The short version
- We use your data to run your assistants and agents for you. That is the only reason we have it.
- We never sell it, never use it for advertising, and never use it to train AI models - ours or anyone else’s.
- Google data (Calendar and Gmail) is used only to check clashes, schedule meetings, and draft replies you approve. It is not sold, not used for ads, and not used to train AI models.
- A personal space is yours alone: nobody can be invited into it and its assistants have no public link.
- Nothing leaves on your behalf without your approval, unless you switch that on yourself for a specific tool.
- You can download everything, or delete everything, yourself, at any time, from inside the app.
Your personal space
Your space is for your own life. It has one member, cannot be shared, and its assistants cannot be reached from outside it. For your account and your space we are responsible for your data as described here.
What we collect
- Your account: name, username, email address, a one-way hash of your password (never the password itself), and when you accepted these terms.
- What you tell your assistants and agents: your answers to the setup questions (about you), their instructions, schedules and objectives.
- Documents you upload: the files and the text extracted from them, so agents can search them. In a CSV file (usually a bank or card statement), long numbers such as account and card numbers are masked to their last four digits as the file is read, before the text is stored for search or seen by any AI model.
- Work and conversations: chats with your agents, the work they do, what they draft, research findings, digests and suggestions.
- Records: an audit log of what people and agents did and when, and simple product usage events (which screens and features are used) kept on our own servers.
- Connections you choose to make: for connected services (such as Google Calendar, Gmail, Slack) we keep the access credentials encrypted at rest. When connected, we read calendar events to check for clashes and schedule meetings, and email threads to draft replies you approve.
- Billing: your plan and its status. Card details go straight to our payment provider; we never see or store your card number.
- Messages to us: feedback you send from inside the product and what you write on the contact or beta forms.
Sensitive information in a personal space
A personal assistant is most useful when it knows about your life, and that can include your finances, your health, your family or your work. You decide what to share; nothing is required beyond your account details. We use it only to do what you asked the assistant to do. Please never enter passwords, full card or account numbers, or government ID numbers: no assistant needs them, and the product never asks. The money manager adds up statements on our servers, so its figures are exact rather than estimated by an AI, and account and card numbers in a statement are masked before any AI model reads it.
How we use it
- To run the service: answer your chats, carry out scheduled and requested work, search your documents, send the digests and emails you approve.
- To keep it safe and working: preventing abuse, rate-limiting, fixing errors, and keeping the audit log you can read.
- To bill the plan you chose.
- To decide what to improve, from usage counts and the feedback you send - never by reading your content.
We do not sell personal data, share it for advertising, or build profiles of you. Your content is not used to train AI models. Staff do not read your spaces; the exception is when you ask us for help with a specific problem, or when the law requires it, and then only what is needed.
Google user data and API services
If you choose to connect your Google account (such as Google Calendar or Gmail) to Desker, we access and process specific Google user data solely to enable user-directed scheduling and communication features for your assistants and agents:
- Which Google data Desker reads and why:
- Google Calendar events: We read calendar events to check for clashes and create or move meetings upon your instructions.
- Gmail and email data: We read email threads to understand context and draft replies you approve. Agents only prepare draft replies; no email is ever sent without your explicit review and approval.
- Used only to provide these features: Data received from Google APIs is used strictly to provide and improve these user-facing calendar and email features. It is not used for any other purpose.
- Not sold: Google user data is not sold to any third party.
- Not used for ads: Google user data is not used for advertising, personalized marketing, or retargeting.
- Not used to train AI models: Information received from Google APIs is not used to train AI models—neither our own models nor those of any third party.
- Human access: No humans read your Google data unless you give explicit permission for technical support, it is necessary for security investigations, or we are compelled by law.
Disconnecting your Google account and deleting your data
You have complete control over your Google connection at all times:
- Disconnecting inside Desker: You can disconnect your Google account at any time in the app under Integrations by clicking Disconnect.
- Revoking access via Google: You can also revoke Desker's access at any time through your Google Account Security permissions.
- How data gets deleted: Disconnecting your Google account immediately deletes all stored OAuth access tokens and credentials from our database. Any drafts or meeting records created by agents can be deleted individually at any time. Furthermore, using Delete my account immediately and permanently purges all your account data, spaces, drafts, and connected-app credentials from our systems.
Desker's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Who else processes it
We use a small set of providers, each only for its part of running the service:
- AI model providers (Anthropic; OpenAI if you choose one of its models, and for document search indexing) receive the text needed for each reply or task. Under their API terms they do not train on it, and keep it only for a limited period for abuse and safety monitoring.
- A web search provider (Brave or Tavily) receives the search queries an agent makes - never your documents.
- Hosting, database and background jobs (Vercel, Neon, Inngest) store and process data to run the service.
- Email delivery (Resend) sends account emails such as password resets, and the digests you ask for.
- Messaging apps you choose (LINE, WhatsApp, Telegram, Slack, Discord, Microsoft Teams) carry the alerts and morning brief you set up under Alerts. Only the apps you add get messages, and you can remove them at any time.
- Payments (Stripe) handles subscriptions and card details.
- Error monitoring (Sentry) receives technical error reports, without message content or request bodies.
- Apps you connect receive exactly what an agent sends them, after your approval unless you allowed that tool to act on its own.
Some of these providers are based in, or store data in, the United States and other countries. Where data leaves your country we rely on the provider’s contractual commitments to protect it.
Cookies and tracking
We set one cookie, to keep you signed in. Your browser also remembers display preferences (like the setup checklist) on your own device. There is no advertising or third-party analytics tracking and no session recording.
Email your agents send
Email from your assistants is written as you, to people you choose, and only with your approval unless you have switched that on.
How long we keep it
- Your data stays while your account and spaces exist.
- Deleting a document, a chat or an agent removes it from the service straight away.
- Deleting your account removes it and every space you alone own - documents, chats, work, drafts, history and connected-app credentials - immediately. Copies in our database provider’s backups expire on its normal schedule and are never restored except to recover from an outage.
- We keep billing records as long as tax law requires.
Your rights, as buttons
Wherever you live, you can do these yourself, without writing to us: open Your space and use Download my data for a complete copy of your account and the spaces you own, as a machine-readable file; or Delete my account to erase it. You can correct anything by editing it in the app. You may also ask us to restrict or stop a particular use of your data, or ask any question about it, at sakditouch.pu@gmail.com; we answer within 30 days. If you are unhappy with our answer you can complain to your data protection authority (in Thailand, the Personal Data Protection Committee; in the EU or UK, your national regulator).
If you live in California
We do not sell or share your personal information, as the California Consumer Privacy Act defines those words, and we have not done so in the past 12 months. We don’t use sensitive personal information for anything beyond providing the service you asked for. You have the right to know what we hold about you, to get a copy, to correct it and to delete it - the buttons above do this - and to do so without being treated any differently. You can also ask through someone you authorise, by writing to sakditouch.pu@gmail.com; we will verify the request before acting on it.
Security
Everything travels over HTTPS. Passwords are stored as one-way hashes, password-reset links as hashes too, and connected-app credentials are encrypted at rest (AES-256-GCM) and decrypted only at the moment of use. Model and search keys never leave our servers. Every space is reachable only by its members, and a personal space only by you. If a breach ever puts your data at risk, we will tell you and the authorities as the law requires.
Children
Desker is not for children under 13 (or the higher age your country sets). If you believe a child has given us personal data, write to sakditouch.pu@gmail.com and we will delete it.
Changes and contact
When this policy changes in a way that matters, we will tell you in the app and by email before it takes effect, and the version at the top of this page will change. Questions about privacy: sakditouch.pu@gmail.com.