← Docket

Privacy, plainly

Effective 2 October 2026.

Docket runs on your Mac. No server of ours holds your work, and there is no Docket account and no telemetry. The only host we run that the app talks to is docketmac.com, which answers one request with a small static file naming the current version. Everything else the app reaches is somewhere you connected it to, on a credential you made.

You are probably here for one of two reasons: you are deciding whether to trust Docket with your clients' work, or a vendor review of yours needs a policy at a stable URL. Both are answered below, in detail and including the exceptions. Where this page describes a network connection, the authority is the enumerated connection list on the security page, which is checked against a file that ships with this site by a lint that fails a deploy if the two disagree. This page names the categories and points there for the detail, so the list has one home.

1 · What Docket stores, and where

Everything Docket keeps is written as plain JSON files in the app's own data folder on your Mac: the items it gathered, your settings, your meeting recordings and their transcripts. You can open those files in a text editor, back them up, copy them to another Mac and delete them. There is no proprietary database, and nothing is uploaded as a side effect of being stored.

When you were at your Mac, only if you switch that on. At the Mac is off until you turn it on in Settings. Then Docket stores the start and end of each stretch at the Mac and away, for 30 days, in presence.json in the same folder. It stores no app name, window title, web address or keystroke.

Your current frame in the menu bar, only if you switch that on. The menu-bar item is off until you turn it on in Settings. Then the menu bar shows your current frame's name. A meeting title shows in its menu only if you switch that on too. Anyone who can see your screen can read them. It stores nothing beyond its two switches, and it sends nothing.

In which country is your data stored? The one your Mac is in. Docket stores it on your own device, so the answer travels with the machine and there is no copy of it anywhere else to name a second country for. We hold none of it, so we cannot lose it, sell it, be asked to hand it over, or mislay it in a breach of ours.

2 · What leaves your Mac

A stock install that you have connected nothing to reaches two places on its own: the licence check and the update check. Everything else below happens because you connected it or asked for it. Each connection is listed with what it sends on the security page, and these are the categories:

Docket has no analytics, no crash reporting and no telemetry endpoint, so none appears on that list.

Links and the docket command send nothing off your Mac. A docket:// link or the command can leave a card in Needs you or change the current frame, and that card is stored in the same data folder as everything else. The browser, launcher or Terminal you used may keep the text in its own history; that history is the other app's, and Docket cannot see or clear it.

3 · The credentials you connect with

Every credential Docket uses is yours, and you can revoke it at the vendor at any time without telling us. It never passes through anything of ours, and every read and write happens under your own account, so your workspace's own rules keep applying.

For most connectors you create the credential at the vendor and paste it into Docket. A pasted token carries your own access, so there Docket can see and change exactly what you can.

Figma works differently, and more narrowly. You sign in instead of pasting anything, and Figma shows you a consent screen naming what Docket asked for. Docket asks for five things: who you are, the comments on a file and the right to reply to them, and the file's name and its contents. Only one of those five can change anything, and what it changes is a comment. The sign-in cannot list the files in your team, so Docket reads the files you add to it and any Figma file linked from your issues. Docket cannot edit a design, move a file or touch your team's settings with that sign-in, whatever your own account is allowed to do.

If you want Docket to find the files in your team for you, you can paste a Figma personal access token instead. That token carries your own access, like the pasted token for any other connector, and you can revoke it at Figma whenever you like.

One exception, and it is not secret. Docket ships its own Figma client identifier and client secret inside the app bundle, as desktop apps do: that pair identifies Docket to Figma so Figma can show you a reviewed consent screen naming the app that is asking. It is readable by anyone who unzips the app and it grants access to nothing by itself. A token that reaches your files is issued only when you sign in yourself and approve that screen. That token is yours. It goes in your Keychain with the rest, and you can revoke it at Figma whenever you like.

Docket puts credentials in the macOS Keychain, marked this device only, so they never sync to iCloud and never restore onto a different Mac from a backup. You can see them in Keychain Access under the name Docket and delete any of them there. If your keychain is locked or refuses, Docket says so and keeps working from its config file instead, which is readable only by your own user account.

What the Keychain does not do: it does not hide a credential from another program running as you. We measured that: the macOS security command reads a Keychain item in plaintext with no prompt, with or without an access list naming only our own binary. Nothing on macOS prevents it short of sandboxing, and Docket cannot be sandboxed because system-wide dictation needs Accessibility.

Docket takes no token from another tool's config file. It uses only the credentials you enter or sign in with. If you also use Anthropic's Claude CLI, Docket looks in that tool's config for the names of the servers set up there, to tell you whether a connector can work through it. It reads no credential from that file and never changes it.

4 · Meetings, audio and transcripts

Docket can record a meeting on your Mac and transcribe it there. The audio never leaves. Transcription runs on your own machine with the speech model you downloaded once. The recording and the transcript are files in the same data folder, so deleting one is deleting a file. Your meeting recipes are one more file there, recipes.json. What a recipe writes is kept beside the meeting's transcript and is deleted with it.

What can leave is text, and only when you ask for a draft. By default the AI runs on this Mac only. External engines are your choice, and once you pick one, the text of your request goes to that engine and to nothing else. The Sensitive box starts ticked for every recording, and a meeting marked sensitive stays on this Mac whatever that setting says. The AI engine card in Sources names the engine that answered your last request, and names any engine that was handed the prompt even if it did not answer.

5 · This website

docketmac.com is a static site, separate from the app. It sets no cookie of ours, loads no analytics and carries no advertising tag. Three services are involved, and this is what each receives:

We do not sell your data and we do not profile you. We have almost none of it. There is no data-processing agreement to sign, because your work never reaches us to be processed.

6 · Getting your data out, and getting rid of it

Export everything in Settings writes the lot to a file you keep, and it keeps working whether or not your subscription does. Deleting the data folder deletes your data: there is no second copy here to ask us about and no request form to fill in, because nothing on our side holds your data. Removing a connection removes its credential from your Mac; revoking that credential at the vendor is the other half, and only you can do it.

Delete all, under At the Mac in Settings, removes every time it noted, at once and for good.

7 · Questions

Mail hello@docketmac.com with anything about this page or about your data. Docket is built and answered by one person, so replies are sometimes slow. If something here turns out not to match what the app actually did, say so: either the words are wrong or the behaviour is, and both are ours to fix.

8 · Changes to this page

This policy is effective 2 October 2026. When it changes, the effective date above changes with it, the change is named in the release notes, and the previous wording stays in the repository history. We do not edit this page quietly.

That is the whole policy. If you want the detail behind it, the security page enumerates every connection the app can make and shows you how to check it against your own firewall, and the FAQ answers what happens to your work if you stop paying or if we stop building. When you are ready, buy Docket.