Effective date: June 20, 2026 · Last updated: August 1, 2026
Dolli ("Dolli", "we", "us") is a macOS desktop application that helps you capture, organize, and act on information from your tasks, notes, email, messages, and calendar. This policy explains what data Dolli handles, where it goes, and your choices.
Dolli is operated by the developer of Dolli ("the Developer"), who is the data controller for the purposes of this policy. Contact: dolli.support@gmail.com.
1. Summary (the short version)
- Most of your data stays on your Mac. Your tasks, notes, captures, email, iMessages, contacts, and calendar events are read and stored locally in an on-device database and in a local "Vault" folder of Markdown files.
- AI features send the relevant content to our processing service (a Cloudflare Worker we operate), which forwards it to AI providers (Anthropic and OpenAI) to generate summaries, replies, and extractions. This only happens when you use an AI feature.
- If you record a meeting, the audio streams from your Mac directly to Deepgram to be transcribed, using your own Deepgram key. With Screen & System Audio Recording granted, that includes the other participants' audio — so make sure you have their consent.
- Optional cloud sync copies your tasks, notes, and projects to our database (Supabase) so they can sync to the Dolli mobile companion. Sync is off unless you configure it.
- We do not sell your data. We do not use the content of your email or messages for advertising.
- Telemetry is opt-in and never includes the raw content of your prompts, email, or messages.
2. Data we handle, and where it comes from
a. Data stored locally on your device
Dolli reads and stores the following on your Mac (in the app's data
directory and in ~/Documents/FlashFocusVault):
| Category | Source | Notes |
|---|---|---|
| Tasks, notes, captures, projects | You | Created in the app |
| Email messages & metadata | Google account (Gmail API) | Read with your OAuth consent |
| iMessage / SMS messages & contacts | macOS Messages database | Requires Full Disk Access, which you grant manually |
| Calendar events | macOS Calendar | Read locally |
| Calendar events (CalDAV) | iCloud, Fastmail, or another CalDAV server you connect | Fetched over the network using credentials you provide |
| Email messages (IMAP) | Any mail account you connect directly | Fetched over the network using credentials you provide |
| Meeting recordings | Your microphone, and system audio when you allow it | Audio and transcripts stored locally; see section 3 |
| Link previews | Pages you capture a link to | Dolli requests the page to read its title/description |
| Account profile | Your sign-in | Email address, display name, timezone, plan tier |
This local data is not transmitted anywhere except as described in sections 3 and 4 below.
Connecting a CalDAV or IMAP account means Dolli contacts that provider directly from your device, using the credentials you supply. Saving a link means Dolli requests that page to build a preview, so the site you linked to sees a request from your device. Neither is routed through our servers.
b. Account data
Dolli uses a sign-in system to authenticate AI requests. We store your email address, display name, timezone, plan tier, and an authentication token.
3. AI processing (Anthropic, OpenAI & Deepgram)
When you use an AI feature — for example summarizing an item, drafting an email reply, transcribing audio, triaging tasks, or the weekly review — Dolli sends the relevant content for that action to a processing service we operate (a Cloudflare Worker). That service forwards the content to:
- Anthropic (Claude models) — text understanding, summaries, replies, extraction, triage.
- OpenAI — used as a fallback for text generation, and Whisper for audio transcription when you transcribe a voice note.
What is sent depends on the feature you invoke and may include the text of an email, a message, a note, a captured link's contents, or an audio recording. These providers process the data to return a result to you. We do not use this content to train models, and our providers process it under their respective business/enterprise terms. See:
- Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
- OpenAI Privacy Policy: https://openai.com/policies/privacy-policy
- Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
Meeting transcription (Deepgram)
Meeting recording works differently from the features above. While a recording is running, Dolli streams the audio from your device directly to Deepgram for live transcription, using a Deepgram API key that you supply in Settings. It does not pass through our servers, and it does not happen unless you start a recording.
If you have granted Screen & System Audio Recording, that stream includes the other participants' audio, not only your own microphone. Recording a conversation may require the consent of everyone taking part, and the laws on this differ by country and by state. You are responsible for obtaining that consent where it applies.
Resulting transcripts and summaries are stored locally, and are sent to the providers above only if you then use an AI feature on them.
- Deepgram Privacy Policy: https://deepgram.com/privacy
Network transport for AI requests is provided by Cloudflare, which processes the request in transit.
4. Optional cloud sync (Supabase)
If you enable sync (by entering a sync URL and key in Settings), Dolli copies the following to our hosted database, provided by Supabase, so it can sync with the Dolli mobile companion app:
- Tasks, stash/captures, projects, calendar-derived events, workspace context entries, and scheduled notifications.
Your email and iMessage message bodies are not synced to Supabase; they remain on your device. Sync is disabled by default and only runs after you configure it. Supabase Privacy Policy: https://supabase.com/privacy
5. Telemetry (opt-in)
If you turn on "Help improve Dolli" in Settings, we collect privacy-safe usage telemetry: feature names, latency, token counts, and error reports. Raw prompts, responses, email, and message content are never included. Telemetry is off by default and can be turned off at any time.
6. How we use data
- To provide the app's core features (organizing your tasks, notes, email, messages, and calendar).
- To generate AI summaries, replies, transcriptions, and other AI outputs you request.
- To sync your data across your devices (if you enable sync).
- To operate, secure, debug, and improve the service (telemetry, if enabled).
We do not sell your personal data, and we do not use the content of your email or messages for advertising or profiling.
7. Google API Services — Limited Use disclosure
Dolli's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In addition to the statement above, specifically:
- We only access your Google data to provide and improve user-facing features of Dolli that are visible and obvious to you.
- We do not transfer or sell Google user data for advertising, and we do not allow humans to read your Google data, except: (a) with your affirmative consent, (b) for security purposes, (c) to comply with applicable law, or (d) where the data is aggregated and anonymized.
- Where Google user data is processed by AI (sections 3), it is used solely to provide the feature you requested and is not used to develop, improve, or train generalized AI/ML models.
8. Data retention & deletion
- Local data stays on your device until you delete it in the app or remove the app's data directory and the Vault folder.
- Synced data in Supabase is retained until you delete the corresponding items or request account deletion.
- AI providers retain transient request data per their own policies; we do not retain the content of AI requests beyond what is needed to return your result.
To request access to, or deletion of, your account and synced data, email dolli.support@gmail.com. You can also revoke Dolli's access to your Google account at any time at https://myaccount.google.com/permissions.
9. Your rights
Depending on where you live (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights, contact dolli.support@gmail.com. We will respond within the timeframes required by applicable law.
Our legal bases for processing (where GDPR applies) are: performance of our agreement with you (providing the app), your consent (Google access, optional sync, optional telemetry), and our legitimate interests (securing and improving the service).
10. Security
Local data is protected by your macOS user account and the operating system's file permissions. Network traffic to our services and AI providers is encrypted in transit (HTTPS/TLS). No method of storage or transmission is 100% secure; we cannot guarantee absolute security.
11. Children
Dolli is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect their personal data.
12. International transfers
Our service providers (Anthropic, OpenAI, Cloudflare, Supabase, Google) may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
13. Changes to this policy
We may update this policy. Material changes will be reflected by updating the "Last updated" date and, where appropriate, an in-app notice.
14. Contact
Questions or requests: dolli.support@gmail.com Data controller: the developer of Dolli, reachable at the address above