# Privacy and security

> A plain-language guide to the permissions Dotless uses and the controls available to workspace owners.

Canonical: https://www.dotless.co/docs/privacy-and-security

## Permission boundaries

| Connection | Access used by Dotless | Access not requested |
| --- | --- | --- |
| Gmail | Basic account identity and email sending. | Mailbox reading, reply monitoring, deletion, or message management. |
| Outlook | Basic Microsoft identity, offline access, and email sending. | Mail.Read or Mail.ReadWrite. |
| SMTP | Sender configuration supplied by the workspace owner. | Access to unrelated provider account data. |
| CRM integrations | The record scopes described in each provider guide. | Importing the whole CRM or syncing CRM-side edits back into Dotless. |

**AI assistant.** Relevant chat and workspace information is processed to answer your request or perform an authorized action. Review generated content and the action settings. Settings lets you edit or remove saved memories; personal memories and shared workspace preferences have different scopes. Voice recordings are sent for transcription, and you can review the text before sending.

**History and feedback.** Chat history is saved in this browser until you delete it or clear site data; signing out does not clear it. Rating an answer sends Dotless the conversation through that answer and any comment. Removing the rating deletes that feedback record. Feedback chat copies are cleared after 90 days from their last update. Deleting a local chat does not remove saved memories, action records, or changes already made in the app.

**Client email and websites.** Replies or forwards sent to a Dotless client-chat address are processed separately from send-only Gmail, Outlook, or SMTP connections. Website forms, reports, public reviews, and hosting can process customer or visitor data. Domain registration sends required business contact details to registration providers. See the [Privacy Policy](https://www.dotless.co/privacy) for recipients, retention, and controls.

## Lead and prospect data

Dotless is designed around business information and publicly available business or professional contact data. Availability does not make every use lawful or appropriate. You are responsible for the purpose, audience, message, opt-out handling, and applicable rules.

Locked email and phone values remain excluded from CRM sync until a user chooses to unlock them.

## Connection control

- Only the workspace owner can create or remove supported CRM connections.
- Disconnecting removes stored CRM authorization and pending sync work from Dotless.
- Existing records in an external CRM are not deleted automatically.
- OAuth access can also be revoked from the provider’s connected-app settings.
- Never share provider secrets, access tokens, refresh tokens, or passwords with support.

## Policies and requests

- Privacy Policy
- Prospect Privacy
- Data Processing Addendum
- Subprocessors
- Security and vulnerability reporting
- Terms of Use
