Skip to content
← Back to deskmy

Privacy policy

Last updated: October 2026

The short version: your workspace is isolated, your data is never sold and never used to train third-party models, and agents can't take external action without a human approving it. The full version is below.

1. Overview

This policy explains what personal data deskmy collects, why we collect it, how long we keep it, and the control you have over it. It applies to all users and visitors worldwide and is part of our Terms of Service.

deskmy is a US company. This policy was prepared with the EU/UK GDPR, Brazil's LGPD, and US state privacy laws (including California's CCPA/CPRA) in mind. We may update it as regulations evolve — check this page periodically.

2. Who is responsible for your data

For workspace content — conversations, recordings, transcripts, files, Vault artifacts, and agent activity — the workspace owner (typically your employer or team admin) is the data controller, and deskmy acts as the data processor, handling that content only on the workspace's instructions.

For account, billing, and product-usage data, deskmy is the data controller. Questions or requests about your data can be sent to [email protected]; workspace-content requests may need to go through your workspace admin.

3. What we collect

Account data — name, email, company, profile picture, and optional details like role or phone number — provided when you register or update your profile. Your profile is visible to members of your workspace.

Content you produce — conversations, meeting audio and video, transcripts, recordings, files, links, and AI artifacts stored in the Vault, plus sticky notes and widgets on MyDesk.

Usage data — pages and features you use, search keywords, the URL you came from, browser and device information, and IP address, used to operate and improve the service.

Third-party account data — if you sign in with Google, Microsoft, or another provider, we receive the basic profile data you authorized with that provider.

Billing data — payment and transaction details processed by our payment provider. Card numbers are handled by the processor; we do not store full card data.

AI agent activity — instructions you give agents, the tools they run, the approvals you grant, and the audit log those actions generate.

Marketing data — if you enter your email on our website or subscribe to updates, we store that email to contact you about deskmy. You can unsubscribe at any time.

Sensitive data — we do not intentionally collect sensitive personal data (such as health, biometric, racial, political, or religious information). Please do not submit it through the platform; if you do, it is processed under the same protections described here.

4. How we use it and legal bases

To run the workspace — presence on the office map, conversations, meetings, recording and transcription, agent execution, and storing what your team produces (performance of our contract with you).

To improve the product — understanding how features are used, diagnosing problems, and developing new capabilities (legitimate interest).

To personalize the service — adapting content and features to how your team works (legitimate interest).

For contractual and legal purposes — billing, enforcing our terms, security, fraud prevention, and meeting legal obligations (contract and legal obligation).

For product communications — service announcements and, where you opted in, marketing emails (consent, which you can withdraw anytime).

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We do not use your data for purposes outside this policy without telling you first.

5. AI processing

Meeting transcripts and Vault content may be processed by AI models to produce summaries, answers, and agent output — this is core to how deskmy works.

Each workspace is isolated. Your data is never shared with other companies' workspaces, and it is not used to train models for third parties.

Agent actions that have external side effects — sending email, spending money, deleting data — wait for explicit human approval, and every action is recorded in your workspace's audit log.

Meetings and conversations may be recorded and transcribed. Recording indicators are shown to participants. If you organize a workspace or a meeting, you are responsible for informing participants and obtaining any consent required by law.

6. How long we keep data

We keep personal data for as long as needed to provide the service or fulfill the purposes in this policy — for example, while your account is active. After account deletion, remaining data is removed from production systems within a reasonable period and from backups within up to 90 days.

Security and access logs are kept for up to 12 months for security and abuse prevention, unless law requires longer.

Data may be preserved after that only when required by law or in anonymized, aggregated form. You can request removal or anonymization at any time, subject to legal retention requirements.

7. Security

We apply technical and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration, or disclosure. Data in transit is encrypted, and payment card data is processed over SSL by our payment provider.

If a security breach affects your data, we will notify you and, where required, the relevant authorities. No system is perfectly secure — to the maximum extent permitted by law, we are not liable for breaches caused by third parties, by events beyond our reasonable control, or by a user sharing their own credentials.

We may disclose personal information when required by law or when necessary to enforce our Terms of Service.

8. Sharing and transfers

Inside your workspace, profile data and the content you publish are visible to other members of that workspace.

We share data with service providers — payment processors, hosting, AI model providers, and product analytics — only as needed to deliver the service. Each provider is bound by contractual data-protection obligations and has its own privacy policy.

deskmy is headquartered in the United States, and some providers operate in other countries. By using deskmy you consent to the transfer, processing, and storage of your data in the US and other jurisdictions. Where required (for example, for EU/UK or Brazilian data subjects), we rely on appropriate safeguards such as Standard Contractual Clauses.

When you follow a link to a third-party site or app, this policy no longer applies — their practices are governed by their own policies.

9. Cookies

deskmy uses cookies and similar technologies to keep you signed in, remember preferences, and understand how the product is used. Session cookies disappear when you close the browser; persistent cookies remain until removed.

You can configure your browser to refuse cookies, though parts of the platform may stop working correctly.

10. Your rights

Depending on where you live, you may have the right to: access, correct, export (port), or delete your personal data; restrict or object to processing; withdraw consent; opt out of the sale or sharing of personal data (we do not sell it); and lodge a complaint with a supervisory authority — such as your local DPA (EU/UK), the ANPD (Brazil), or your state regulator (US).

Workspace admins control retention, agent permissions, and access policies for the workspace. Exercising workspace-level rights may require your admin.

To exercise any right, contact us at [email protected]. We will not discriminate against you for exercising your privacy rights.

11. Children

deskmy is a workplace product and is not directed at children. People under 18, or without full legal capacity, may use the platform only with the express consent of a legal guardian, as described in the Terms of Service. If we learn that we have collected a child's data without that consent, we will delete it.

12. Changes to this policy

We may modify this policy at any time. Changes take effect when published, and we will notify you of material updates inside the app or by email.

Continued use of the service after changes are published constitutes acceptance of the updated policy.