Skip to content

Version 2026-09-27.2

Privacy Policy

What Desker collects, why, and who else sees it.

What we collect

  • Account data: your name, email address and a hash of your password.
  • Organisation data: members, roles, invitations, plan and billing status.
  • Content you provide: agent configuration, uploaded documents, scopes of work.
  • Conversations between your agents and your clients, and the work your agents produce, including drafts and research findings.
  • An audit log of actions taken by people and agents, and product usage events (which screens and features are used).
  • Feedback you send from inside the product.

How we use it

To operate the Service for you: answering your clients, running your agents’ work, metering your plan, and showing you what happened. Usage and feedback are used to decide what to improve. We do not sell personal data and do not use your content to train models.

Who else processes it

  • Model providers (Anthropic, and OpenAI if you choose it) receive the content needed to generate a reply or carry out a task.
  • A web search provider (Brave or Tavily) receives search queries an agent makes.
  • Our hosting, database and job-runtime providers (Vercel, Neon, Inngest) store and process data to run the Service.
  • Our payment provider (Stripe) handles payment details; we never see your card number.
  • Integrations you connect (a publishing webhook, an email provider, Google Calendar, Slack, GitHub) receive exactly what your agents send them, after your approval unless you allowed that tool to act on its own.
  • An error-monitoring service may receive technical error reports without request bodies or message content.

Cookies, tracking and recordings

We set one cookie, to keep you signed in. There is no advertising or analytics tracking, no session recording, and the site loads no fonts or scripts from other companies’ servers: everything is served from our own domain.

Emails and unsubscribing

Emails your agents send, and agent reports you choose to have emailed, go out from your organisation through the email provider you connect. Each one names your business, gives its postal address, and has an unsubscribe link. Anyone who unsubscribes is taken off that organisation’s list straight away and is not emailed by its agents again.

Children

We do not knowingly collect personal data from children under 13 (or the higher age your country sets). If you believe a child has given us personal data, write to sakditouch.pu@gmail.com and we will delete it.

Security

Integration credentials are encrypted at rest and decrypted only at the moment of use. Model and search keys never leave the server. Access to your organisation requires a membership with a role.

Retention and your rights

Data is kept while your organisation exists and deleted when it is closed, subject to backups and legal obligations. You can ask for a copy of your data or its deletion at sakditouch.pu@gmail.com. Your clients’ messages to your agents are your data; requests about them should come to us through you.

Changes and contact

We will announce material changes in the Service. Questions about privacy: sakditouch.pu@gmail.com.

Questions about this document? Write to sakditouch.pu@gmail.com, or read the Terms of Service.