Privacy
A private AI assistant that keeps your data on your Mac
OpenDot stores everything in plain files on your Mac, masks personal details before a cloud model sees them, and asks before it does anything that changes the world.

Your data lives in a folder you can open
Everything OpenDot knows is stored in ~/.opendot on your Mac, as plain files you can read. Settings, each Dot's identity and memory, chat transcripts and the audit log are ordinary JSON and JSONL files. There is no account to create and no OpenDot server that holds your conversations.
Each Dot also gets its own workspace folder, and that is the only folder its file tools can touch, plus any folders you add yourself. Deleting a Dot moves its folder to ~/.opendot/trash/ rather than erasing it.
Personal details are masked before a cloud model sees them
When a Dot uses a cloud model, OpenDot first replaces personal details with placeholders and restores them locally when the answer comes back. A message that says "Send the invoice to maya.chen@example.com" reaches the model as "Send the invoice to ⟦EMAIL_1⟧".
In Settings, Privacy, you choose what gets masked. The options include email addresses, phone numbers, card numbers, bank accounts (IBAN), social security numbers, IP addresses, API keys and tokens, and passwords in links. Names and street addresses are available too, and there is an experimental name detector. You can also add your own terms, which are always masked.
A "Try it" box in the same screen shows exactly what the model would see, so you can test the rules before you rely on them.

Local models keep thinking on your Mac
Masking applies to what is sent to cloud models. If you run a model on your Mac through Ollama, LM Studio, llama.cpp or vLLM, the Dot's thinking never leaves your machine at all. Dots that read Gmail, Outlook or other online services still need a connection to reach them, but that traffic goes straight from your Mac to the service.
Anything risky asks first
Every tool a Dot can use is set to Allow, Ask or Block, per tool. When a Dot wants to do something that changes the world, like sending an email, deleting a file or paying for something, an approval card appears with three choices: Allow once, Always allow or Deny.
Dot Links add a second layer. They are permission rules between Dots: which Dot may message which, on what schedule, how often and whether you approve each message. Every message between Dots is logged.

Keys and tokens stay in the Keychain
API keys and OAuth tokens are encrypted with the macOS Keychain. Google and Microsoft sign-in use your own OAuth client, so your mail and calendar never pass through anyone else's app. The audit log records what Dots did without storing message contents.
Open source, so you can check
OpenDot is MIT licensed and the source is on GitHub. If you want to know exactly what leaves your Mac, you can read the code instead of taking our word for it.
Frequently asked questions
Does my data leave my Mac?
Not by default. Everything lives in ~/.opendot on your Mac. With a cloud model, only what the model needs to answer is sent, and personal details are masked first. With a local model, the Dot's thinking never leaves your Mac.
Where are my API keys stored?
In the macOS Keychain. OpenDot stores API keys and OAuth tokens encrypted with it.
Can a Dot send an email without asking me?
Only if you allow it. Tools that change things, like sending, deleting or paying, ask for approval first, and you can set each tool to Allow, Ask or Block.
Is OpenDot open source?
Yes. OpenDot is MIT licensed and the source is on GitHub.
