Privacy Policy
Last updated: 12 September 2026
This describes what we collect and why.
1. What we collect
Account data (email, display name) and the documents you create. When you use AI features, bounded edits send your selected text, surrounding context, and instruction to Google Gemini or, for complex work or fallback, Anthropic Claude. Whole-document and explicitly referenced-document operations send the scope you requested. BYOK sends the requested content to the provider you configure. AI provider keys are encrypted and never logged in plaintext.
2. Analytics
We use Google Analytics 4 Advanced Consent Mode to understand how people find and use DotMD. Before you allow analytics, or after you decline it, analytics storage remains denied and Google receives only content-free cookieless measurement pings. If you allow analytics, analytics storage is granted; Google Analytics identifiers are used only after you allow Product analytics in Settings. Advertising storage, user data, and personalisation remain denied in every state. Events include page and section views, calls to action, signup and login outcomes, aggregated toolbar-control use, Settings sections, and completed or failed product actions.
We use a one-way pseudonymous account identifier to measure activation and retention. We do not include document or folder identifiers, titles, content, selections, prompts, model output, formulas, cell values, names, email addresses, IP addresses, secrets, raw URLs, query strings, error messages, or stack traces in analytics event fields. Like any internet service provider receiving a browser request, Google receives network metadata, including the source IP address, and processes it under Google Analytics terms and controls. Advertising signals and ads personalisation are disabled. Product events are retained for no more than 90 days in our Google BigQuery analytics warehouse; daily aggregate and financial records may be retained longer for cohort, accounting, and legal purposes.
3. Telemetry
Content-free service metrics are enabled by default. These service metrics cover service health, request volume, endpoint latency, status codes, and errors and stay in our AWS environment; they do not include document content, titles, selections, prompts, or model output. Raw error messages and stack traces are never sent to Google. We do not write the content of your documents to logs. In Settings, you can change optional Product analytics.
4. Data residency
Your documents and account data are stored in a single region: the United States (AWS, us-west-2). We do not replicate your content across regions.
If you access DotMD from outside the United States — for example from the EU, the UK, or India — your data is transferred to and processed in the United States. Where required, we rely on appropriate safeguards for that transfer, such as the European Commission’s Standard Contractual Clauses. Contact us if you would like more detail.
5. Data deletion
You can delete any document or your entire account at any time. When you delete your account, your documents are deleted without undue delay and residual copies in backups are removed as those backups expire.
6. AI features and your data
Included DotMD AI uses Google Gemini for eligible bounded edits and Anthropic Claude for complex work or fallback, using DotMD’s key and up to the monthly token allowance in our Terms. BYOK sends the requested content to the provider you configure.
For bounded edits, we send your selected text, its immediate context, and your instruction. Whole-document and explicitly referenced-document operations send the scope you requested. We do not use your prompts or document content to train our own models, and we do not store AI provider keys in plaintext. When you use a third-party model, including via BYOK, that provider’s own terms and privacy practices govern the data you send it.
8. Your choices
You can export or delete your data at any time. In Settings, you can change optional Product analytics. Content-free operational and security metrics needed to run and protect DotMD remain enabled. Contact us at
admin@dotmd.coto exercise your rights.