DashBack to Dash

Privacy Policy

Last updated August 22, 2026

Dash is a private agent workspace that turns information you submit or choose to connect into decision cards, research results, task activity, and actions you ask it to take. This policy explains what information Dash handles, why it is used, where it may be processed, and how you can control or delete it.

Information Dash handles

Account information includes your name, email address, sign-in provider identifier, session information, and account preferences. Connected-source information may include relevant Gmail messages, Google Calendar events, and Apple Calendar events supplied during a scan, including people, dates, locations, links, and message or event content.

Dash also handles information you provide directly, such as prompts, answers, voice input sent for transcription, shared text, links, images, documents, and other files. Your workspace stores decision cards, selected options, running and completed tasks, task steps, generated results and files, learned preferences, and context you choose to add about your goals or routines.

Limited device and service information is used to operate the product, including push-notification tokens, source connection status, scan state, timestamps, request and error records, browser-task state, and basic analytics or diagnostics.

Connected Google services

If you connect Google, Dash requests the profile, Gmail, and Google Calendar permissions shown on Google’s consent screen. It uses them to find relevant decisions and, when a task you choose requires it, to read, organize, send, or update Gmail content and to read, create, update, or remove Calendar events. Google OAuth tokens are encrypted at rest.

Dash’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, or used to train general-purpose AI models.

Optional Apple sources

In Settings, you can choose to connect Reminders, Contacts, Files, Photos, Health, Home, Music, Location, Maps, Weather, Alarms and Motion on your iPhone. Dash uses only sources you enable and the access iOS permits. When you use a connected source for a conversation, relevant data and the result of the requested action are sent to Dash and its AI service providers to answer your request. Files access is limited to the folder you select. Location is requested while the app is open.

Health data is used only for your health and fitness requests. When you connect Health, you allow permitted Health results to be shared with Dash and its AI providers for those requests. You choose the Health data types iOS permits, and can change those permissions in Health or iPhone Settings. Dash does not use Health data for advertising, sell it, or use it for unrelated tasks. Requested Health reads and supported changes, such as logging water intake, run without a separate action confirmation once connected.

Connections are saved separately for each account on each iPhone. Disconnecting stops future access through Dash; it does not revoke the iOS permission, remove information already shared in your conversations, or delete reminders, contacts, files, photos, playlists or alarms you created. Deleting your Dash data clears its connection settings on this iPhone and saved conversation data. You can manage system access in iPhone Settings.

Apple Calendar and shared content

Apple Calendar permission is controlled by iOS. When you choose to scan it, upcoming event data is sent to Dash so it can identify conflicts and decisions. You can turn access off in iPhone Settings.

Content sent through the iOS share sheet is stored with your account so Dash can analyze it and create a task or decision. If you explicitly import selected website sessions from Chrome, only cookies for the domains you choose are transferred to your isolated cloud browser profile. Passwords, bookmarks, browsing history, and unrelated websites are not imported.

Decision cards

A decision card is Dash’s summary of something that may need your attention. Decision cards can contain source context, possible actions, recommendations, and the option you select. Decision cards are unrelated to payment cards, which are handled separately through the Vault.

Vault, passwords, and payment cards

Full usernames, passwords, card numbers, expiry dates, and billing postal codes saved through the Vault are stored in the iOS Keychain on your device and protected by device authentication. Dash’s server stores only the metadata needed to identify a saved item, such as its label, website, username hint, card brand, and last four digits. It does not store the full password or card number.

When a task needs a saved item, you must unlock it using Face ID/password. The secret is encrypted to a one-time recipient and filled directly into the isolated HTTPS browser. It is redacted from AI model context, task logs, screenshots, and generated artifacts. Your CVC (card security code) is requested only when needed for a transaction and is never saved.

How information is used

Dash uses information to authenticate you, operate connected sources, find relevant decisions, research and complete tasks you deliberately start, remember preferences and context you provide or confirm, save your feed and task history, deliver notifications you enable, prevent abuse, troubleshoot failures, and improve reliability and safety.

Dash does not sell or rent personal information, create advertising profiles, or track you across other companies’ apps or websites for advertising.

Service providers and other recipients

Information may be processed by providers needed to operate a feature you use. OpenAI or Anthropic may process prompts and relevant task context for AI inference. Vercel, the configured database host, Inngest, and Apple Push Notification service support hosting, storage, background work, analytics, and notifications. Exa may process research queries, and E2B provides isolated browser and code environments.

Google, Apple, and websites an agent visits may receive information necessary for a sign-in, message, booking, form, purchase, or other action you requested. Providers receive only the information reasonably needed for their role. Information may also be disclosed when required by law, valid legal process, or the need to protect users, the public, or the service.

Retention

Account details, connected-source state, decision cards, task history, preferences, and submitted content are retained while your account is active so your workspace continues across sessions. Short-lived authentication handoffs and one-time secret payloads expire or are deleted after their purpose is complete. Isolated task environments and provider logs follow their configured lifecycle.

Disconnecting sources

You can remove Google from Settings under Connected sources. This stops Gmail and Calendar watches, deletes Dash’s stored OAuth tokens, and asks Google to revoke access. Apple Calendar access can be changed in iPhone Settings.

Deleting your data or account

You can always delete your information from Settings under Account & data. Delete all data disconnects sources and permanently deletes your workspace, history, agent runs, files, learned preferences, notifications, and saved Vault metadata while keeping your account available.

Delete account deletes the same information, deletes your Dash account, and signs you out. When deletion is started from the iPhone app, Dash also deletes Vault entries from that device’s Keychain. Because Keychain items are stored locally, remove Vault items on any other device where you saved them. Information is retained after deletion only when required for legal, fraud-prevention, security, or backup-integrity purposes, and only for as long as that reason applies.

Security

Dash uses encrypted network connections, encrypted Google tokens, restricted service credentials, device-protected Keychain storage, isolated task environments, secret redaction, and confirmation boundaries for consequential actions. No internet service can guarantee absolute security.

Your choices and requests

You may edit your saved context and preferences, disconnect sources, remove individual Vault items, delete all data, or delete your account from Settings. You may also request access to or correction of your information through the developer support contact shown in the App Store listing or on the Google authorization screen.

Children, international processing, and policy changes

Dash is not directed to children under 13 and does not knowingly collect personal information from children under 13. Information may be processed in Canada, the United States, and other countries where Dash’s providers operate. Privacy and government-access rules may differ between countries.

This policy may be updated when the product, providers, or legal requirements change. The date at the top will be updated, and additional notice will be provided when a change materially affects how personal information is collected, used, or disclosed.

Contact

For privacy questions or requests, contact the Dash developer through the support contact shown in the App Store listing or on the Google authorization screen. Include the email address associated with your Dash account so the request can be verified.

PrivacyTerms