Legal

Privacy Policy

Last updated: 30 July 2026 Effective: 30 July 2026 Version: 1.0

In plain language

Desert Desk is a customer-support tool that other businesses embed on their own websites. That means we hold two very different kinds of information: a little bit about the businesses who buy from us, and whatever their own customers happen to type into a chat widget.

We collect as little as we can get away with. We don't sell personal information, we don't run advertising or analytics trackers, and we don't use anyone's conversations to train AI models. If you chatted with a Desert Desk widget on some company's website, that company decides what happens to your conversation — not us — and section 2 explains how to reach them.

This summary is here to be useful, not to be binding. The numbered sections below are the actual policy.

Contents
  1. Who we are
  2. Three kinds of people
  3. What we collect
  4. How we use it
  5. AI processing
  6. Why we're allowed to
  7. Who we share it with
  8. How long we keep it
  9. Your rights and choices
  10. California disclosures
  11. How we protect it
  12. Where it's stored
  13. Children
  14. Cookies
  15. Changes to this policy
  16. Contact us

Who we are

Desert Desk LLC, a Delaware limited liability company doing business as “Desert Desk” (“we”, “us”, “our”), operates the Desert Desk platform at desertdesk.app and this marketing site at www.desertdesk.app.

Desert Desk is an embeddable AI helpdesk. Businesses (we call them customers or tenants) sign up, configure an AI agent against their own knowledge base, and embed a chat widget on their own website. Their end users then talk to that widget.

Our registered address for legal notices is [NOTICE ADDRESS].

Three kinds of people, and why the difference matters

This policy covers three groups, and our obligations to each are genuinely different.

Site visitors

People who browse this marketing site. We are the controller of the very small amount of information involved. Section 3 covers what that is — it's close to nothing.

Customer staff

People who create a Desert Desk account, log into the admin portal, and configure the product. We are the controller of their account information: name, email, role, authentication data, billing contact.

End users of our customers

People who type into a Desert Desk chat widget on some other company's website. Here we are a processor — a service provider acting on that company's instructions. That company is the controller. They decide what the widget asks for, how long conversations are kept, and whether to delete them.

If you chatted with a widget and want your data deleted: the fastest route is usually the widget itself, which offers a “Delete this conversation” option and a link you can save to manage the conversation later from any device. Otherwise, contact the business whose website you were on. If you contact us directly, we will pass your request to that business and support them in answering it, but we cannot act on their data without their instruction.

What we collect

From site visitors

This marketing site runs no analytics, no advertising trackers, and no third-party scripts other than a webfont request. We don't set cookies here. Our hosting provider processes standard server request data (IP address, user agent, requested URL) for security and delivery, as any web host does.

From customer staff

  • Account details — name, work email address, company name, assigned role.
  • Authentication data — a hashed password (we never store the password itself), multi-factor authentication secrets and recovery codes, and a token identifying a browser you've marked as trusted.
  • Billing information — billing contact email, transaction history, and a customer reference held by our payment processor. Card numbers go directly to Stripe and are never stored on our systems.
  • Configuration you provide — branding, business hours, agent instructions, knowledge base documents, and integration credentials, which are encrypted at rest.
  • Activity records — an audit log of sensitive administrative actions, including who performed them and when, retained as a security control.

From end users of our customers

  • Conversation content — the messages typed into the widget, and the responses returned by the AI agent or a human agent.
  • Contact details, only if the customer asks for them — a customer can optionally enable a short pre-chat form requesting things like name, email, or company. This is off unless they turn it on, and the fields are theirs to choose.
  • Session identifiers — an opaque browser-generated identifier used to keep a conversation continuous across page loads. It is not linked to any advertising or cross-site profile.
  • Satisfaction feedback — an optional thumbs rating, reason tags, and free-text comment.
  • Screen content during a co-browsing session — only if the end user explicitly accepts a co-browsing request from a human agent. Form inputs are masked by default. This content is relayed live and is never written to our database or logs; only a metadata record of the session's timing and participants is kept.

We do not knowingly collect payment card numbers, government identifiers, health information, or precise location through the widget, and we ask customers not to configure it to request them. Card-number-like strings that appear in conversation text are automatically detected and masked.

How we use it

  • To provide the service — routing conversations, generating AI responses, connecting end users to human agents, storing transcripts for the customer's own review.
  • To bill — metering conversations, processing top-ups and subscriptions, sending receipts and balance notifications.
  • To secure the service — authenticating logins, detecting abuse, rate-limiting, and maintaining the audit log. This includes emailing customer staff when their account is accessed from a browser we don't recognise.
  • To support customers — responding when they contact us for help.
  • To operate the business — accounting, legal compliance, and enforcing our terms.

We do not use personal information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.

AI processing

Conversation content is sent to Anthropic PBC for model inference, together with the customer's own configured instructions and knowledge base. This is the core of how the product works.

  • We do not train AI models on anyone's data, and our model provider does not train its models on inputs or outputs submitted through its business API by default.
  • Knowledge base documents that a customer uploads are stored with the model provider so the agent can reference them. They contain whatever the customer chose to upload.
  • AI responses can be wrong. They are generated text, not verified fact, and should not be relied on as professional advice.
  • Where the customer has enabled it, an end user can ask to be transferred to a human.

Our AI & Bot Disclosures page covers this in more detail.

Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We share personal information with:

  • Subprocessors who help us run the service — hosting, AI inference, payments, and email delivery. Each is bound by contract to process data only on our instructions. Our full Subprocessor List names every one, what it does, and whether it is always used or only when a customer switches it on.
  • Services a customer connects themselves — such as a CRM, a spreadsheet, or a live-agent platform. When a customer configures an integration, they are directing us to send data there, and that destination's own privacy terms take over.
  • Professional advisers — accountants and lawyers, under confidentiality obligations.
  • Authorities — where we are legally compelled. We will tell the affected customer unless we are legally prohibited from doing so.
  • An acquirer — if the business is sold or merged, subject to this policy continuing to apply.

How long we keep it

CategoryRetention
Conversation contentSet by the customer. The default is 90 days, configurable between 30 and 180 days. An automated nightly process anonymises conversations past that window — message content is permanently replaced, while aggregate satisfaction ratings and timestamps remain.
Customer account recordsFor the life of the account, then removed when the account is closed and purged.
Billing and transaction recordsUp to 7 years, to meet tax and accounting obligations.
Audit logRetained as a security record for the life of the account.
Co-browsing screen contentNever stored. Relayed live and discarded.
BackupsHeld by our hosting provider on their standard cycle. Deleted data persists in backups until they age out.

When a customer closes their account, we archive it for a grace period and then permanently purge it, deleting every record tied to that account across our systems.

Your rights and choices

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, or object to certain processing. You also have the right not to be discriminated against for exercising these rights.

If you are customer staff

Most of what you need is in the admin portal: update your profile, change your email, reset your password, export conversation data, and set your retention period. For anything else, contact us using the details in section 16.

If you are an end user of one of our customers

You have three routes, and the first two are immediate:

  • In the widget — choose “Delete this conversation”. It is removed permanently and at once.
  • Save a management link — the widget can generate a private link that lets you return later, from any device, to view or delete that conversation.
  • Ask the business whose website you were on. They can locate and delete your conversation on your behalf.

If you write to us instead, we will forward your request to the relevant customer and help them respond. We aim to acknowledge requests within 10 business days and resolve them within 45 days, extendable once where the law permits.

We may need to verify your identity before acting, and for widget conversations that verification usually has to come from the business you were dealing with, since we hold no independent way to confirm who you are.

California disclosures

This section supplements the rest of this policy for California residents under the California Consumer Privacy Act as amended by the CPRA.

Categories of personal information collected in the last 12 months: identifiers (name, email, session identifier, IP address); commercial information (transaction and billing records); internet or network activity (audit and security logs); and, where a customer's end users provide it in conversation, other information they choose to type.

Sources: directly from you, from our customers, and automatically from your device when you use the service.

Business purposes: as described in section 4.

Sale or sharing: we have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months. We do not do so now, and we have no plans to. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” link, and we honour Global Privacy Control signals by default as a consequence of collecting nothing to sell.

Sensitive personal information: we do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond what is necessary to provide the service.

To exercise your rights, contact us at privacy@desertdesk.app. You may use an authorised agent, with written proof of authorisation.

How we protect it

Every customer's data is isolated from every other customer's at the database level, enforced by row-level security policies rather than only by application code. Access to the admin portal requires a password and supports multi-factor authentication. Passwords are hashed; stored third-party credentials are encrypted; data is encrypted in transit. Sensitive administrative actions are recorded in an audit log, and unmasking redacted information requires both an explicit permission grant and a written justification.

Current state. We have not yet completed a third-party penetration test or a SOC 2 audit. Both are on our roadmap, and we publish the full list of what is in place today versus what is planned on our Trust Center rather than implying more than is true. No system is perfectly secure.

To report a suspected vulnerability or security incident, email security@desertdesk.app. Our Incident Response & Data Breach page sets out what happens next.

Where it's stored

Our infrastructure and our subprocessors are located in the United States. If you access the service from outside the United States, your information is transferred to and processed there, where privacy laws may differ from those in your country.

We do not currently offer data residency in other regions.

Children

Desert Desk is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. Customers are responsible for ensuring their own use of the widget complies with laws protecting minors. If you believe a child has provided us with personal information, contact privacy@desertdesk.app and we will delete it.

Cookies

We set two cookies, both strictly necessary: one to keep you logged into the admin portal, and one to remember a browser you have chosen to trust for multi-factor authentication. We run no analytics, advertising, or tracking cookies anywhere on this site or in the product.

The chat widget also uses browser storage — not cookies — to keep a conversation continuous and to remember that you've dismissed a notice. Our Cookie Policy lists every one and explains why no consent banner is required.

Changes to this policy

We will update this policy as the product and our obligations change. The “Last updated” date at the top always reflects the current version. If we make a material change, we will notify customers by email or through the admin portal before it takes effect. Continuing to use the service after a change takes effect means you accept the updated policy.

Contact us

Privacy questions and requests
privacy@desertdesk.app
Security reports
security@desertdesk.app
Legal notices
legal@desertdesk.app
General support
support@desertdesk.app
Postal address
Desert Desk LLC
[NOTICE ADDRESS]

If you are dissatisfied with how we handled your request, you may lodge a complaint with your local data protection authority. California residents may contact the California Privacy Protection Agency.