Captured work is processed on the consultant's computer. Publishing an approved record, connecting a service or exporting content creates a separate data transfer. These are the destinations, controls and storage boundaries your IT team can review.
Local processing
On the computer
Screen text and selected documents are indexed locally. Meeting audio is optional. When enabled, it is transcribed on-device during active or manually started meetings. Capture, full-text and semantic search, review and approval run on Windows and macOS.
Organisation repository
The consultancy receives the approved record and its approved source excerpts only when the consultant publishes them. Authorised engagement members can read the published record. The wider capture index, original sources and drafts are not replicated by publication.
Drafting runs on the Mac. On Windows the consultant writes the record from the attributed day. See system requirements for hardware guidance.
Screen images are discarded after text extraction. Raw meeting audio stays local, with bounded encrypted recovery files held until successful processing, deletion or storage cap eviction. Voice embeddings are not stored or compared across meetings.
Data transfers
Account services
Sign-in, billing, device registration and aggregate licence state go to Overshow's account services. These requests do not contain the local capture index.
Record publication
Choosing Publish sends the approved record, approved source excerpts and publication metadata to the organisation repository. Authorised members can retrieve that published content.
Exports and diagnostics
Exports and file mirrors write content to a folder you choose, which may be cloud-synced. A submitted feedback diagnostic can send text you review and attach to Overshow.
Connected AI clients
A client you approve receives scoped, read-only access. A cloud client sends queries and retrieved snippets to its provider. A local client keeps that exchange on the computer. You can revoke access.
URL enrichment
When enabled for an allowed site, URL enrichment makes requests to that site to retrieve content. The destination sees those requests under its own privacy terms.
Calendar and email
An authorised Google or Microsoft connection lets the desktop fetch permitted calendar or mail data directly from the provider. Overshow's account service holds encrypted provider tokens and connection metadata, rather than a routine copy of calendar events or messages.
The consultant chooses capture sources and can pause from the app, the menu bar on macOS or the tray on Windows. Review, approval and publication remain separate from capture.
Screen context, documents, calendar, email and optional meeting audio have separate controls
Exclude specific apps, sites, windows or monitors
Password managers, private browsing and remote desktops have built-in exclusions
Correct, exclude or delete record items before approval
Example source settings
Screen contextOn
DocumentsOn
CalendarOff
EmailOff
Meeting audioOff
System permissions
On macOS, Screen Recording and Accessibility are required for capture. Microphone access is needed for optional meeting audio transcription. On Windows, read-only screen capture needs no equivalent system grants. Capture starts after onboarding is completed.
Data protection
Privacy responsibilities
The privacy notice describes the data processed and the controller and processor roles. Your consultancy is responsible for the permissions and policies required for its use of capture and the organisation repository.
ICO registration
San Digital Limited is registered with the Information Commissioner's Office. Registration is separate from product certification or an assessment of your deployment.
Review materials
A DPIA template is available for your data protection review. The Trust Centre lists certifications, platform verification and sub-processors for your security team to inspect.
SQLCipher encryption at rest (AES-256-CBC). The database key is derived using HKDF-SHA256 from a platform keychain secret, machine ID, OS user ID and app user ID.
One active device per user. You confirm the transfer before access moves to another computer and the previous device's access is revoked. Captured data stays on the computer that recorded it.
The desktop app has no analytics beacons. Account traffic, approved publication and submitted diagnostics follow the separate paths described above.
Mac binaries are signed and notarised. Windows installers are signed. The local API binds to the loopback interface by default and requires authentication.