, and nothing on our servers reads it. It is created on your Mac when Dot first runs, so no part of an update or install can carry one person's notes onto another person's Mac.
- It is stored as ordinary files, protected by your account and by whatever disk encryption you have switched on. Dot does not add encryption of its own.
- When Dot reads one of these files while carrying out a request, what it read is sent with that request, on the same terms as everything else in section 2. The folder staying on your Mac is not a promise that its contents never leave it.
- It is a normal folder. Open it in Finder, read it, edit it, or delete any of it or all of it, at any time, without going through Dot.
- Uninstalling Dot does not delete it. Remove
~/Library/Application Support/Dotyourself if you want it gone. - Your conversation is the one thing in that folder that is also kept with your account, so removing the folder does not remove it. Clear the conversation in Dot to delete both copies, or close your account.
Web pages Dot opens, and the sites you sign into there. Dot has a browser of its own, which it uses to open and read pages without taking over your screen. That browser runs on a machine we operate rather than on your Mac, so that a task can carry on while your laptop is shut. Three things follow from that.
- What a page says is sent with the request that read it, on the same terms as everything else in this section. That includes the contents of pages behind a sign-in, such as your mail, if you ask Dot to work in one.
- Signing in is yours to do, and nothing you type there reaches the model. Where a site wants a password, a code, or a challenge, Dot draws that page inside its own window and sends your clicks and keystrokes straight to the browser. What you type in it is not read, not transcribed, and not sent to any model provider. Dot does not type your password and does not know it.
- What signing in leaves behind is stored on that machine, not on your Mac. Cookies and site data are kept in the browser's profile so that you do not have to sign in again, on a machine we operate, in your own instance of it. This is a real change and worth being plain about: an earlier version kept them in Dot's container on your own Mac. Ask Dot to sign you out of a site to remove them, or write to us and we will destroy the profile.
A record of each task, so you can find it again. Every task keeps a small file in its own folder, holding what you asked for in the words you typed it in, what Dot did about it, and what it said back. It is what the list in Dot's window is showing you, and it is why a task is still there tomorrow and why one that was running when you quit comes back rather than being lost. It stays until you clear that task, which deletes the record and the folder with it. Nothing about it is uploaded.
The conversation Dot has with the model is not part of it and is not kept anywhere. What is written down is the exchange as you can see it.
Device identifier. A random token generated on first launch and stored in your Keychain. It contains no information about you or your device and exists solely to apply usage limits and prevent abuse.
Service and diagnostic data. Technical information necessarily generated by using an internet service, including IP address, request timestamps, counts, model and version identifiers, and error conditions.
Information you choose to provide. If you contact support, subscribe to updates, request a feature, or report a problem, we process what you send us, including any contact details and any material you attach.
Subscription information, if you buy a plan. Dot is free to use and needs no account. If you choose a paid plan, checkout happens on Stripe, and we process what Stripe tells us: that a subscription exists, which plan it is, and which device it belongs to. Your card details are entered on Stripe's pages, are handled by Stripe, and never reach us. Stripe also holds the email and billing address you give it, under its own policy, and that email is how you sign in to manage or cancel the subscription.
Optional diagnostics and analytics, where you enable them. If we offer crash reporting or product analytics and you opt in, we process the resulting technical reports and usage events.
3. What we do not process
- Audio of any kind. Dot does not ask for microphone access and cannot record you.
- Anything captured while Dot is idle. Dot does not record, monitor, sample, or index your screen or keyboard in the background.
- Your clipboard, except when you paste into a page Dot has handed you. Dot no longer types anything on your behalf, so it has no reason to touch the clipboard at all; when you press paste inside a page it is showing you, that text goes to the page, exactly as it would in any browser.
- Passwords, passcodes and the answers to sign-in challenges. Dot never types one and never reads one: where a site asks, it hands you the page and waits.
- Anything in Safari, Chrome, or any other browser you use. Dot's browser is its own, with its own cookies, and it cannot read theirs.
- Special category data, which we do not seek. Because Dot reads whatever a page or a screenshot contains when you ask it to, such information may incidentally appear. We do not use it, and it is not retained beyond what section 6 describes.
4. Why we process it
We process the information above to:
- interpret your requests and carry them out;
- operate, maintain, secure, and improve the Service, including diagnosing faults and improving accuracy and reliability;
- apply usage limits, and detect, prevent, and investigate abuse, fraud, and security incidents;
- provide support and respond to you;
- provide any account, licence, or paid features you choose to use;
- comply with law and enforce our terms.
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use your request content or screen information to train machine learning models.
5. Who we share it with
Service providers. We use third parties to provide the Service, currently including model inference, application hosting, database, and payment providers, and in future potentially including support, email, error reporting, and analytics providers. Payments are processed by Stripe. They may process the information described above only to provide services to us and under contractual obligations.
Our model inference providers are Anthropic and OpenAI. Which of them receives a given request is determined by which model Dot picks for it, which it decides from what you have asked for and changes as the work goes on: a small model reads pages and searches your note, and a larger one does the work. Both state in their published terms for API use that they do not train their models on what is submitted through their APIs, and we do not train on it either. What they do is theirs to change, so what is described here is their position as we understand it, and their own terms govern it rather than this policy.
Legal and protective disclosure. We may disclose information where we believe in good faith it is required by law, legal process, or a governmental request, or where necessary to investigate suspected fraud or abuse, to enforce our terms, or to protect the rights, property, or safety of any person.
Business transfer. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, information may be transferred as part of that transaction. This policy will continue to apply, or you will be notified of any replacement policy.
With your direction. Where you ask Dot to perform an action, that action takes place in the applications and services you direct it to, and information may reach them as a consequence of what you asked for.
6. Retention
Screen information and the contents of pages Dot reads are processed to fulfil your request and are not retained by us afterwards. Our servers do not log the contents of requests.
Your conversation is the exception, and it is deliberate. What you type to Dot and what Dot says back are stored on our servers, under your account, so that they survive reinstalling Dot, replacing your Mac, or anything that removes ~/Library/Application Support. It is stored as one document per account and is retained until you clear the conversation in Dot or close your account, at which point it is deleted. Clearing the conversation deletes it from our servers as well as from your Mac, in the same action.
Two things this is not. It is not used to train models. And it is not the record of what Dot *did*: the per-task record described in section 2, the tool calls and their results, is written by Dot, kept on your Mac, and retained until you clear that task. The note and the task folders are likewise kept on your Mac and retained until you delete them.
The cookies of any site you sign into in Dot's browser are kept on the machine Dot works on, in your own instance of it, for as long as that machine exists. Ask Dot to sign you out of a site to remove them, or write to us and we will destroy the profile.
Mail sent from and received at your Dot's address is stored on our servers and retained until you delete it or close your account, at which point it is deleted with the account. Usage counters are keyed to a device identifier, contain no content, and expire automatically.
Service and diagnostic data, support correspondence, and account and transaction records are retained for as long as needed for the purposes in section 4 and to meet legal, accounting, and security obligations, after which they are deleted or anonymised.
Our service providers retain data under their own policies. A model inference provider may retain API data for a limited period for abuse monitoring.
7. Security
We protect information using measures appropriate to its sensitivity, including encryption in transit, storage of credentials in your system Keychain, and server credentials held only in our server environment and never distributed in the application.
Dot also enforces protections in software rather than relying on model behaviour. Two protections hold at every setting: it will not type or click while a password field has focus, and it refuses to operate password managers. A third, read-only mode, disables input control entirely when you switch it on.
How much Dot checks with you before acting is a setting, and the default is the middle one. On the default, Dot asks before acting inside a terminal or System Settings, and before acting on a screen that appears to be issuing instructions to it; ordinary work, including sending and deleting, proceeds without a question. The careful setting also asks whenever the model itself flags a step as consequential. The unrestricted setting never asks, and the two protections above still hold.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Legal bases (EEA and UK)
Where the UK or EU GDPR applies, we rely on: performance of a contract, to provide the Service you have requested; legitimate interests, to secure, maintain, and improve the Service and prevent abuse; consent, where you opt in to optional features such as analytics or marketing, which you may withdraw at any time; and legal obligation, where the law requires it.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal information, to withdraw consent, and to appeal a refusal. California residents may request disclosure of the categories of personal information collected and the purposes of collection, may request deletion or correction, and may not be discriminated against for exercising these rights.
Because Dot does not require an account and request content is not retained by us, we may hold little or no information identifying you. Where we cannot verify a request against information we hold, we may be unable to act on it, and we will tell you so.
You can exercise your own control at any time: open ~/Library/Application Support/Dot/Files in Finder and read, edit, or delete what Dot has written there; withdraw Screen Recording or Accessibility permission in System Settings, which stops Dot seeing or touching anything; enable read-only mode; tap Right Option or press Escape to stop an action in progress; quit Dot to stop all processing; or delete the com.use-dot.dot Keychain entry to discard your device identifier.
To make a request, contact us at admin@provableintelligence.com. EEA and UK users may also complain to their local supervisory authority.
10. International transfers
We operate in the United States and use providers located there. If you use Dot from outside the United States, your information will be transferred to and processed in the United States and other countries whose data protection laws may differ from your own. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
11. Children
Dot is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Third-party services
Dot acts within applications and websites you direct it to, and our website may link to third-party sites. Their handling of your information is governed by their own policies, not this one, and we are not responsible for their practices.
13. Changes
We may update this policy as the Service changes. The effective date above will be revised, and the current version will always be available at use-dot.com/privacy. Where a change materially affects what leaves your device or how it is used, we will provide notice in the application or by other reasonable means before it takes effect. Continued use after a change takes effect constitutes acceptance.
14. Contact
admin@provableintelligence.com
Provable, a sole proprietorship, United States.