Who this policy covers
This policy explains how Doppel (“we,” “us,” or “our”) handles personal information through the Doppel Mac app, our website, and our authorization, licensing, and support services. It covers users, purchasers, website visitors, and people contacting us. Contact us at hello@doppelapp.ai about this policy or a privacy request.
Your work library and personal memory are stored and processed on your Mac. We do not receive a cloud copy of that library or your conversations simply because you use Doppel. Connected services, purchases, and information you choose to send us have the separate data flows described in this policy.
When you use Doppel for an employer or another organization, that organization may also set rules for the information you may process. This policy does not replace those rules or the privacy notices of services you connect.
Work content on your Mac
Depending on the sources and permissions you enable, Doppel can process selected files and their metadata, notes, chats, meeting audio and transcripts, calendar information, screen images and on-screen text, browsing history, mail, and information retrieved from connected accounts. These sources may contain personal information about you and other people.
Doppel creates local search indexes, summaries, extracted decisions and actions, and associations between your work to help you search, ask questions, prepare for meetings, and draft work. This personal memory, including its knowledge graph and embeddings, is processed locally. The app’s local AI inference does not send prompts or source content to a hosted AI model. Local context remains on your Mac unless you use a feature that sends it elsewhere or export or share it yourself.
The app may use the name supplied by your macOS account to personalize the interface. It also stores preferences and local trial status. We do not require a Doppel account or payment information to start the local trial.
We do not sell your work content or use it to train shared or general-purpose AI models. Local personalization does not give us access to your library. Backups, device-management tools, or cloud-synced folders that you configure separately may copy local files under their own settings.
No automatic usage telemetry
Doppel does not send us background product-usage analytics, a history of your activity, or automatic crash reports. Local diagnostic logs and usage counters used by the app remain on your Mac unless you choose to share a diagnostic export. We do not use advertising trackers to monitor your work.
This does not mean that the app never makes a network request. Connected features, authorization, license checks, downloads, updates, checkout, and reports you choose to send require the limited information described below. For example, opening checkout sends the selected plan and the feature or screen that prompted the upgrade. Our online services and their hosts also process ordinary request metadata and operational logs; these are distinct from background monitoring of your activity in the app.
Connected accounts and actions
Connections are optional and enabled by you. Doppel includes built-in connectors for third-party services; those connectors are part of our app, even though the connected account is provided by someone else. When you connect an account, Doppel requests permissions for the selected features and may retrieve account identifiers, messages, files, events, issues, or records. Some connectors sync and index supported content locally; others retrieve it on request. An enabled sync can continue in the background until you disconnect it.
Actions such as sending a message, creating a file, posting a comment, or updating a record send the relevant content and destination to the service you choose. The provider receives the requests and content needed for the feature. Most content requests go directly from the app to the provider; they are not routed through a Doppel cloud library. Review an action before authorizing it. A scheduled or previously authorized action may run within the permissions you gave.
Apple Calendar and Reminders access uses macOS permissions and the accounts configured on your Mac. Changes can sync through those accounts, including iCloud, according to your system settings.
If you configure another app to access Doppel through MCP, that app receives the results allowed by the connection you configure. A project-scoped connection can return its brief and source excerpts; broader access must be explicitly configured. The receiving app may send those results to its own cloud services. Its terms and privacy practices apply, and its traffic does not necessarily pass through our servers. Remove the connection in that app to stop its access.
You can disconnect a service in Settings → Integrations and revoke authorization in the provider’s account settings. Disconnecting stops future authorized access through that connection. Disconnecting Gmail, Outlook, Slack, Notion, or Raindrop.io in Doppel also removes that integration’s locally indexed content. Accounts added through Manage sources are separate: remove their selected sources or disconnect those accounts there to remove their imported copies. Saved chats, exports, and content captured through other sources are separate; review those using Doppel’s source and storage controls. Revocation does not retract messages or files already sent to another service.
Google account data
If you connect Google, Gmail permissions support reading and searching messages, drafting replies, and sending approved messages. Google Calendar access supports reading events and identifying meetings. Google Drive access supports finding and reading files and creating files through the app. Access depends on the permissions you grant.
Google-derived content is used for these user-facing features, including local search and AI assistance. We do not use it for advertising, credit decisions, or training general-purpose AI models. We do not sell it.
Doppel’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the user-facing features you request. We do not permit human access except with your affirmative agreement to specific data, where necessary for security or legal compliance, or as otherwise expressly permitted by that policy. Any transfer must also meet those requirements; a business transfer involving Google data requires your prior explicit consent.
To withdraw Google access, disconnect Google in Doppel and review your Google account’s third-party connections. Delete retained imports using the local controls described below.
Other requests that leave the Mac
- Web search and web pages. A web search sends a query to the configured provider—Brave Search when configured, or DuckDuckGo as the fallback. Opening or retrieving a web page contacts its host. Queries can include details from your request; do not include information you do not want sent to that service.
- Weather. A forecast sends a place name for geocoding or latitude and longitude to Open-Meteo. If you request weather for your current location and permit location access, these can be precise coordinates supplied by macOS. You can enter a place instead of granting location access.
- Downloads and updates. Setup downloads model files from Hugging Face and its download infrastructure. Update checks and app downloads contact the release host, currently GitHub. These services receive artifact requests and ordinary connection metadata, rather than your work library.
- Sharing. Exports, approved app actions, and other sharing features make the selected information available to their chosen recipient or tool. That recipient’s handling is outside the local-only processing boundary.
As with other internet services, destinations can receive your IP address, request time, and technical request headers. Their own privacy policies govern their independent handling of requests.
Purchases and licenses
Purchases use Paddle checkout. Paddle handles payment details and acts as the merchant of record. We receive information needed to issue and manage your license, such as your email address, transaction and customer identifiers, purchased plan, subscription status, and payment or refund events. We do not receive your full payment-card details.
Activation and license renewal send signed license material and a device-generated public key or related proof to Doppel’s licensing service. This allows us to validate entitlement and enforce device limits. The device proof is not your Mac’s hardware serial number. Licensing does not send your notes, transcripts, prompts, or local search history.
License checks and refreshes may happen automatically while you use a paid plan. We store license and activation records, including the device public key, activation identifiers, and entitlement status, for license validation, recovery, and device management. Opening the purchase flow also sends the selected plan and an upgrade-context label identifying the feature or screen that led to checkout. That label does not contain the content of your work.
Cloudflare hosts our licensing and OAuth services. License email delivery uses Resend, which receives the recipient address and the message, including license information. Paddle’s checkout and account-management services also have their own privacy notice.
Support and diagnostics
When you contact us, we receive your address, your message, and any attachments you provide. We use them to respond and investigate the issue you raise. We cannot inspect a local library remotely simply because you ask for help; share only the information needed for your request.
Crash reports remain local unless you choose to send a particular report. A sent report can include app and operating-system versions, timestamps, exception details, and stack traces. You can inspect the report before sending it. Exception text may contain contextual information, so review it for sensitive details. Sent reports pass through our Cloudflare Worker and are stored in our crash intake for up to 90 days. There is no automatic background submission of crash reports.
A diagnostic export creates a local archive of technical status, logs, and crash files. It omits settings values and is designed to exclude document content, queries, and transcripts. Error text can still contain contextual details, so inspect the archive before sharing it. Exporting an archive does not send it to us.
Waitlist and launch notifications
If you join the waitlist, we collect the email address you submit, the signup time, and a record of your agreement to receive launch notifications. We store these records in our website’s Cloudflare database. We send a welcome confirmation and notify you when Doppel is available. Resend processes your email address and the message to deliver these emails. We also keep limited delivery records, such as send status and the provider’s message identifier, to prevent duplicate emails and investigate delivery failures. Joining does not create an app account, start a trial, or authorize a purchase.
We do not add waitlist addresses to unrelated marketing lists or use them to track app activity. Use the “Leave the waitlist” link in your welcome email to remove your signup. You can also request deletion by emailing hello@doppelapp.ai from the address you registered. We retain your entry until you withdraw or we finish the launch-notification process, then remove it unless another legal obligation requires retention.
To limit automated submissions, the website derives a short-lived, keyed identifier from the connection’s IP address. It changes every 15 minutes, is kept separately from signup records, and expired identifiers are removed when later submissions are processed. We do not store the raw IP address in the waitlist database or log form contents.
Website and cookies
When you visit the website, our hosting infrastructure handles your request and may process IP addresses, browser information, requested URLs, timestamps, and security or error logs to deliver and protect the site.
We have not added advertising pixels, cross-site marketing trackers, or behavioral analytics to this website. Essential hosting, security, or authentication features may use cookies or similar storage. An access-controlled preview may require the hosting platform’s sign-in; that platform handles its own account and session information.
Contact links open your email service. Following an external link or entering a payment flow also brings the relevant provider’s privacy practices into scope.
Storage, retention, and deletion
Local content: retention depends on your source settings, Storage controls, and deletions. Removing the app itself does not necessarily remove its Application Support files or Keychain entries. A plan downgrade or cancellation does not delete your local library. Source originals and exports you saved elsewhere are separate from Doppel’s retained copies.
Service records: we retain billing and license records as needed to provide the purchase, handle refunds or disputes, prevent fraud, and meet applicable accounting or legal duties. Support correspondence is retained as needed to resolve and document the request. The crash-intake retention period is up to 90 days. A report attached to a support email follows support-record retention rather than the crash-intake timer.
Operational records: retention is limited by the purpose of the record, the service provider’s settings, and any applicable legal requirement. Authorization exchanges are transient in the relay application; associated request and error logs can remain in the hosting service. We retain operational records only as needed to investigate failures or abuse, protect the service, or meet legal obligations. Contact us for information about a particular record. Disconnecting an account does not itself delete existing billing, support, or security records.
We cannot remotely retrieve or delete a library that exists only on your Mac. Use the app’s controls for that content; contact us if you need help. For information we hold, request deletion using the contact below. We may retain records where law or a legitimate unresolved claim requires it and will explain an applicable exception.
Security and your choices
Doppel uses macOS permission controls, Keychain credential storage, and encrypted transport for its service requests. Local storage remains subject to your device’s security and backup settings; this policy does not promise that every local file is separately encrypted by Doppel. Protect your Mac account and consider macOS FileVault.
You can choose sources, limit capture, pause supported recording features, disconnect integrations, remove retained content, and change macOS permissions. Denying a permission can disable the feature that needs it. No security measure eliminates every risk.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of information we hold, restrict or object to certain processing, withdraw consent, or complain to your data-protection authority. We will handle requests within the periods required by applicable law, verify identity proportionately, and not penalize you for exercising a protected right.
Email hello@doppelapp.ai with “Privacy request” and describe what you need. Do not send your entire work library or payment-card details to verify your identity.
Children and policy changes
Doppel is a work tool and is not directed to children under 13. If you believe a child has supplied personal information directly to us, contact us so we can investigate and remove it where required.
We will update the date on this page when the policy changes. Material changes will be communicated through an appropriate channel, such as an in-app notice, website notice, or email where we have your address. We will obtain new consent before a new use of Google data or other processing where consent is required. A policy change does not authorize an undisclosed use retroactively.
See the Terms of use for product and purchase terms.