Privacy
What Desk stores, what leaves the service, and who else touches it. Desk is bring-your-own-key: your AI provider is billed by you and sees your prompts.
Last updated
The short version
- Your projects, cards and conversations are private to your account. Sharing is opt-in, one item at a time, by link.
- Desk does not sell your data, does not show ads, and does not use your content to train any model.
- Desk has no AI costs of its own. You supply an API key from Anthropic or OpenAI, and your prompts go to that provider under your own account.
- You can export everything as Markdown files at any time, and you can delete your account.
What Desk stores
- Account. Your email address and sign-in credentials, held by our authentication provider (Clerk). Desk stores an internal user record keyed to it.
- Your content. Projects, cards, chat messages, generated artifacts, subjects and the notes filed under them, and any files you attach.
- Your API key. Encrypted before it is written down, with AES-256-GCM under a separate key-encryption key; only the wrapped key and the ciphertext are stored. It is decrypted server-side to make a request on your behalf, and is never sent to your browser or to either app after you save it.
Desk does not ask for your name, phone number, address or payment details, and has no payment processing at all.
Where your content goes
Desk is a client for services it does not run. What you write reaches them:
- Your AI provider — Anthropic or OpenAI. Your prompts, the conversation, and the content of cards being generated or revised, sent under your own API key and billed to your account. Their terms and privacy policy govern what they do with it.
- Web search.When a request needs current information, the search runs on Anthropic’s servers as part of the same request; your query text reaches them.
- Scholarly lookups. When Desk checks a citation it queries OpenAlex, doi.org and Wikidata with the reference in question.
- Maps.Building a map card sends the place names in it to OpenStreetMap’s Nominatim service to turn them into coordinates.
- Images. Image search queries go to Unsplash.
None of these receive your account identity from Desk — they receive the text of the request.
Who processes it for us
- Clerk — authentication and session management.
- Vercel — hosting, and file storage for attachments.
- Neon — the Postgres database your content lives in.
These are infrastructure providers acting on our instructions. Traffic between you, Desk and all of the above is encrypted in transit with standard TLS.
Dictation
The dictate button transcribes speech to text while you hold it, using the operating system’s own speech recognition. The audio is not recorded, stored or sent to Desk — only the text it produces, and only into the field you were typing in.
Getting your data out, and deleting it
Export. Account settings has an export that produces every project, card and subject as plain Markdown files in Open Knowledge Format. It is readable anywhere and needs no special software.
Deletion. You can delete individual items in the app. To delete your account and everything in it, write to us at the address below and we will remove it. Backups roll off on their own schedule.
Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to its processing. The address below is how to exercise them.
Changes and contact
If this policy changes materially we will update the date at the top and, for anything significant, say so in the app.
Questions, requests, or anything that looks wrong here: privacy@deskapp.me.