Legal

Privacy Policy

This policy explains what stays on your Mac, what is sent when you use network features, and the choices available to you.

Effective
Version
2026-08-08

1. Who is responsible

Happy Coder Industries Limited is responsible for Dogger’s handling of personal data as controller where applicable. We are an English private limited company, number 14121168, with registered office at Unit 2 Beverley Court, 26 Elmtree Road, Teddington, England, TW11 8ST.

For privacy questions or rights requests, email [email protected].

2. Data kept locally

Dogger is primarily local software. It keeps the following data on your Mac rather than in a Dogger cloud account:

  • settings and window state in ~/.dogger/config.json;
  • project, context, task, script, resource, run-history, and AI conversation data below ~/.dogger;
  • shared-source repository checkouts, staged and approved revisions, review state, and local context bindings below ~/.dogger;
  • telemetry consent and a random installation identifier in local configuration, plus separate bounded telemetry and feedback delivery queues below ~/.dogger/offline/queues;
  • provider-neutral AI token-usage records, without prompts or responses, below ~/.dogger/usage;
  • the Premium licence key in macOS Keychain, with non-secret plan, purchaser-display, and validation metadata in local configuration; and
  • the website-view zoom percentage in the macOS webview’s local storage.

The current OpenAI API token is stored verbatim in the local configuration file and can be returned to Dogger’s desktop interface for editing. Protect access to your macOS account and local files. Dogger does not receive this token except as part of provider-bound requests described below.

Dogger does not automatically upload local projects, tasks, histories, or settings to us. Tasks you choose to run are programs and may access data or networks independently of Dogger’s product-controlled flows.

3. Purchases and licence validation

Happy Coder Industries Limited sells Dogger Premium. The purchase form sends the name, email address, and selected Lifetime or Yearly product, plus any discount code you choose to apply, to Dogger. Dogger stores the order details, applicable GBP price and licence-length snapshot, discount terms, and temporary or completed discount-use record. For a paid order, Stripe processes payment through its hosted Checkout under Stripe’s own terms and privacy practices. Stripe is a payment processor, not the merchant of record for Dogger. If Dogger provides a discounted licence without taking payment, no checkout or buyer data is sent to Stripe.

A signed Stripe webhook confirms paid fulfilment; Dogger’s server authorizes free discounted fulfilment. Dogger stores the purchaser name, normalized email, product and terms, pricing and discount snapshots, timestamps, status, and nullable Stripe order/payment references. It stores only a keyed hash and short support prefix for the licence key, not the full key. Resend receives the recipient address and licence email content so it can deliver the key.

When you enter or retain a Premium key, Dogger sends that key to doggerapp.com. Our server hashes it and checks Dogger’s licence database, returning only whether it is valid, a display customer name, and the Premium plan. We do not create a device instance identifier or impose an activation limit. Validation is necessary to provide and protect the Premium licence contract.

Recent validation can be reused for 24 hours. Stale credentials are checked at startup and periodically. Temporary failures do not expire a previously confirmed entitlement while its Keychain credential remains available; a confirmed rejection or Logout revokes Premium access immediately without deleting local project data.

4. AI features and OpenAI

OpenAI is the only currently supported AI provider. You supply your own API token, and requests are made under your OpenAI account. OpenAI’s terms, charges, controls, and retention practices apply independently.

  • Token test: sends the entered token to OpenAI’s models endpoint.
  • Dictation: sends the recorded audio clip, derived file name and media type, and transcription model.
  • Task generation: may send task name, configured paths and runtime, prompts, attached images, prior conversation, the current task’s existing files, optional container-context AI instructions when set, and bounded codebase or current-task files requested by the model. It does not send other tasks’ files from the project. This flow does not apply Dogger’s shared credential redactor.
  • Failed-run explanation: sends bounded run metadata and output, conversation, and model-requested bounded codebase reads/searches. Dogger applies pattern-based redaction for the configured OpenAI token and common credential forms, but cannot guarantee removal of every secret or personal value.
  • Cancelled-run analysis: is off by default. If you enable it, cancellation may send task metadata, command, output, task files, and local Git status/diff evidence. This flow does not currently apply the shared credential redactor.

Use these features only with content you are authorised to send. Disable cancelled-run analysis or do not invoke an AI action when you do not want its described context sent.

5. Shared task sources and Git hosts

Premium shared task sources are opt-in and do not synchronize automatically. When you explicitly clone, pull, or push, the selected Git host receives the repository request, authentication material supplied through your configured Git or SSH credential facilities, and the repository content involved in that operation. The Git host’s terms, access controls, logs, and retention apply separately.

Dogger stores the source checkout and review state only below ~/.dogger. Incoming revisions remain staged until you review and approve them. Commits and pushes are separate explicit actions. Dogger does not add private tasks, tags, annotations, run history, project or context membership, host paths, runtime references, local execution trust, credentials, or application settings to a shared repository.

Removing a source deletes its local checkout and binding records. It does not delete remote repository content, private tasks, local task snapshots already made available, or their run history.

6. Optional telemetry and explicit feedback

Product telemetry is off by default. If you explicitly enable it, Dogger records coarse events about application starts, use of named product features, and completed operations with success, failure or cancellation and a broad duration bucket. We use these events to understand feature adoption and improve product reliability.

Telemetry includes the Dogger version, macOS platform, optional processor architecture, the applicable schema and policy versions, and a random installation identifier. The identifier is generated by Dogger and is not derived from hardware, an account, a licence key, a path, or other user data.

Default telemetry does not include task names or content, scripts, arguments, terminal output, logs, prompts, responses, file or repository paths, container names, licence keys, API credentials, feedback text, contact details, or other secrets. Dogger builds events from a closed allowlist rather than serialising application state.

You can review or change telemetry consent at any time under Connected Services. Disabling it stops new collection; you can separately discard telemetry still queued on your Mac. A changed schema or policy requires a current explicit choice before collection resumes.

In-app feedback is separate from telemetry and is sent only after you review the exact payload and choose Send. You may optionally provide an email address for a reply. App version and operating-system diagnostics are individually disclosed and off by default. Feedback is pattern-redacted before it is queued, but you should still avoid including secrets or personal data that are not needed for your request.

When the service cannot be reached, consented telemetry is queued locally for up to 30 days and feedback for up to 90 days, subject to item-count and size limits. Delivery retries in the background and does not block local task workflows. Accepted submissions use random idempotency identifiers to avoid duplicate storage.

Our server validates strict bounded payloads and applies abuse controls. It does not store request IP addresses; a keyed, short-lived digest may be used for rate limiting. Telemetry is retained for up to 90 days and shown to operational administrators only as aggregate daily product metrics that meet a minimum distinct-installation threshold. Feedback is retained for up to 365 days and is available only for feedback triage. Administrator access uses a locally managed operational username and hashed password, short-lived secure sessions, and audited access and status changes; it is not a Dogger end-user or Premium account.

7. Website, updates, and support

  • The website and its HTTPS infrastructure process normal request information such as IP address, time, requested path, user agent, and security/diagnostic data. The website does not use a third-party analytics beacon. First-party secure cookies are set only for operational administrator sessions when that area is enabled.
  • If trusted-proxy rate limiting is enabled, a SHA-256 hash of the connecting address is held in process memory. Checkout windows last ten minutes; discount preview and licence-validation windows last one minute. Entries are then removed on cleanup, capacity eviction, or process restart.
  • Update checks and downloads contact GitHub Releases or, for Homebrew installations, Homebrew and its GitHub-backed package infrastructure. These services receive ordinary network request information. Dogger does not add an end-user account identifier.
  • If you email support, we receive the address, message, and attachments you choose to send. A public GitHub issue is visible according to GitHub’s settings and policies.

8. Why we use data

Depending on the activity, we process data to:

  • perform the software, Premium, purchase-support, and validation contracts you request;
  • pursue legitimate interests in securing, operating, troubleshooting, and preventing abuse of the website and licence service;
  • process optional telemetry with your consent to improve Dogger, and handle feedback you explicitly submit to respond and plan improvements;
  • answer support and rights requests; and
  • meet legal, tax, accounting, or dispute obligations.

Optional AI actions occur only when you configure or invoke the relevant feature. Product telemetry remains disabled unless you allow it, feedback is sent only after review and confirmation, and shared task source network actions occur only when you explicitly request them.

9. Recipients and international processing

Data may be handled by providers needed for the activity: Stripe for payment processing; Resend for licence email; OpenAI for the AI actions you choose; GitHub and Homebrew for releases and updates; the Git host you select for a shared task source; and our website-hosting, PostgreSQL database, reverse-proxy, deployment, email, and support infrastructure providers. Operational administrators may access feedback and thresholded aggregate metrics only for the purposes described above. Administrator sign-in credentials are stored locally as a password hash on our website database and are not verified by an external identity provider.

Some providers may process data outside the United Kingdom. Their own terms and privacy notices explain their locations and safeguards. We use providers for the stated purposes and do not sell personal data.

10. Retention and deletion

  • Local Dogger data has no automatic age-based expiry. It remains until you delete the relevant item or local Dogger data. Deleting a task or project removes its nested history, but separately stored AI usage records are not automatically removed with it.
  • Logout removes the saved Premium credential and entitlement metadata, not projects, tasks, settings, or history.
  • Shared-source caches and bindings remain until you remove the source or local Dogger data. Removing a source does not remove remote content or local task snapshots and histories.
  • Local telemetry queue items expire after 30 days and local feedback queue items after 90 days. You can discard queued telemetry immediately from Connected Services. Submitted telemetry is deleted after 90 days and submitted feedback after 365 days under the normal retention schedule.
  • Support emails are normally deleted 12 months after the request closes, unless they are still needed for an active dispute, security matter, or legal obligation.
  • Dogger retains order and licence records while needed to provide and administer the licence, handle refunds or disputes, support accounting, and meet legal obligations. A refund or dispute can revoke the linked licence. Product-data retention remains separate; rate-limit buckets are removed after their short abuse-control window and by the daily retention job.
  • External providers retain data under their own policies and account controls.

11. Your rights

Depending on applicable law, you may ask us for access, correction, deletion, restriction, objection, or portability of personal data we control, and may withdraw consent where consent is the basis. We may need to verify your request and may retain information where law permits or requires it.

Email [email protected] to exercise a right. You may also complain to the UK Information Commissioner’s Office or your local supervisory authority. Local data on your Mac is ordinarily controlled directly by you and may not be available to us.

12. Security and contact

We use measures appropriate to Dogger’s current architecture, including macOS Keychain for the Premium key, bounded server and Git operations, review-gated shared-source adoption, allowlisted product-data schemas, least-privilege database roles, protected administrator sessions, no-store API responses, and redaction before feedback queue writes and on the failed-run explanation path. No system is completely secure; review the feature-specific limits in this policy.

Questions about this policy can be sent to [email protected]. The related software terms are available in our Terms of Service.

Revision history

  • 2026-08-08 8 August 2026: Added discount records, conditional Stripe disclosure, and server-authorized free fulfilment.
  • 2026-08-07 7 August 2026: Updated Stripe payment, Dogger order and licence storage, validation, and Resend fulfilment flows.
  • 2026-08-03.3 4 August 2026: Added opt-in product telemetry, explicit feedback, bounded delivery queues, service retention, user controls, and locally managed operational administrator credentials.
  • 2026-08-03.2 3 August 2026: Added explicit shared-source Git flows, local caches, controls, and retention; updated offline Premium continuity.
  • 2026-08-03 3 August 2026: Initial publication.

We will update this page and its effective date when the policy changes. For a material change, we will provide additional notice through an appropriate website, product, purchase, or direct-contact channel where reasonably required.