PRIVACY
Privacy Policy
Effective August 10, 2026
Dahlia is a macOS meeting transcription and note-taking application. This policy explains what data Dahlia accesses, how it is used and stored, when it leaves your Mac, and how you can manage or delete it.
1. Data Dahlia handles
Meeting data
Dahlia can store audio recordings, transcripts, summaries, notes, screenshots, project information, tags, and application settings. This data is created and kept locally on your Mac and in backups you configure.
Google account and Calendar data
If you connect Google Calendar, Dahlia accesses your Google account identifier, display name, email address, calendar list, and upcoming events from calendars you select. Event data can include the title, description, start and end times, attendance status, event type, calendar and event identifiers, conference link, and Google Calendar link. Calendar access is read-only; Dahlia does not create, edit, or delete calendar events.
Google Drive data
If you connect Google Drive, Dahlia creates and manages a Meeting Notes
folder and Google Docs exported
by Dahlia. Access is limited to files and folders created by, or explicitly used with, Dahlia. Dahlia does not
request access to unrelated Drive files.
Diagnostics
Dahlia may send crash reports, sanitized technical-error categories, and allowlisted short technical context such as the operation category, audio-source category, locale, diagnostic code, and small language-processing counts to Sentry. Automatic network and lifecycle breadcrumb capture and default personal information are disabled, and request, user, and extra fields are removed.
Anonymous usage analytics
Dahlia sends low-frequency workflow events to TelemetryDeck, such as whether recording, transcription, summary generation, or export started, completed, or failed, whether AI chat was used, and whether Dahlia's built-in AI used a Dahlia MCP tool. These events can include fixed categories for transcription mode, audio sources enabled when recording starts, new or continued recording, trigger, destination, failure stage, built-in AI origin, read or write operation, and coarse feature area. For completed recordings, Dahlia also sends the duration rounded to whole minutes and capped at 360 minutes. Dahlia does not collect MCP usage by external clients or send MCP tool names, arguments, or results. TelemetryDeck's SDK also attaches an installation-specific hashed identifier, anonymous session identifier, app and SDK versions, operating-system and device characteristics, language, locale, region, time zone, appearance, and accessibility settings. It also supplies calendar buckets (such as hour and day of week), first-use date, session counts, distinct usage days, and previous and average session duration. Dahlia does not attach meeting content, chat prompts or responses, names, email addresses, file paths, local record identifiers, credentials, or free-form error messages to diagnostics or usage events.
2. How data is used
Dahlia uses data to provide user-facing features you choose, including:
- recording, transcribing, organizing, searching, and displaying your meetings;
- showing your selected upcoming calendars and preparing a meeting from an event;
- associating an event with a meeting and using that context in a summary or AI chat you initiate; and
- exporting a summary to a Google Doc when you request it.
Dahlia also uses the anonymous usage analytics and sanitized technical diagnostics described above to measure feature reliability, investigate failures, and improve product quality.
Dahlia does not sell Google user data, use it for advertising or credit decisions, or use it to train or improve a general-purpose AI model.
3. Storage and retention
- OAuth access and refresh tokens, Google account identifier, display name, and email address are stored as an OAuth session in the macOS Keychain until Google access is disconnected.
- Upcoming Google Calendar events are cached in memory while Dahlia is running.
- When you associate an event with a saved meeting, the event title, description, times, identifiers, and links are stored in Dahlia's active local meeting database and in any database backups you create. The active record remains while at least one saved meeting refers to the event and is removed after the last referring meeting is deleted. Existing backups retain their earlier copy until you delete the backup.
- Selected calendar identifiers and the Drive export folder and account identifiers are stored in local settings. Exported document URLs and identifiers are stored with the related meeting in the local database and in any database backups you create.
- Exported Google Docs remain in your Google Drive until you delete them there.
- The TelemetryDeck SDK keeps a bounded local queue for best-effort delivery. In UserDefaults it keeps recent session details for 90 days and keeps first-use date and cumulative session and usage-day statistics until the application data is removed. Anonymous analytics and diagnostics are retained by TelemetryDeck and Sentry under their respective service policies.
Dahlia does not operate a developer server that receives or stores your Google Calendar events, Google Drive documents, meeting recordings, or transcripts.
4. AI services and other transfers
When you generate a summary, enable automatic summary generation after batch transcription, or use AI chat, Dahlia sends the content required for that request to the AI connection you configured. If the meeting is linked to a calendar event, that content can include the event title, description, start time, and end time. The applicable provider processes that data under your account and its terms and privacy policy. Dahlia does not send Google Calendar data to an AI service merely because you connected your account or viewed your schedule.
When you export to Google Docs, the rendered summary and included images are sent directly from Dahlia on your Mac to Google Drive. Outside the user-facing features described in this policy, Dahlia does not disclose Google user data except as necessary for security purposes or to comply with applicable law.
5. Manage and delete your Google data
-
Stop future access: In Dahlia, open Calendar or Export settings and choose
Disconnect
. Dahlia removes both locally stored Google OAuth sessions and attempts to revoke all Google access granted to Dahlia. Google revocation applies to the whole OAuth project, so disconnecting Calendar or Drive disconnects both services. Dahlia also clears saved Calendar and Drive selection identifiers. If revocation cannot be completed, remove Dahlia from your Google Account's third-party connections page. - Delete saved calendar details: Delete the meetings linked to those events. Dahlia removes a saved calendar event from the active database after no remaining meeting refers to it. Delete any Dahlia database backups separately to remove copies retained in those backups. Removing Dahlia's local app data does not remove backups you exported elsewhere.
-
Delete exported documents: Disconnecting does not delete documents already exported to
Google Drive. Delete those documents or the
Meeting Notes
folder in Google Drive. Delete the related meeting and database backups to remove locally stored document URLs and identifiers. - Review Google access: You can also remove Dahlia from your Google Account's third-party connections page.
6. Security
Dahlia uses Google's OAuth authorization flow with PKCE, HTTPS for Google and AI service requests, macOS Keychain for OAuth credentials, code signing, and macOS access controls. You are responsible for securing your Mac, local backups, Google account, and configured AI accounts.
7. Google API Services User Data Policy
Dahlia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Changes and contact
This policy will be updated when Dahlia's data practices materially change. For general questions or technical reports that do not contain sensitive information, use the public Dahlia issue tracker. The Dahlia maintainers do not receive or store your meeting content or Google user data and cannot access or delete data on your Mac, in your backups, or in your third-party accounts. Manage or delete that data using the steps above. Do not include private meeting content, credentials, or other sensitive information in a public issue.