Plain-language policy
Doto is a local-first Android launcher. It has no ads, no Doto account, and no automatic analytics or crash reporting. The only things that ever reach the developer are the diagnostic report and crash logs you choose to attach to a support email — and you can read both before they go.
Sensitive access is optional and tied to a feature you choose. Most information stays on your device. The limited cases where information can leave the device are explained below.
This policy covers the Google Play edition with package ID dev.dbdoo.launcher.
- Advertising
- None
- Developer analytics
- None
- Data sale
- Never
Data and features
Launcher and app information
Doto reads the launchable apps, shortcuts, icons, labels, and placement choices needed to work as your home screen. This information is processed locally.
Notifications and media controls
If you enable notification access, Android may expose active notification titles, text, sender names, badges, and media details. Doto keeps the active snapshot in memory so widgets and controls can work; it does not upload notification content.
Calendar, usage, and status widgets
Optional agenda, daily screen-time, Wi-Fi, battery, and connected-device widgets read only the information required for the selected widget. Calendar events, usage history, Wi-Fi names, and accessory details are processed locally.
Music visualization
Visualization reads live audio levels through Android. Audio is processed while a visualizer is active and is not recorded, saved, or uploaded.
Notes and personalization
Notes, layouts, icon appearance, widget configuration, and launcher preferences are stored on your device.
External services
Weather and place names
Weather sends forecast coordinates to the Norwegian Meteorological Institute (MET Norway) to retrieve a forecast. If precise location was already enabled for another feature, Android may briefly provide a more precise fix. Doto immediately rounds a current-location fix to about 0.1 degrees before caching it or sending it to MET. For a custom city, Android's configured geocoder receives the city name and returns coordinates; Doto also rounds those coordinates to about 0.1 degrees before sending them to MET. The configured geocoder may also process rounded current-location coordinates to produce a readable place label. MET receives ordinary network metadata such as an IP address and may log the IP address and coordinates under its terms. While a current-location weather widget is active in the foreground, Doto may refresh approximately every 30 minutes; it does not run a continuous background location tracker.
If the Google Weather app is unavailable, tapping a weather widget can open an HTTPS Google Search URL containing the readable city or place label. That search is handled by Google and the selected browser under their respective privacy policies.
Forecast data © the Norwegian Meteorological Institute, licensed under CC BY 4.0, and adapted by Doto.
Google Play Billing
Google Play processes the optional one-time Doto Pro purchase and ownership checks. Doto receives the product ID, purchase and acknowledgment status, and a purchase token that it returns to Play for acknowledgment. The token is never logged, saved, backed up, or sent to a Doto server. Doto keeps only a local ownership record and verification time, uses a maximum seven-day offline grace, and deletes that local record when you clear app storage or uninstall. Google Play Billing may send technical and operational diagnostics to Google under Google's Privacy Policy. Doto does not receive your payment-card details.
Android services and backup
Android provides permission screens, notification access, app usage access, geocoding, encrypted-capable cloud backup, and device transfer. Cloud backup and device transfer are separate Android system paths governed by your device or account provider's terms and settings.
Permissions and access
Doto explains sensitive access before opening Android's permission or special-access screen. You can deny or revoke optional access at any time; the related feature will stop or use its documented fallback.
- Notifications
- Badges, notification widgets, opening notifications, and media controls.
- Calendar
- Agenda widgets that you choose to use.
- Microphone / audio
- Live Android audio levels for music visualization; audio is not saved.
- Approximate location
- Current-location weather after you explicitly select it, including bounded foreground refreshes while its widget is active.
- Precise location
- Android requires this access to reveal the connected Wi-Fi network name.
- Nearby devices
- Connected Bluetooth names, battery reports, and a transient device address used only to match and deduplicate devices.
- Usage access
- On-device daily app screen-time summaries.
- Health Connect
- Read-only access to steps, heart rate, and sleep for the three health widgets, and only if you add one. Doto never writes, changes, or deletes health data.
Health data
Doto can show your steps, heart rate, and sleep on your home screen. These three widgets are optional. If you never add one, Doto never asks for health access and never reads anything.
What it reads. With your permission, Doto reads steps, recorded heart rate and sleep sessions from Health Connect. Steps include today and seven recent days; sleep includes the last recorded sleep and seven recent nights. Heart rate includes the latest recorded reading, seven recent hourly averages and available intraday detail over seven days. Data depends on what your watch or source app writes to Health Connect. Doto is a display, not a measuring device or a live medical monitor. It requests read access only, separately for each widget, and never writes, changes or deletes health records.
When it reads. Only metrics with a placed widget and your permission are read while Doto is in the foreground. Summaries refresh on return to the launcher; steps and heart rate then refresh about every five foreground minutes, and sleep about every hour. Recent history loads when requested by a widget and again on return for widgets that requested it. Doto does not read health data in the background.
Where it goes. Readings, history and source labels stay in process memory on your phone. Doto never saves them to disk, includes them in backups, logs or diagnostic reports, uploads them, or shares them with anyone, including the developer. There is no Doto account or server holding your health data.
Turning it off.Removing the last widget for a metric stops its reads and clears its in-memory readings and history. This does not revoke its Android permission. Leaving the foreground cancels reads and clears the health snapshot; permissions are checked before fresh readings appear on return. In Settings → Privacy → Health Connect, Manage access opens Android's controls. Disconnect clears all readings, stops reads and asks Health Connect to revoke Doto's permissions. If Android cannot complete revocation, Doto reports the failure and directs you to Manage access; reads stay stopped for that session until you choose to reconnect. You can also revoke access directly in Health Connect. Doto clears affected readings when the next permission check detects revocation, including on return to the launcher. None of these actions deletes records held by Health Connect or by the original source app.
Advertising and analytics. Health data is never used for advertising, never used to profile you, and never fed to analytics. Doto has no advertising and no developer-operated analytics of any kind.
Storage and backup
Launcher layout, notes, appearance settings, widget configuration, custom weather city, and the selected weather location mode are stored locally. Android cloud backup may transfer this selected state only through a transport that reports encryption capability. Android device transfer is a separate system path and may also move the same allowlisted state.
Cached weather coordinates, forecast responses, active notifications, Wi-Fi names, Bluetooth addresses, audio, and Google Play purchase tokens are not included in Doto's backup allowlist. Backup availability and retention are controlled by Android and your device or account provider.
Diagnostics you send
Doto never sends logs or diagnostics on its own. When you email support, you can choose to attach a diagnostic report. It is written into the email body, so you can read every line before sending, and it travels only when you press send in your own email app. The report describes the launcher's state: app version, device model, Android version, feature settings, permission and entitlement status, and the music pipeline's state, including the name of the app currently playing audio. It never includes song titles, contacts, messages, files, location, or anything you typed.
If the launcher has crashed, it writes a crash log — a technical stack trace of what failed, with the app version and nothing personal — to its own private storage, keeping only the newest five and never backing them up. You can also choose to attach those recent crash logs to a support email under the same rules, in the same readable body.
Reports arrive in the developer's support mailbox, are used only to answer your email, and are kept no longer than the conversation. If Doto adds other diagnostic reports in the future, they will follow these same rules: clearly offered, shown to you in full, and sent only by you.
Retention and deletion
Local launcher state remains until you change it, clear the app's storage, or uninstall Doto. Active notification, audio, Wi-Fi, and connected-device snapshots are kept only as needed for the live feature. Cached weather locations and forecasts may remain until they are refreshed, replaced, cleared with app storage, or removed when Doto is uninstalled.
You can delete local data from Android App info → Storage & cache → Clear storage, or by uninstalling the app. You can manage or delete Android backups through your device or account provider. There is no Doto account and no developer-held account profile to request for deletion.
Security and changes
Doto minimizes external transfer, keeps optional access feature-scoped, and limits Android backup to selected user-created launcher state. No software can guarantee absolute security, but the app is designed to avoid operating a developer data store for your private launcher content.
This policy may be updated when the app's features or data practices change. The current version will remain at this URL with a revised effective date.
Questions or privacy requests
dbdoo.dev@gmail.com