Privacy, plainly
Effective 2 October 2026.
Docket runs on your Mac. No server of ours holds your work, and there is no Docket account
and no telemetry. The only host we run that the app talks to is docketmac.com,
which answers one request with a small static file naming the current version. Everything else
the app reaches is somewhere you connected it to, on a credential you made.
You are probably here for one of two reasons: you are deciding whether to trust Docket with your clients' work, or a vendor review of yours needs a policy at a stable URL. Both are answered below, in detail and including the exceptions. Where this page describes a network connection, the authority is the enumerated connection list on the security page, which is checked against a file that ships with this site by a lint that fails a deploy if the two disagree. This page names the categories and points there for the detail, so the list has one home.
1 · What Docket stores, and where
Everything Docket keeps is written as plain JSON files in the app's own data folder on your Mac: the items it gathered, your settings, your meeting recordings and their transcripts. You can open those files in a text editor, back them up, copy them to another Mac and delete them. There is no proprietary database, and nothing is uploaded as a side effect of being stored.
When you were at your Mac, only if you switch that on. At the Mac is off
until you turn it on in Settings. Then Docket stores the start and end of each stretch at the Mac
and away, for 30 days, in presence.json in the same folder. It stores no app name,
window title, web address or keystroke.
Your current frame in the menu bar, only if you switch that on. The menu-bar item is off until you turn it on in Settings. Then the menu bar shows your current frame's name. A meeting title shows in its menu only if you switch that on too. Anyone who can see your screen can read them. It stores nothing beyond its two switches, and it sends nothing.
In which country is your data stored? The one your Mac is in. Docket stores it on your own device, so the answer travels with the machine and there is no copy of it anywhere else to name a second country for. We hold none of it, so we cannot lose it, sell it, be asked to hand it over, or mislay it in a breach of ours.
2 · What leaves your Mac
A stock install that you have connected nothing to reaches two places on its own: the licence check and the update check. Everything else below happens because you connected it or asked for it. Each connection is listed with what it sends on the security page, and these are the categories:
- The tools you connected. Jira, Confluence, Linear, Figma, Miro, Dovetail, your mail server over IMAP, any connector you added from the library (GitHub, GitLab, Asana, Notion and the others the security page lists), and any feed you added. Each one is reached at the address you gave, or the one its connector names, with the credential you gave, and carries the query needed to read your own items plus the comments and changes you sent or approved. Miro, Dovetail, IMAP, the library's connectors and your feeds are read-only. When you open an epic and press Show everyone's, Docket reads that epic's tickets from the same Jira, once.
- Your calendar, which is not a network connection. Calendar events come from your Mac's own calendars through Apple's EventKit. A direct Google Calendar route exists in the code and no stock install can reach it, because Docket ships no Google OAuth client; it opens only if you create one in your own Google Cloud project and write it into your config by hand.
- The AI engine you picked. By default the AI runs on this Mac only. That
is Apple's on-device model, or Ollama on
localhost. An engine is on this Mac only at a loopback address: localhost, ::1 or one starting with 127. Any other address, a .local name included, is an external engine. External engines are your choice, and nothing goes to one until you pick it: an installed Claude CLI, a Claude API key toapi.anthropic.com, a Gemini key togenerativelanguage.googleapis.com, or a custom endpoint at the URL you typed. If your install already used an external engine before this default, we kept the position it had. Section 4 says what is in the prompt. - The licence check.
api.gumroad.com, at most once a day, receiving your licence key, the product id, and a yes or no on whether to count this Mac. We send yes only on the first check for a key on this Mac. Gumroad then adds one to that key's use count. That is how a team licence sees how many Macs use it. Every later check sends no. Not your name, not a device identifier, none of your data. - The update check. One GET to
docketmac.comfor a static file, shortly after launch. Nothing is sent, not even the version you are running: the comparison happens on your Mac after the file arrives. If there is an update, the download comes fromgithub.comand lands onobjects.githubusercontent.com. - The speech model. Once, the first time you record or dictate, from
huggingface.coand the regionalcdn.hf.coaddress it redirects to. Nothing about you is sent, and the model runs on your Mac from then on.
Docket has no analytics, no crash reporting and no telemetry endpoint, so none appears on that list.
Links and the docket command send nothing off your Mac. A
docket:// link or the command can leave a card in Needs you or change the current
frame, and that card is stored in the same data folder as everything else. The browser, launcher
or Terminal you used may keep the text in its own history; that history is the other app's, and
Docket cannot see or clear it.
3 · The credentials you connect with
Every credential Docket uses is yours, and you can revoke it at the vendor at any time without telling us. It never passes through anything of ours, and every read and write happens under your own account, so your workspace's own rules keep applying.
For most connectors you create the credential at the vendor and paste it into Docket. A pasted token carries your own access, so there Docket can see and change exactly what you can.
Figma works differently, and more narrowly. You sign in instead of pasting anything, and Figma shows you a consent screen naming what Docket asked for. Docket asks for five things: who you are, the comments on a file and the right to reply to them, and the file's name and its contents. Only one of those five can change anything, and what it changes is a comment. The sign-in cannot list the files in your team, so Docket reads the files you add to it and any Figma file linked from your issues. Docket cannot edit a design, move a file or touch your team's settings with that sign-in, whatever your own account is allowed to do.
If you want Docket to find the files in your team for you, you can paste a Figma personal access token instead. That token carries your own access, like the pasted token for any other connector, and you can revoke it at Figma whenever you like.
One exception, and it is not secret. Docket ships its own Figma client identifier and client secret inside the app bundle, as desktop apps do: that pair identifies Docket to Figma so Figma can show you a reviewed consent screen naming the app that is asking. It is readable by anyone who unzips the app and it grants access to nothing by itself. A token that reaches your files is issued only when you sign in yourself and approve that screen. That token is yours. It goes in your Keychain with the rest, and you can revoke it at Figma whenever you like.
Docket puts credentials in the macOS Keychain, marked this device
only, so they never sync to iCloud and never restore onto a different Mac from a backup.
You can see them in Keychain Access under the name Docket and delete any of them
there. If your keychain is locked or refuses, Docket says so and keeps working from its config
file instead, which is readable only by your own user account.
What the Keychain does not do: it does not hide a credential from another program running as you. We measured that: the macOS
security command reads a Keychain item in plaintext with no prompt, with or without
an access list naming only our own binary. Nothing on macOS prevents it short of sandboxing, and
Docket cannot be sandboxed because system-wide dictation needs Accessibility.
Docket takes no token from another tool's config file. It uses only the credentials you enter or sign in with. If you also use Anthropic's Claude CLI, Docket looks in that tool's config for the names of the servers set up there, to tell you whether a connector can work through it. It reads no credential from that file and never changes it.
4 · Meetings, audio and transcripts
Docket can record a meeting on your Mac and transcribe it there. The audio never
leaves. Transcription runs on your own machine with the speech model you downloaded once. The recording and the transcript are files in the same data folder, so
deleting one is deleting a file. Your meeting recipes are one more file there, recipes.json.
What a recipe writes is kept beside the meeting's transcript and is deleted with it.
What can leave is text, and only when you ask for a draft. By default the AI runs on this Mac only. External engines are your choice, and once you pick one, the text of your request goes to that engine and to nothing else. The Sensitive box starts ticked for every recording, and a meeting marked sensitive stays on this Mac whatever that setting says. The AI engine card in Sources names the engine that answered your last request, and names any engine that was handed the prompt even if it did not answer.
5 · This website
docketmac.com is a static site, separate from the app. It sets no cookie of ours, loads no analytics and carries no advertising tag. Three services are involved, and this is what each receives:
- Vercel hosts the pages. Its servers see what any web server sees: the page you asked for, your IP address, your browser's user agent, and the time. We add no tracking of our own on top of it.
- MailerLite holds the release-notes list. The footer form posts your email address to MailerLite, who store the list and send the mail. Nothing else on the page is sent, and one click in any of those emails removes you.
- Gumroad is the merchant of record for the purchase. You buy from Gumroad, who take the payment and hold the card details; we never see a card number. As the seller we see what Gumroad shows a seller about a sale, including the buyer's email address, and we use it to answer you and to support your licence. The app's daily licence check goes to the same company, carrying the key, the product id and whether to count this Mac, as section 2 says.
We do not sell your data and we do not profile you. We have almost none of it. There is no data-processing agreement to sign, because your work never reaches us to be processed.
6 · Getting your data out, and getting rid of it
Export everything in Settings writes the lot to a file you keep, and it keeps working whether or not your subscription does. Deleting the data folder deletes your data: there is no second copy here to ask us about and no request form to fill in, because nothing on our side holds your data. Removing a connection removes its credential from your Mac; revoking that credential at the vendor is the other half, and only you can do it.
Delete all, under At the Mac in Settings, removes every time it noted, at once and for good.
7 · Questions
Mail hello@docketmac.com with anything about this page or about your data. Docket is built and answered by one person, so replies are sometimes slow. If something here turns out not to match what the app actually did, say so: either the words are wrong or the behaviour is, and both are ours to fix.
8 · Changes to this page
This policy is effective 2 October 2026. When it changes, the effective date above changes with it, the change is named in the release notes, and the previous wording stays in the repository history. We do not edit this page quietly.
That is the whole policy. If you want the detail behind it, the security page enumerates every connection the app can make and shows you how to check it against your own firewall, and the FAQ answers what happens to your work if you stop paying or if we stop building. When you are ready, buy Docket.