DotDial is an experimental beta. The latest published beta is the only version for which security fixes are planned.
Please report security issues privately through GitHub's private vulnerability reporting when it is enabled. Do not file a public issue for an unpatched vulnerability. Include the affected release and a concise reproduction; do not attach account cookies, browser-profile files, access tokens, passwords, or call recordings.
The app stores a persistent ChatGPT browser profile and, when enabled, incoming audio recordings on the local device. Protect your Linux user account and review the Privacy notes before using DotDial with sensitive conversations. The current dot call adapter uses internal ChatGPT web endpoints and may stop working after a service change.
There is no guaranteed response time during the beta. If GitHub private vulnerability reporting is unavailable, wait until the repository owner provides a private contact channel; do not post exploit details publicly.