Privacy overview
How Overshow keeps capture and search on your device, and exactly what leaves your machine.
Last updated: 24 September 2026
Local Processing
Overshow captures and searches your content on your computer. Your personal index stays in a database under your user account. Public Mac builds also run Ask locally. Public Windows builds provide local capture and search, and Ask through an AI provider you set up and consent to. Shipping builds omit meeting recording and carry no text embeddings. Experimental builds can include local meeting transcription or embeddings, and an experimental Mac build can use cloud Ask. Publishing an approved record creates a separate organisation record containing the entries and source excerpts you choose.
You are always in control of what Overshow captures. Pause and resume, exclude applications, and use built-in exclusion categories so the index reflects choices you make in Settings, not a default that assumes everything should be recorded.
Local Storage
Screen activity you choose to record, audio you choose to record, transcripts, on-screen text, search indexes, summaries, and related metadata are handled locally. Overshow does not operate a default cloud pipeline that reads your capture content for product analytics or model inference. Routine licence traffic does not send your screen, audio, or index content to Overshow. It carries sign-in, billing, device registration, and aggregate licence-usage counts. A separate Publish action sends only the approved record and its approved source excerpts to the organisation repository.
Data transfers
These are the routes by which data leaves your computer:
- Authentication. Signing in (for example via OAuth or email magic links) uses app.over.show and identity providers you choose.
- Billing. Subscription and payment handling goes through Stripe when you purchase or manage a plan.
- Licence and device checks. The licence server receives device registration metadata and aggregate licence-usage counts, never captured content.
- Optional calendar sync. If you enable it, calendar connection data is handled with encryption in transit and according to the integration settings you approve.
- Optional cloud mail. If a Microsoft or Google mailbox is connected, messages are fetched over a read-only OAuth grant you approve. Without a grant cloud mail stays inert. See Mail integration for the exact data, local-storage, sharing, and deletion boundaries.
- Cloud Ask. Windows builds, and an experimental Mac build, can send an approved Ask prompt and selected evidence to a provider you configure, after you set it up and give current consent. Secrets are removed first, along with any email addresses, phone numbers and IBANs you choose to scrub, and mail and calendar content from connected accounts is never sent. Retrieval, capture, transcription and embeddings remain local. This consent is independent of approval for connected AI clients.
- AI apps (Mac). If you approve an app through AI apps, a cloud app's queries and the snippets returned to it are processed by that app's provider. A local app (such as a local LLM) keeps everything on your machine. Your consultancy decides which AI connections are permitted, you approve each app, and you can revoke it at any time.
- Other approved clients. A local client you approve under Settings, Connections reads the parts of your history you grant, with secrets removed and every read logged. What it does with them next depends on that client.
- Microsoft 365 Copilot. The organisation connection lets authorised users and agents retrieve published records for the engagements they can access. If you approve your own Copilot connection, it can search your permitted history, including unpublished work, through Overshow's gateway on Cloudflare, which does not store it. On both routes, your organisation's Microsoft 365 keeps the questions, returned excerpts and answers under its policies.
- Teams transcripts. These travel the other way: selected Teams transcripts come into your private history for review and are never published automatically.
- Organisation repository publication. Approval freezes a daily record locally. It does not share it. If you then choose Publish, the approved record, approved source excerpts, and publication audit metadata are stored in the organisation repository for authorised members. Drafts, original sources, window titles, URLs, file paths, device details, mail-derived content, and the rest of the local capture index are not included.
- Optional link enrichment (off by default). If you enable URL enrichment, Overshow fetches titles and metadata for recognised links found in your captures, limited to a per-domain allow-list. The request carries that link's URL to its own site. The fetched metadata is encrypted at rest.
- Files you export yourself. Manual exports, the optional markdown mirror, and the skill bundle write plaintext copies to folders you choose, so a cloud-synced destination moves them off the machine. Diagnostics leave only when you attach them to feedback.
Nothing in that list replaces on-device capture or search. These routes cover account, payment, explicit approved-record publication, and optional integrations, AI connections or exports you enable, not continuous processing of your screen or microphone in the cloud.
Go deeper
- On-device processing: what runs locally and what that means day to day
- Encryption at rest: how sensitive material is protected on disk
- Capture controls: pause, resume, and per-app exclusions
- Mail integration: what cloud and local mail access reads, stores, and shares
- Trust centre: policies and commitments in one place
- Security: how we approach security for the product and infrastructure
Marketing pages such as Trust centre and Security summarise how we think about trust and operations. This documentation focuses on what the desktop app actually does on your machine.