In plain language
Desert Desk is a customer-support tool that other businesses embed on their own websites. That means we hold two very different kinds of information: a little bit about the businesses who buy from us, and whatever their own customers happen to type into a chat widget.
We collect as little as we can get away with. We don't sell personal information, we don't run advertising or analytics trackers, and we don't use anyone's conversations to train AI models. If you chatted with a Desert Desk widget on some company's website, that company decides what happens to your conversation — not us — and section 2 explains how to reach them.
This summary is here to be useful, not to be binding. The numbered sections below are the actual policy.
Contents
Who we are
Desert Desk LLC, a Delaware limited liability company doing business as “Desert Desk” (“we”, “us”, “our”), operates the Desert Desk platform at desertdesk.app and this marketing site at www.desertdesk.app.
Desert Desk is an embeddable AI helpdesk. Businesses (we call them customers or tenants) sign up, configure an AI agent against their own knowledge base, and embed a chat widget on their own website. Their end users then talk to that widget.
Our registered address for legal notices is [NOTICE ADDRESS].
Three kinds of people, and why the difference matters
This policy covers three groups, and our obligations to each are genuinely different.
Site visitors
People who browse this marketing site. We are the controller of the very small amount of information involved. Section 3 covers what that is — it's close to nothing.
Customer staff
People who create a Desert Desk account, log into the admin portal, and configure the product. We are the controller of their account information: name, email, role, authentication data, billing contact.
End users of our customers
People who type into a Desert Desk chat widget on some other company's website. Here we are a processor — a service provider acting on that company's instructions. That company is the controller. They decide what the widget asks for, how long conversations are kept, and whether to delete them.
If you chatted with a widget and want your data deleted: the fastest route is usually the widget itself, which offers a “Delete this conversation” option and a link you can save to manage the conversation later from any device. Otherwise, contact the business whose website you were on. If you contact us directly, we will pass your request to that business and support them in answering it, but we cannot act on their data without their instruction.
What we collect
From site visitors
This marketing site runs no analytics, no advertising trackers, and no third-party scripts other than a webfont request. We don't set cookies here. Our hosting provider processes standard server request data (IP address, user agent, requested URL) for security and delivery, as any web host does.
From customer staff
- Account details — name, work email address, company name, assigned role.
- Authentication data — a hashed password (we never store the password itself), multi-factor authentication secrets and recovery codes, and a token identifying a browser you've marked as trusted.
- Billing information — billing contact email, transaction history, and a customer reference held by our payment processor. Card numbers go directly to Stripe and are never stored on our systems.
- Configuration you provide — branding, business hours, agent instructions, knowledge base documents, and integration credentials, which are encrypted at rest.
- Activity records — an audit log of sensitive administrative actions, including who performed them and when, retained as a security control.
From end users of our customers
- Conversation content — the messages typed into the widget, and the responses returned by the AI agent or a human agent.
- Contact details, only if the customer asks for them — a customer can optionally enable a short pre-chat form requesting things like name, email, or company. This is off unless they turn it on, and the fields are theirs to choose.
- Session identifiers — an opaque browser-generated identifier used to keep a conversation continuous across page loads. It is not linked to any advertising or cross-site profile.
- Satisfaction feedback — an optional thumbs rating, reason tags, and free-text comment.
- Screen content during a co-browsing session — only if the end user explicitly accepts a co-browsing request from a human agent. Form inputs are masked by default. This content is relayed live and is never written to our database or logs; only a metadata record of the session's timing and participants is kept.
We do not knowingly collect payment card numbers, government identifiers, health information, or precise location through the widget, and we ask customers not to configure it to request them. Card-number-like strings that appear in conversation text are automatically detected and masked.
How we use it
- To provide the service — routing conversations, generating AI responses, connecting end users to human agents, storing transcripts for the customer's own review.
- To bill — metering conversations, processing top-ups and subscriptions, sending receipts and balance notifications.
- To secure the service — authenticating logins, detecting abuse, rate-limiting, and maintaining the audit log. This includes emailing customer staff when their account is accessed from a browser we don't recognise.
- To support customers — responding when they contact us for help.
- To operate the business — accounting, legal compliance, and enforcing our terms.
We do not use personal information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
AI processing
Conversation content is sent to Anthropic PBC for model inference, together with the customer's own configured instructions and knowledge base. This is the core of how the product works.
- We do not train AI models on anyone's data, and our model provider does not train its models on inputs or outputs submitted through its business API by default.
- Knowledge base documents that a customer uploads are stored with the model provider so the agent can reference them. They contain whatever the customer chose to upload.
- AI responses can be wrong. They are generated text, not verified fact, and should not be relied on as professional advice.
- Where the customer has enabled it, an end user can ask to be transferred to a human.
Our AI & Bot Disclosures page covers this in more detail.
Why we're allowed to process it
We process personal information because it is necessary to perform our contract with a customer, because we have a legitimate interest in securing and operating the service, because we are complying with a legal obligation, or because consent was given — for example, when an end user accepts a co-browsing request.
Current state. Desert Desk operates from the United States and is presently built for United States customers. We apply principles comparable to those in the EU and UK General Data Protection Regulation — data minimisation, purpose limitation, and honouring access and deletion requests — but we do not currently claim formal GDPR compliance, and we have not appointed an EU or UK representative. A formal compliance programme, including Standard Contractual Clauses, is on our roadmap. See the Trust Center.
How long we keep it
| Category | Retention |
|---|---|
| Conversation content | Set by the customer. The default is 90 days, configurable between 30 and 180 days. An automated nightly process anonymises conversations past that window — message content is permanently replaced, while aggregate satisfaction ratings and timestamps remain. |
| Customer account records | For the life of the account, then removed when the account is closed and purged. |
| Billing and transaction records | Up to 7 years, to meet tax and accounting obligations. |
| Audit log | Retained as a security record for the life of the account. |
| Co-browsing screen content | Never stored. Relayed live and discarded. |
| Backups | Held by our hosting provider on their standard cycle. Deleted data persists in backups until they age out. |
When a customer closes their account, we archive it for a grace period and then permanently purge it, deleting every record tied to that account across our systems.
Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, or object to certain processing. You also have the right not to be discriminated against for exercising these rights.
If you are customer staff
Most of what you need is in the admin portal: update your profile, change your email, reset your password, export conversation data, and set your retention period. For anything else, contact us using the details in section 16.
If you are an end user of one of our customers
You have three routes, and the first two are immediate:
- In the widget — choose “Delete this conversation”. It is removed permanently and at once.
- Save a management link — the widget can generate a private link that lets you return later, from any device, to view or delete that conversation.
- Ask the business whose website you were on. They can locate and delete your conversation on your behalf.
If you write to us instead, we will forward your request to the relevant customer and help them respond. We aim to acknowledge requests within 10 business days and resolve them within 45 days, extendable once where the law permits.
We may need to verify your identity before acting, and for widget conversations that verification usually has to come from the business you were dealing with, since we hold no independent way to confirm who you are.
California disclosures
This section supplements the rest of this policy for California residents under the California Consumer Privacy Act as amended by the CPRA.
Categories of personal information collected in the last 12 months: identifiers (name, email, session identifier, IP address); commercial information (transaction and billing records); internet or network activity (audit and security logs); and, where a customer's end users provide it in conversation, other information they choose to type.
Sources: directly from you, from our customers, and automatically from your device when you use the service.
Business purposes: as described in section 4.
Sale or sharing: we have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months. We do not do so now, and we have no plans to. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” link, and we honour Global Privacy Control signals by default as a consequence of collecting nothing to sell.
Sensitive personal information: we do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond what is necessary to provide the service.
To exercise your rights, contact us at privacy@desertdesk.app. You may use an authorised agent, with written proof of authorisation.
How we protect it
Every customer's data is isolated from every other customer's at the database level, enforced by row-level security policies rather than only by application code. Access to the admin portal requires a password and supports multi-factor authentication. Passwords are hashed; stored third-party credentials are encrypted; data is encrypted in transit. Sensitive administrative actions are recorded in an audit log, and unmasking redacted information requires both an explicit permission grant and a written justification.
Current state. We have not yet completed a third-party penetration test or a SOC 2 audit. Both are on our roadmap, and we publish the full list of what is in place today versus what is planned on our Trust Center rather than implying more than is true. No system is perfectly secure.
To report a suspected vulnerability or security incident, email security@desertdesk.app. Our Incident Response & Data Breach page sets out what happens next.
Where it's stored
Our infrastructure and our subprocessors are located in the United States. If you access the service from outside the United States, your information is transferred to and processed there, where privacy laws may differ from those in your country.
We do not currently offer data residency in other regions.
Children
Desert Desk is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. Customers are responsible for ensuring their own use of the widget complies with laws protecting minors. If you believe a child has provided us with personal information, contact privacy@desertdesk.app and we will delete it.
Changes to this policy
We will update this policy as the product and our obligations change. The “Last updated” date at the top always reflects the current version. If we make a material change, we will notify customers by email or through the admin portal before it takes effect. Continuing to use the service after a change takes effect means you accept the updated policy.
Contact us
- Privacy questions and requests
- privacy@desertdesk.app
- Security reports
- security@desertdesk.app
- Legal notices
- legal@desertdesk.app
- General support
- support@desertdesk.app
- Postal address
- Desert Desk LLC
[NOTICE ADDRESS]
If you are dissatisfied with how we handled your request, you may lodge a complaint with your local data protection authority. California residents may contact the California Privacy Protection Agency.