Skip to content

Privacy overview

How Overshow keeps capture and search on your device, and exactly what leaves your machine.

Last updated: 30 July 2026

Local-first by design

Overshow is built so that capture, processing, and storage happen on your Mac. Your indexed content and derived artefacts stay in a database on disk under your user account. That is not a slogan: the desktop app runs transcription, text extraction, embedding, and search without sending those payloads to Overshow’s servers for processing.

You are always in control of what Overshow captures. Pause and resume, exclude applications, and use built-in exclusion categories so the index reflects choices you make in Settings, not a default that assumes everything should be recorded.

What stays on your device

Screen activity you choose to record, audio you choose to record, transcripts, on-screen text, search indexes, summaries, and related metadata are handled locally. Overshow does not operate a default cloud pipeline that reads your capture content for product analytics or model inference. The desktop app does not send your screen, audio, or index content to Overshow. The licence server receives only sign-in, billing, device registration, and aggregate licence-usage counts.

The exceptions

Only the following categories move data off your Mac:

  • Authentication. Signing in (for example via OAuth or email magic links) uses app.over.show and identity providers you choose.
  • Billing. Subscription and payment handling goes through Stripe when you purchase or manage a plan.
  • Licence and device checks. The licence server receives device registration metadata and aggregate licence-usage counts, never captured content.
  • Optional calendar sync. If you enable it, calendar connection data is handled with encryption in transit and according to the integration settings you approve.
  • Optional cloud mail. If a Microsoft or Google mailbox is connected, messages are fetched over a read-only OAuth grant you approve; without a grant cloud mail stays inert. Google controls remain hidden from general users while Google OAuth verification is in progress. See Mail integration for the exact data, local-storage, sharing, and deletion boundaries.
  • Approved AI clients (Pro and Enterprise). If you connect an AI client through the read-only Memory MCP integration, a cloud client's queries and the snippets returned to it are processed by that client's provider; a local client (such as a local LLM) keeps everything on your machine. Every client requires explicit consent and approval, and you can revoke it at any time.
  • Optional link enrichment (off by default). If you enable URL enrichment, Overshow fetches titles and metadata for recognised links found in your captures, limited to a per-domain allow-list. The request carries that link's URL to its own site; the fetched metadata is encrypted at rest.
  • Files you export yourself. Manual exports, the optional markdown mirror, and the skill bundle write plaintext copies to folders you choose, so a cloud-synced destination moves them off the machine. Diagnostics leave only when you attach them to feedback.

Nothing in that list replaces on-device capture or search. These exceptions cover account, payment, and optional integrations or exports you explicitly enable, not continuous processing of your screen or microphone in the cloud.

Go deeper

Marketing pages such as Trust centre and Security summarise how we think about trust and operations. This documentation focuses on what the desktop app actually does on your machine.