Privacy Policy

Last updated: February 21, 2026

1. Introduction

dotty ("we", "us", "our") operates the dotty.bot website and the dotty CLI agent. This Privacy Policy describes how we collect, use, and protect your information when you use our service.

2. Information We Collect

Account Information: When you register, we collect your email address and phone number. Your phone number is used for verification codes and optional session notifications via SMS or voice calls.

Usage Data: We collect information about your interactions with the service, including call duration, session metadata, and feature usage. This helps us improve the product and enforce usage limits.

Call Transcripts: Voice calls made through dotty are transcribed for the purpose of providing the AI assistant experience. Transcripts are stored in your account and are not shared publicly unless you explicitly use a public demo call (which does not require an account).

API Keys: If you use the Bring Your Own Key (BYOK) feature, your third-party API keys are encrypted at rest and are only used to make requests on your behalf. We never log or share your API keys.

3. How We Use Your Information

  • To provide and maintain the dotty service
  • To send verification codes via SMS during account setup
  • To send session status updates and notifications you have opted into
  • To authenticate you when you call your dotty phone number
  • To enforce usage limits and prevent abuse
  • To improve the service based on aggregate usage patterns

4. SMS and Voice Communications

By providing your phone number and verifying it, you consent to receive:

  • One-time verification codes during account setup and phone changes
  • Session status updates (task completed, blocked, errors) if you have notifications enabled
  • Responses to SMS commands you send to the dotty number

You can opt out of SMS notifications at any time by replying STOP to any message, disabling notifications in your dashboard settings, or by texting "quiet" to the dotty number. Message and data rates may apply. Message frequency varies based on your coding session activity.

5. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not sell, share, or rent your phone number or SMS opt-in consent information with any third parties or affiliates for marketing or promotional purposes. Your phone number and opt-in data are used exclusively by dotty and shared only with our SMS service provider (Twilio) solely for the purpose of delivering messages you have opted into. We use the following service providers to operate dotty:

  • Twilio — phone calls and SMS delivery
  • ElevenLabs — speech-to-text and text-to-speech
  • Anthropic — AI assistant (Claude)
  • Supabase — database and authentication
  • Stripe — payment processing
  • Vercel — website hosting

Each provider only receives the minimum data necessary to provide their service.

6. Data Security

We implement reasonable security measures to protect your data, including:

  • Encryption of sensitive data at rest (API keys, PINs)
  • HTTPS for all communications
  • Hashed and salted caller identification
  • Rate limiting on authentication endpoints
  • Timing-safe comparison for authentication tokens

7. Data Retention

Account data is retained as long as your account is active. Call transcripts and session data are retained for up to 90 days. You can request deletion of your account and associated data by contacting us.

8. Your Rights

You can:

  • Access your data through the dashboard and API
  • Update your phone number and preferences at any time
  • Opt out of SMS notifications
  • Request deletion of your account
  • Revoke API keys at any time

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the service. Your continued use of dotty after changes constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions or requests, contact us at privacy@dotty.bot.

Terms of Service | Home