Privacy Policy

Draft updated: 12 September 2026. This policy accompanies the self-hosted apps subscription launch. Deployment, live payment setup and Store publication are separate steps. Confirm company details before making the policy effective.

Who handles your data

Altitude Digital Solutions Ltd operates the Dotobot account service and is the controller for its account data. Contact support@dotobot.com for privacy questions, access, correction, export or deletion requests. Registered office: [PLACEHOLDER: registered office address]. ICO registration number: [PLACEHOLDER: ICO registration number].

You operate your harness and control the information it stores and sends to the AI providers and connectors you select. Where it processes other people’s personal data, you are responsible for the processing you authorise.

Account and connection sync

The account service processes:

Server access keys are encrypted with AWS KMS, bound to your account and server. The service can decrypt them to return a connection to your authenticated apps. This is not end-to-end encrypted sync. We do not use saved keys to connect to your server as part of linking or synchronisation; reachability checks happen on your device. Link codes contain full bearer keys and should be treated as secrets. Keys, link codes and authentication request bodies must not enter service logs.

Existing hosted accounts can retain their legacy connection copy during the compatibility transition. Newly synced keys use KMS encryption. Removing a saved connection prevents legacy APIs from returning it; account deletion also removes its legacy cloud-held credential copies. The transition does not rotate or change the key stored on your server.

Apps store account tokens and server keys in the device Keychain. Server selection and non-secret preferences are device-local. Cached credentials allow existing connections to continue during account-service outages. Device caches can contain conversation history, drafts, images and other material displayed in the app.

Subscription payments unlock the Mac and iPhone apps; payment status never controls your self-hosted server. The account service does not store or relay your ordinary chats, uploads, bot memory, browser sessions or provider credentials. It does not receive your harness usage ledger. Dotobot has no advertising or tracking analytics and does not sell personal data or use account data to train AI models.

Choosing Report on a message while signed in sends up to 4,000 characters of that message and its context to Dotobot for review, as well as recording diagnostics on your harness. Cloud report records are retained for 180 days unless a legal obligation requires longer. Delivery to the support mailbox is best effort. Automatic diagnostic reports remain on your own harness; they do not upload ordinary conversation transcripts to the account service.

Your server and selected services

Your harness stores chats, files, bot memory, browser sessions, provider credentials, audit records and local usage information. You decide how it is secured, backed up and deleted. Staged computer screenshots normally expire after 72 hours; this is configurable. Deleting an app or account does not delete server data.

AI providers you choose can receive prompts, conversation history, memory, tool results, attached files, screenshots and audio as needed for the features you use. Live voice can connect directly from the app to the selected voice provider. The app asks you to acknowledge this disclosure before enabling AI interaction. Connectors and MCP services receive the data needed for actions you enable. These services have their own terms, retention settings and privacy policies.

Providers and processing locations

Amazon Web Services (AWS) supplies Cognito sign-in, DynamoDB account storage, KMS encryption, Lambda/API Gateway and transactional email. The account service is configured in eu-west-2 (London). Google and Sign in with Apple provide the sign-in methods you choose. Apple Hide My Email may use a private-relay address and a separate identity. Apple processes Store purchases, restores and subscription notifications. Stripe processes website payments and billing management. We receive subscription and payment identifiers/status, but do not collect full payment-card details. Cloudflare delivers the website and public releases; GitHub provides software distribution. Your chosen AI and connector providers receive data as described above. Your own hosting provider hosts your harness; Dotobot does not purchase a VM when you sign up.

Provider processing may occur outside the UK. See the provider’s privacy and transfer information when choosing it. We apply the safeguards required for any international transfers for which we are responsible.

Why data is processed and how long it is kept

We process account and server-directory data to provide the service you request (performance of a contract). Security and operational processing serves our legitimate interests in keeping the service reliable and protecting accounts. We also process information where needed to meet legal obligations. Your consent choices for sharing with selected AI providers are recorded on your device.

Active account and connection records are kept until you remove them or delete your account; subscription expiry alone does not delete them. Billing and transaction records required for accounting, tax or disputes are retained for the applicable statutory period. Apple and Stripe retain payment records under their own policies and legal obligations. Account deletion removes cloud-held server credentials and Cognito identity and cancels a website subscription. Cancel an Apple subscription in your Apple ID settings as well. Partial deletion is retried automatically; contact support if it does not complete. A minimal deletion marker remains to reject stale tokens and prevent reimport. Removed-connection markers contain no bearer key. Operational logs for the new account endpoints are retained for 30 days. Any retained encrypted recovery backups follow the configured AWS recovery window and are not used to resurrect removed accounts. Data already on your server or other devices is controlled there.

A device erases removed connection credentials when it next successfully syncs. Removing a connection cannot revoke an already-cached bearer on an offline device; rotate the linking key on your server if access must be revoked.

Your rights and contact

You may have rights to access, correct, erase or export your data, restrict its processing or object to it, depending on the applicable law. Use Delete account in the app or on your account page for account removal or contact us for other requests. We may verify your identity before acting. You can manage and delete your server data directly.

You can complain to the UK Information Commissioner’s Office at ico.org.uk or your local supervisory authority. We do not make solely automated decisions about you with legal or similarly significant effects. Dotobot is not intended for children under 18.

The Terms of Use explain app subscriptions and self-hosted responsibilities.

Material policy changes will be communicated in the app or through account email where required. Contact: support@dotobot.com.