Effective Date: March 8, 2026
Dotos ("Dotos," "we," "us," or "our") provides backend infrastructure and security services for organization-administered workspaces.
This Privacy Policy explains what information Dotos collects and processes directly, and clarifies our role in relation to organizational workspace data.
Dotos operates a user-centered system administered by organizations.
There are two distinct categories of data within the Services:
If you use Dotos through an organization ("Organization"):
If you have questions about workspace data, you must contact your Organization directly.
Dotos collects limited information necessary to:
We act as the data controller for this limited operational data.
We collect only the information necessary to operate and secure the Services.
This may include:
For Organization owners or designated administrators:
To maintain platform integrity, we collect:
These logs are used solely for operational security and system reliability.
We do not use this information for advertising or profiling.
Dotos supports authentication through third-party SSO providers, including Google, Microsoft, Apple, Twitter (X), and Facebook. When you choose to sign in using an SSO provider, we receive limited profile information from that provider to authenticate your identity and create or link your account.
What we receive from SSO providers:
How we use SSO data:
What we do not do with SSO data:
Revoking SSO access:
You may revoke Dotos's access to your SSO account at any time through your provider's account settings (e.g., Google Account > Security > Third-party apps, Microsoft Account > Privacy > Apps and services, or equivalent settings for Apple, Twitter, or Facebook). Revoking access prevents future SSO sign-ins but does not automatically delete your Dotos account or data. To request account deletion, contact [email protected].
Dotos does not independently:
Workspace data is controlled exclusively by the Organization.
We use operational data to:
We do not use operational data for behavioral advertising.
We retain operational data only as long as necessary to:
Workspace data retention is determined by the Organization. Dotos deletes or returns workspace data in accordance with its agreement with the Organization.
We may share operational data with:
We do not sell personal information.
We implement reasonable administrative, technical, and organizational safeguards to protect operational data, including:
No system can guarantee absolute security.
If you use Dotos through an Organization:
For operational data controlled directly by Dotos (such as administrator account information or SSO profile data), you have the right to:
Requests may be directed to:
We may verify identity before responding.
If operational data is transferred internationally, appropriate safeguards are implemented as required by applicable law.
We may update this Privacy Policy from time to time.
Material changes will be communicated appropriately.
For workspace-related matters, please contact your Organization directly.
For operational data matters, you may contact:
Dotos
When you choose to connect your Google account to sync your email signature, Dotos requests permission to manage your Gmail settings (the gmail.settings.basic scope). Dotos uses this access solely to write the email signature you create in Dotos to your Gmail account's send-as settings. Dotos does not read, send, delete, or otherwise access the content of your email messages, your contacts, or any other Gmail data. We store only the authorization tokens required to perform this sync and basic sync metadata (the last sync time and status). You can disconnect at any time from within Dotos, which revokes Dotos's access to your Google account.
Dotos's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.