Privacy overview
How Overshow keeps capture and search on your device, and exactly what leaves your machine.
Last updated: 30 July 2026
Local-first by design
Overshow is built so that capture, processing, and storage happen on your Mac. Your indexed content and derived artefacts stay in a database on disk under your user account. That is not a slogan: the desktop app runs transcription, text extraction, embedding, and search without sending those payloads to Overshow’s servers for processing.
You are always in control of what Overshow captures. Pause and resume, exclude applications, and use built-in exclusion categories so the index reflects choices you make in Settings, not a default that assumes everything should be recorded.
What stays on your device
Screen activity you choose to record, audio you choose to record, transcripts, on-screen text, search indexes, summaries, and related metadata are handled locally. Overshow does not operate a default cloud pipeline that reads your capture content for product analytics or model inference. The desktop app does not send your screen, audio, or index content to Overshow. The licence server receives only sign-in, billing, device registration, and aggregate licence-usage counts.
The exceptions
Only the following categories move data off your Mac:
- Authentication. Signing in (for example via OAuth or email magic links) uses app.over.show and identity providers you choose.
- Billing. Subscription and payment handling goes through Stripe when you purchase or manage a plan.
- Licence and device checks. The licence server receives device registration metadata and aggregate licence-usage counts, never captured content.
- Optional calendar sync. If you enable it, calendar connection data is handled with encryption in transit and according to the integration settings you approve.
- Optional cloud mail. If a Microsoft or Google mailbox is connected, messages are fetched over a read-only OAuth grant you approve; without a grant cloud mail stays inert. Google controls remain hidden from general users while Google OAuth verification is in progress. See Mail integration for the exact data, local-storage, sharing, and deletion boundaries.
- Approved AI clients (Pro and Enterprise). If you connect an AI client through the read-only Memory MCP integration, a cloud client's queries and the snippets returned to it are processed by that client's provider; a local client (such as a local LLM) keeps everything on your machine. Every client requires explicit consent and approval, and you can revoke it at any time.
- Optional link enrichment (off by default). If you enable URL enrichment, Overshow fetches titles and metadata for recognised links found in your captures, limited to a per-domain allow-list. The request carries that link's URL to its own site; the fetched metadata is encrypted at rest.
- Files you export yourself. Manual exports, the optional markdown mirror, and the skill bundle write plaintext copies to folders you choose, so a cloud-synced destination moves them off the machine. Diagnostics leave only when you attach them to feedback.
Nothing in that list replaces on-device capture or search. These exceptions cover account, payment, and optional integrations or exports you explicitly enable, not continuous processing of your screen or microphone in the cloud.
Go deeper
- On-device processing. what runs locally and what that means day to day
- Encryption at rest. how sensitive material is protected on disk
- Capture controls. pause, resume, and per-app exclusions
- Mail integration. what cloud and local mail access reads, stores, and shares
- Trust centre. policies and commitments in one place
- Security. how we approach security for the product and infrastructure
Marketing pages such as Trust centre and Security summarise how we think about trust and operations. This documentation focuses on what the desktop app actually does on your machine.