Legal

Cookie Policy

Last updated: 30 July 2026 Effective: 30 July 2026 Version: 1.0

In plain language

We set two cookies across the entire product, and both are required for you to stay logged in. There is no analytics, no advertising, no tracking pixel, and no third-party script that follows you anywhere. That's why you've never seen a cookie banner from us.

The chat widget uses browser storage — which is not the same as cookies — to keep a conversation going across page loads. Section 5 lists every item.

This summary is for orientation only. The numbered sections are the policy.

Contents
  1. The short version
  2. What cookies are
  3. This marketing site
  4. The admin portal
  5. The chat widget
  6. Why there's no consent banner
  7. Controlling what's stored
  8. If you're a Desert Desk customer
  9. Changes
  10. Contact

The short version

Two cookies. Both strictly necessary. No analytics, advertising, or tracking cookies anywhere — not on this site, not in the admin portal, not in the widget we put on our customers' websites.

We think this is worth stating plainly rather than burying, because “we only use essential cookies” is a claim many companies make while loading a dozen trackers. Ours is a complete list, and it's short enough to check.

What cookies are

A cookie is a small text file a website asks your browser to store and send back on later visits. Cookies are commonly used for keeping you logged in, and also — by many sites, though not this one — for measuring behaviour and targeting advertising.

Related technologies do similar jobs without being cookies. Local storage and session storage keep data in your browser, but unlike cookies they are never automatically transmitted to a server. We use them in the chat widget, and we list them here for completeness even though most cookie policies leave them out.

This marketing site

We set no cookies on www.desertdesk.app. There is no analytics, no tag manager, no advertising pixel, no chat tracker, and no social embed.

The only third-party request the page makes is to Google Fonts for the two typefaces used in the design. That request reveals your IP address to Google as any font request would, but sets no cookie and creates no identifier.

Our hosting provider processes standard server logs — IP address, user agent, requested URL — to deliver the site and protect it from abuse. That's infrastructure logging, not cookie-based tracking.

The admin portal

Two cookies, set at desertdesk.app for customers who log in. Both are strictly necessary — without them you cannot maintain a logged-in session.

Cookies set by the Desert Desk admin portal
Name Purpose Category Lifetime
session Keeps you signed in. Cryptographically signed so it cannot be tampered with, and contains session identifiers only — not your password, and no personal profile. Strictly necessary 8-hour sliding idle timeout, with a 30-day absolute maximum
td_token_<id> Remembers that you chose to trust this browser for multi-factor authentication, so you aren't asked for a code every time. Namespaced per user, so several people can use the same browser without interfering with each other. Strictly necessary Set when you tick “remember this device”; cleared when you disable multi-factor authentication

That is the complete list. There is no third cookie, and no third party sets a cookie in the portal.

The chat widget

The widget our customers embed on their websites sets no cookies at all. It uses browser storage instead, which stays on your device and is never transmitted automatically.

Browser storage used by the chat widget
What's stored Why Where
Conversation session identifier Keeps a conversation continuous if you navigate between pages or reload. Scoped to the specific business whose widget you're using, so one company's widget can never pick up another's session. Session storage — cleared when you close the tab
Conversation history Redisplays the messages already exchanged so a refresh doesn't lose the thread. Local storage
Live-agent connection state Lets the widget reconnect you to the same human agent after a reload rather than putting you back in a queue. Session storage
Dismissal markers Remembers that you closed a notice, an announcement card, or a tooltip so it doesn't reappear on every page. Keyed to the specific item and its version. Local storage
Feedback markers Records that you already answered a satisfaction prompt, so you aren't asked twice for the same conversation. Local storage

None of this is used to build a profile, track you across websites, or target advertising. Every item is scoped to a single business's widget on a single site, and clearing your browser storage removes all of it.

Why there's no consent banner

Consent requirements generally attach to cookies and similar technologies that are not strictly necessary — analytics, advertising, and cross-site tracking. Everything listed above is strictly necessary to deliver a service you asked for: staying logged in, or keeping a chat conversation coherent.

Under the California Consumer Privacy Act as amended, we neither sell personal information nor share it for cross-context behavioural advertising, so there is nothing for an opt-out to switch off. We have no advertising relationships, no data brokers, and no trackers to disable. Global Privacy Control signals are honoured by default as a consequence — there is nothing they need to stop.

This commitment is conditional on staying true. If we ever add analytics or any non-essential storage, we will update this page, advance the “Last updated” date, and put a proper consent mechanism in place before that technology loads. We won't quietly reclassify a tracker as “essential”.

Controlling what's stored

Every major browser lets you view, block, and delete cookies and site data through its settings, usually under Privacy. You can also use private browsing, which discards everything when the window closes.

Blocking cookies for desertdesk.app will prevent you logging into the admin portal — the session cookie is what keeps you signed in, and there is no alternative mechanism. Clearing the widget's browser storage is harmless: you'll simply start a fresh conversation next time.

If you want a conversation removed from our systems rather than just from your browser, the widget offers a “Delete this conversation” option, and can generate a private link so you can do it later from another device. Our Privacy Policy covers this in section 9.

If you're a Desert Desk customer

Because the widget sets no cookies, embedding it does not by itself create a cookie-consent obligation on your site. It does create a privacy-notice obligation: your own policy should disclose that you operate a chat widget, that conversations are processed by an AI service on your behalf, that browser storage is used to maintain the session, and how long you retain conversations.

You are welcome to link to this page from your own cookie policy. If your compliance team needs specifics we haven't covered here, email privacy@desertdesk.app and we'll answer directly.

Changes

We will update this page whenever what we store changes. The “Last updated” date at the top reflects the current version. Because the whole point of this policy is that the list is short and complete, keeping it accurate is a commitment rather than a formality.

Contact

Privacy questions
privacy@desertdesk.app
Postal address
Desert Desk LLC
[NOTICE ADDRESS]