Deska legal

Privacy Policy

Last updated: June 2, 2026

Deska is local-first: your development workspace generally stays on your computer. This policy explains the narrower cases where data is stored locally, sent to Deska Cloud, or sent to a third party because you chose a connected feature.

Scope and controller

This Privacy Policy explains how Pasho ("Deska," "we," "us," or "our") handles personal data when you use the Deska desktop application, the Deska Cloud website, account and billing services, managed AI features, and related services that link to this policy (together, the "Services").

Pasho is the controller for personal data it determines how and why to process. For privacy questions or requests, contact [email protected].

Local-first by design

Deska is designed so that core desktop work stays on your device. Workspace files, repository content, project paths, terminal state, layouts, snapshots, settings, local notes, and locally stored AI session files are generally processed and stored locally. Deska Cloud does not automatically receive your workspace contents merely because you use the desktop application.

Data leaves your device when you choose a feature that requires it, such as a third-party AI provider, managed AI feature, provider OAuth flow, account sign-in, payment flow, crash report, optional product analytics, external browser panel, Git operation, or update check. The sections below explain these cases.

Cloud workspace sync is not part of the current local-first desktop flow. If we introduce an optional sync feature, we will update this policy and describe the data involved before it applies.

Data we collect

Depending on the features you choose, we process the following categories:

  • Account data. Your email address, authentication identifier, and related sign-in information when you create or use a Deska Cloud account. Authentication is provided through Clerk.
  • Billing and entitlement data. Stripe customer and checkout identifiers, subscription identifiers, plan, payment status, renewal period, lifetime entitlement status, and entitlement issuance data. Stripe processes your payment method details; we do not store full card numbers.
  • Managed-feature usage. When managed AI features are available and you use them, the content needed to fulfill your request — such as audio for transcription, or chat prompts together with a context snapshot of your canvas (your project name and relative file paths, the titles and types of open panels, URLs open in browser panels, and terminal or agent status) — plus usage measurements such as audio seconds and token counts.
  • Support and feedback data. Information you send us when you request support or submit optional product feedback, including your message and an optional rating.
  • Website and service technical data. Information ordinarily generated when your device communicates with a website or API, such as IP address, request date and time, browser or client information, and security logs. Necessary cookies and similar technologies may be used for authentication and service operation.
  • Optional desktop analytics. An install identifier, app version, platform, architecture, locale, Electron version, packaged-app status, product events such as installs and updates, and feedback you choose to submit. Analytics are designed not to include account information, workspace contents, file paths, project names, or hostnames.
  • Optional crash reports. An install identifier, app and runtime versions, platform, operating-system release, locale, error details, and diagnostic context. Deska configures crash reporting to avoid default personal information and to scrub common secrets, home-directory paths, and detailed navigation URLs before sending reports.

Data stored on your device

The desktop application stores local configuration and workspace state so it can restore your environment. This may include project paths, panel and terminal state, local snapshots, settings, AI session files, an anonymous install identifier, buffered analytics events awaiting delivery, and an offline entitlement token containing an account identifier, plan tier, and issuance time.

BYOK credentials for Deska's chat features are stored locally. Deska uses operating-system-backed encryption when Electron's secure storage is available. On systems where secure storage is unavailable, such as some Linux configurations, the desktop may fall back to base64 encoding, which is not encryption. Credentials used by the embedded coding-agent runtime may also be stored locally in that runtime's credential file.

You control your device and are responsible for its security, backups, operating-system account controls, and deletion of local data when appropriate.

AI providers and audio

When you use a BYOK workflow, Deska sends the information needed for your request directly from your device to the provider you choose. Depending on your workflow, that can include prompts, code, selected files, tool outputs, conversation history, or microphone audio. Your provider processes that data under its own terms and privacy policy.

When you use a managed AI feature, Deska Cloud receives the information needed for the request and forwards it to the applicable provider. Managed voice transcription forwards your audio to Groq. Managed chat is routed through OpenRouter, which dispatches the request to an underlying model provider (such as Anthropic). To answer questions about your workspace, managed chat also includes a context snapshot of your canvas — your project name and relative file paths, the titles and types of open panels, URLs open in browser panels, and terminal or agent status. We do not intentionally use your prompts, audio, workspace files, or AI output to train our own models.

Only send personal, confidential, or regulated information to an AI workflow if you have authority to do so and have evaluated the provider configuration for your use case.

Why we use data

We use personal data to:

  • provide accounts, entitlements, offline access tokens, and requested features;
  • process purchases, subscriptions, taxes, and billing support;
  • route managed AI requests and measure applicable usage limits;
  • secure, operate, troubleshoot, and improve the Services;
  • respond to support requests and optional feedback;
  • provide updates and important service communications; and
  • comply with law and enforce our Terms of Service.

How we share data

We share personal data only as needed for the purposes described above, including with:

  • Clerk for authentication and account sessions;
  • Stripe for checkout, payment processing, taxes, subscriptions, and billing portal functions;
  • hosting and database providers that operate Deska Cloud infrastructure;
  • Sentry for optional error and crash reporting;
  • deska-analytics at analytics.deska.dev for optional desktop product analytics;
  • AI providers selected by you or used to fulfill a managed request, such as Groq, Anthropic, OpenAI, Google Gemini, OpenRouter, or other providers available in the Services; and
  • authorities, advisors, or transaction participants where reasonably necessary to comply with law, protect rights and security, or complete a corporate transaction.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising, and we do not use third-party advertising trackers in the Services.

Your choices

Deska desktop provides settings for crash reporting and anonymous usage analytics. Both settings are enabled by default in the current desktop application and can be disabled in the application settings. Disabling them stops future submissions from the relevant channel. Locally buffered analytics events may remain on your device until removed by the application or by you.

You can remove BYOK credentials through the desktop interface, sign out to remove the locally cached entitlement token, manage subscriptions through the available Stripe billing portal, and delete local workspace state from your device. You can also contact us about your Deska Cloud account.

Retention

We retain personal data only as long as reasonably needed for the purposes described in this policy, including providing active accounts and entitlements, maintaining security, resolving disputes, and meeting tax, accounting, and legal obligations.

Retention depends on the data: account and entitlement records may remain while your account or purchased entitlement exists; billing records may be retained as required by law; usage meters may be retained for billing, quota, and abuse-prevention purposes; and diagnostics and support messages may be retained as needed to investigate issues and improve reliability. Local desktop data remains on your device until you or the application remove it.

International transfers

Our providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. Contact us if you need more information about applicable safeguards.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data; receive a portable copy; withdraw consent; appeal certain decisions; and lodge a complaint with a data-protection authority. You will not receive discriminatory treatment for exercising applicable rights.

California residents may also have rights to know the categories and specific pieces of personal information collected, request correction or deletion, and opt out of sale or sharing. Because we do not sell personal data or share it for cross-context behavioral advertising, there is no sale or advertising-sharing opt-out to exercise for Deska at this time.

To make a request, email [email protected]. We may need to verify your identity and may retain limited information about the request as required by law. These rights can be subject to exceptions.

Children

The Services are intended for adults and are not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact [email protected] so we can take appropriate action.

Security

We use technical and organizational measures designed to protect personal data. Examples include scoped local filesystem access, webhook signature verification, signed offline entitlement tokens, restricted server-side provider credentials, secure-storage support for certain local credentials, and diagnostic scrubbing. No system is completely secure, and you should protect your device, accounts, credentials, and backups.

Changes to this policy

We may update this policy as the Services and law evolve. We will post the revised version here, update the date above, and provide additional notice where required. Review this policy periodically, especially before enabling a new cloud or managed feature.

Contact

For privacy questions or requests, contact Pasho at [email protected].

💡 Ideas+🐛 Bugs