Who we are and what this covers
Blackboard Technologies Inc., based in Toronto, Ontario, Canada, provides Dash Desktop, Dash Web, and Dash Cloud. Contact [email protected] for privacy questions or requests; please put “Privacy” in the subject line.
This policy covers those Dash products. Browsing our marketing site is covered by the Website Privacy Policy. Other products, websites you open in Dash, and independent model or integration providers have their own policies.
Our approach to privacy
We design Dash to keep your work on your devices where possible, encrypt designated private content before it reaches our services, and limit the information and human access needed to operate the product. Some features require readable information to pass through additional services. We explain those differences so you can choose the access you grant.
Dash Desktop works without a Cloud account. Account registration, local use, subscriptions, and individual integrations have different information needs. Accepting the Terms acknowledges this policy; it is not blanket consent to optional marketing, every integration, or unrelated uses of personal information.
What stays local, what is encrypted, and what we can process
| Information or feature | What our services receive or can read |
|---|---|
| Local files, browser profiles, model files, and agent conversations | These are not automatically uploaded as an account backup. Features or integrations you use may transmit selected content. |
| Supported account notes, saved lenses, private directory information, and synced settings | Content is encrypted on an authorized device before upload. Our services store encrypted records and readable synchronization metadata. |
| Supported ordinary device-to-device application traffic | Content is encrypted between participating clients, including when routed through Dash Relay. Our services can process connection and traffic metadata. |
| Local MCP | An authorized client receives tool results from your machine. It may send those results to its own services or providers. A local connection does not itself route tool contents through our hosted MCP endpoint. |
| Hosted Relay MCP | Our hosted endpoint processes authorized tool requests and results in readable form. Those results can include previously local or encrypted content. The external client also receives the results. |
| Accounts, subscriptions, operations, and support | Our services can read the information needed for these activities, such as contact details, subscription status, connection metadata, resource counts, and messages you send us. |
The encryption descriptions above apply to the supported features. Encryption does not prevent an authorized recipient, a compromised device, or a service you choose to send content to from reading that content.
Information we receive
Account, billing, and service information
We process your email address, any account name you provide, verification state, account identifiers, authentication records, and account creation and update times. We also process device and session identifiers, connection and authorization information, and technical information needed to authenticate and connect your devices and integrations.
When you register for Dash Cloud, we record the versions of the Terms and Privacy Policy presented with your agreement and when the service received it. Desktop’s initial agreement is recorded locally on your machine and is not uploaded as an account agreement record.
For paid accounts, we store Stripe customer and subscription identifiers and relevant plan, payment, renewal, cancellation, and entitlement information. Payment and billing details entered in Checkout are handled by Stripe and Link. Our integration does not ask you to send full card numbers or card security codes to Dash. Stripe may make customer and transaction information available to us in its dashboard for billing and support.
Cloud connections expose information needed to serve and secure requests, such as IP addresses, request times, connection destinations, and technical request information. Our infrastructure providers may also process network and security logs. Application logs can include error details and operational identifiers.
Usage and resource information
We collect account-level and aggregate operational information such as request and message counts, traffic volume, encrypted-record sizes and counts, connection counts, connection timing, and service errors. We may also receive operating-system and browser names, such as macOS and Chrome, and whether you use Desktop or Web Dash. These measurements help us understand compatibility and reliability, estimate infrastructure costs, manage capacity, and investigate unusual usage or abuse.
These usage reports do not include the URLs you visit, your browsing history, terminal text, file contents, or model prompts. Authorized administrators can view account-level usage statistics, such as the number of megabytes of encrypted traffic sent through Dash Relay, and act on excessive or abusive resource use. These statistics are separate from encrypted customer content. A count or connection status may still reveal that an account is active, and is not treated as anonymous merely because it excludes content.
Encrypted account records
When you use supported account features, your device encrypts the content before uploading it. This includes account notes, explicitly saved lenses, private machine and workspace names and mount information, and supported synced preferences, credentials, and agent instructions, memory, and skills.
Our service stores the encrypted records along with identifiers, sizes, revisions, timestamps, deletion markers, and synchronization metadata. Encryption conceals the document contents, not the existence, approximate size, or timing of activity.
Live tabs and pane sizes are saved locally. Settings sync is not a full copy of your disk: it does not automatically back up repositories, project files, browser cookies and history, bookmark and preload libraries, local model files, terminal sessions, or agent conversation logs.
Support and deliberate submissions
Information you send in feedback, support email, bug reports, or other deliberate submissions is readable by us. Feedback can include your message, app version, platform, and source information. Signed-in feedback is automatically associated with your account ID, email address, and name; a separate contact field may also be available. Only include content you want us to receive; private-account encryption does not extend to an ordinary support message or attachment.
Encryption and its limits
Supported account content is designed to be readable on authorized clients and stored as encrypted content by our services. Ordinary service administration does not provide a way to read it. The normal current registration and sign-in process also protects the original password from disclosure to our service. Authentication records and information needed to coordinate access remain readable service information.
Signed-in clients may remember access across sessions using local or browser storage. The protection available depends on the platform and configuration. Signing out or removing a device is not a guarantee that every local file, cache, backup, or previously shared copy has been erased. Secure the devices and browser profiles that can access your account.
Resetting a forgotten password by email does not, by itself, recover old encrypted content. Keep your recovery information and independent backups: if you lose every means to unlock the content, we may be unable to restore it.
Encryption cannot protect against a compromised unlocked device, someone you authorize to read the data, or maliciously modified client software. Content decrypted by an authorized device can become readable to another recipient when you use an integration such as hosted MCP. We do not describe every category of information as inaccessible to Blackboard.
Local storage and files
Dash stores profile data on your device or in your browser, including local notes, bookmarks, scripts, settings, and account caches. Local storage is not a substitute for disk encryption or a secure vault. The fact that selected account records are encrypted does not mean every local record is protected by your account password.
Project files, downloaded models, browser-engine profiles, platform-app state, terminal data, applied agent instruction files, and agent conversation logs can remain outside Dash’s structured local storage. They are protected by the relevant application and operating-system controls, not automatically by your Dash account password. Someone with access to your unlocked device may be able to access them.
You can use local features without a cloud account. Update checks, downloads, websites, and separately configured integrations still communicate with their respective servers when used.
Remote access, agents, and MCP
Direct and relayed device connections
Supported ordinary device-to-device application traffic is encrypted between the participating clients, whether it travels directly or through Dash Relay. Relay helps establish connections and, when available for your plan, forwards encrypted application traffic. It can observe routing, connection status, timing, and traffic sizes without receiving the normal application payload in readable form. Direct connections can still involve our services for account authentication and coordination.
Authorized devices can receive the content needed for your operations. Removing a device or changing its permissions cannot erase information it already received.
Local and hosted MCP
MCP allows an external coding harness or other client to use the Dash capabilities you authorize. The client and the device performing the operation can read the permitted results. This may include files, notes, command output, bookmarks, or other content that was previously local or encrypted in storage.
Hosted Relay MCP processes content in readable form. Within the permissions you enable on a target device, the hosted service can request operations and receive their results. This can reveal a file, note, command output, or other content after an authorized device reads or decrypts it. Hosted MCP therefore has a different privacy boundary from ordinary encrypted device traffic. Review its disclosure before enabling it and restrict or revoke permissions in MCP settings when you no longer want that access.
Processing content in transit is different from storing it as an account record. The fact that a result passes through hosted MCP does not make it part of encrypted account sync or establish a retention period for it. Operational records, support submissions, and information retained by the external client have their own handling, as described in the retention section below.
A localhost MCP connection reaches a gateway on your machine. The authorized external client receives the information it requests, and any remote operation remains subject to the target’s permissions. The client’s subsequent handling of that information is governed by its provider and your configuration.
Models, tools, and browser scripts
Installed local models run on the machine hosting them. Their prompts and conversations are not sent to a model publisher merely because you installed that model. Remote agent sessions, tools, or external AI providers can send information elsewhere when you use them. A tool can read content, modify files, run commands, use credentials, or contact websites within its permissions.
Running an open-weight model locally does not make the whole task offline or prevent unintended disclosures. Model output can be influenced by instructions in files, websites, or tool results. When you allow a model or agent to act through tools, those permissions determine what it can access or transmit. A project folder alone is not an operating-system sandbox for commands. Review the access you grant, especially for unattended operations and sensitive information.
Model downloads and app updates contact their distribution hosts, which receive normal download request information. Websites opened in Dash can collect information through their own cookies, scripts, forms, and network requests. Preload scripts and extensions you install may also access or transmit website data. Review them before use.
How we limit access and use information
We process information to create and secure accounts, authenticate devices, synchronize encrypted records, route authorized operations, deliver downloads and updates, administer subscriptions, send service emails, answer support requests, investigate faults and abuse, and meet applicable legal obligations.
We restrict access to information available to Blackboard to authorized personnel and service providers who need it to operate and secure the services, provide support, administer billing, investigate abuse, or meet legal obligations. Access is subject to appropriate confidentiality obligations and access controls. Permission to administer the service does not itself enable access to content protected by end-to-end encryption. Authorized hosted MCP operations and deliberate submissions can separately make content readable as described above.
We do not use private files, notes, or agent conversations to train a general-purpose AI model. If you send content to another provider, its own terms determine its uses.
Service providers and other disclosures
Our current core providers include:
| Provider | Role and information involved |
|---|---|
| Cloudflare | Hosts the API, relay, databases, web app, and distribution infrastructure; processes stored records and operational network information for those services. |
| Stripe and Link | Checkout, subscriptions, payment details, merchant-of-record services, transaction support, fraud prevention, and billing records. Their own privacy terms also apply. |
| Resend | Delivers account verification, recovery, and service emails; processes recipient details, message content, and delivery information. |
| Providers you choose | Model hosts, AI services, Git providers, websites, external MCP clients, and other integrations receive the requests and content needed for the features you use. |
Your account authorizations and product choices determine many of these disclosures. We may also disclose information we hold when reasonably necessary to comply with law, protect people and systems, or respond to a valid legal request. This does not by itself make content protected from ordinary service access readable to us.
Blackboard is based in Canada, but hosting, email, payment, and support providers may process information in other countries, including the United States. Information processed abroad may be subject to local laws and lawful access requests. We do not promise Canada-only storage.
Retention and deletion
Encrypted account records are retained to provide synchronization while they remain in your account, subject to deletion and service operation. Metadata needed to coordinate deletions and prevent stale access can remain after content is removed. Devices that are offline may retain cached copies, and recipients may retain information they already received.
Other information has different purposes and retention needs. Account and subscription records support providing and administering the service; usage snapshots and operational records support security, capacity, reliability, and cost management; correspondence supports handling requests. Information passing through a service is not necessarily retained as a document, but readable processing alone is not a promise of zero retention. We aim to retain information only as long as reasonably needed for its purpose, legal obligations, dispute resolution, and appropriate security records.
You can delete your Dash Cloud account in Dash’s account settings. Deletion ends access to the account, cancels any active subscription, and removes or schedules removal of account records, sessions, authorizations, and private account content. Cancelling a subscription alone does not delete your account or its data.
Deleting your Cloud account does not erase your local project files, local browser profiles, third-party accounts, or independent device backups. Cached copies on your devices and information already received by others may remain. Billing records and support or security records may have separate retention needs and legal obligations. Stripe and Link retain or delete information under their own policies.
Your choices and requests
You can use local Dash without an account, pause supported synchronization, remove connected devices or integrations, revoke MCP permissions, and delete supported account content. You can contact [email protected] to request access to or correction of personal information, request deletion, ask about processing, or withdraw consent where consent is the basis for processing. We may need to verify your identity. Withdrawing information necessary for an account feature may mean that feature can no longer operate.
We can provide information we hold and assist with available export tools, but ordinary service administration does not allow us to retrieve the readable contents of protected account records. You can also raise a concern with the applicable privacy regulator, including the Office of the Privacy Commissioner of Canada.
Dash uses browser storage and operating-system storage to keep sessions and local state working. The Mixpanel analytics used on the separate marketing site are not part of the Dash app implementation described here. Optional external websites or integrations have their own tracking behavior.
Optional marketing subscriptions are separate from agreement to the Terms and registration for Dash Cloud. Declining marketing does not prevent an otherwise eligible registration. Account verification, recovery, security, subscription, and material service or legal notices may still be sent when needed for your account or use of the service.
Changes and contact
We will publish an updated policy with its effective date when our practices change. We will give notice of material changes through the application, email where available, or another appropriate channel. Where a new purpose, disclosure, or other change requires additional consent, we will obtain that consent. Continued use or agreement to updated Terms does not, by itself, authorize every new use of personal information or retroactively authorize an incompatible use of previously collected information.
Privacy contact: Blackboard Technologies Inc., Toronto, Ontario, Canada, [email protected].