← desklight.ai

Privacy Policy

Last updated: August 1, 2026

This Privacy Policy explains what personal data Desklight ("we", "us") collects when you use the Desklight platform (the "Service"), how we use it, who we share it with, and your rights. We aim to be plain about it.

1. Data we collect

1.1 Account data

When you sign up we collect your email address, name (if provided), and a hashed password. If you sign in via a third-party identity provider, we receive whatever profile fields you authorize (typically email and name).

1.2 Workspace data

Inside the Service you create brands, posts, calendar entries, knowledge base entries, and team members. We store this data so the Service works. We also store any files, documents, photos, or brand assets you upload or generate.

1.3 Generated content

When you ask Allie or any AI agent to generate text, images, or video, we store the prompt, the output, and minimal metadata (model used, generation time) for delivery and revision history.

1.4 Connected services

If you connect a third-party service, we store the connection metadata and an OAuth token issued to us. Some connections use the provider's API directly and others use our connector provider, Composio. We use those tokens only for features you invoke, posts you approve or schedule, and optional publishing automations you explicitly enable. Tokens can be revoked at any time from Connectors in the app or from the third-party provider's settings.

Connectors fall into two groups:

1.5 Social publishing platforms (Meta, LinkedIn, X, TikTok, YouTube, Pinterest)

When you connect a social account, we receive a limited, scoped set of data from that platform. We use it to identify and display the destination you select, show connected-account activity you request, publish posts you approve or schedule, run optional publishing automations you explicitly enable, and show the result of a publish. Facebook Page activity and Threads post history are retrieved only when you open that connection's details; Desklight does not persist those activity responses in its database.

PlatformWhat we receiveWhat we do with it
Facebook (Meta) OAuth access token; businesses and Pages you can access; Page IDs, names, profile metadata, and Page access token; recent Page post text, media, timestamps, and permalinks; and up to five recent comments per displayed post, including commenter ID, name, text, and timestamp Let you select the correct Page; show recent Page activity and comments on demand; and create, edit, or delete a Page post when you request it.
Instagram (Meta) OAuth access token, IG Business account ID, linked Facebook Page ID, IG media IDs after publish Publish images, videos, and captions to the IG Business account. Read back the resulting media ID + permalink.
Threads (Meta) OAuth access token; your Threads user ID and username; and your recent Threads post IDs, text, media type, media or thumbnail URL, timestamp, and permalink Show your connected profile and recent posts on demand, publish text and media posts to your profile, and return the resulting post ID and permalink.
LinkedIn OAuth access token and your LinkedIn member URN Publish posts to your personal feed.
X OAuth access token, your X user ID and handle Publish posts.
TikTok OAuth access token, your TikTok user ID and display name Publish posts.
YouTube OAuth access token, channel ID, channel display name Upload videos with title, description, and thumbnail.
Pinterest OAuth access token, your Pinterest account ID, board IDs, Pin IDs returned after publish Create and schedule image Pins to the boards you select. Read back the resulting Pin ID and URL.

We do not read your inbox, scrape your followers, republish connected-account data as new content, publish outside a post or automation you approve or enable, or use connected-platform data for advertising or training. Our use of information received from Meta APIs adheres to the Meta Platform Terms, including the Limited Use requirements. Desklight's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google's own handling of your data is governed by the Google Privacy Policy. Data obtained from Google APIs is never used to create, train, or improve any machine-learning or artificial-intelligence model.

You can revoke a single platform connection at any time from Connectors → Disconnect inside Desklight, or from the platform's own app-permissions settings. Disconnecting deletes the stored OAuth token and clears provider-account and target metadata immediately. A minimal record that the integration is disconnected may remain for security and operational history.

When Meta or Threads sends Desklight a valid signed data-deletion callback, we immediately revoke that connection and delete its token, selected publishing destinations, platform post identifiers and links, publishing-attempt receipts, and short-lived cached publishing responses. For retry safety and operational proof, we retain a minimized receipt containing a one-way HMAC of the platform identity and the internal workspace IDs affected. Terminal receipts are deleted after 90 days; the raw app-scoped platform user ID is not stored in the receipt.

To delete all data Desklight has received from connected platforms (along with the rest of your workspace), follow the steps in our Data Deletion page.

1.6 Billing data

Payments are processed by Stripe, Inc. We never see or store your full card number. We retain Stripe customer IDs, subscription IDs, plan tier, and high-level billing status (current/past due/canceled) for billing purposes.

1.7 Usage data

We collect basic logs about how the Service is used: timestamps, IP addresses, requested URLs, error events, and feature interactions. Logs are used to operate, secure, and improve the Service.

1.8 Cookies

We use a small number of strictly-necessary cookies to keep you signed in and to remember your UI preferences (theme, sort order, sidebar state). We do not use third-party advertising or cross-site tracking cookies.

2. How we use data

PurposeLegal basis (GDPR)
Operate and provide the ServiceContract
Process payments and manage subscriptionsContract
Send transactional email (assignments, approvals, billing, role changes, password resets)Contract / Legitimate interest
Detect and prevent abuse, fraud, or security incidentsLegitimate interest
Improve features and fix bugsLegitimate interest
Comply with law (tax, accounting, lawful requests)Legal obligation
Marketing email (only if you opt in or are an existing customer)Consent / Legitimate interest

We do not sell or rent your personal data. We do not use your User Content to train AI models — yours or anyone else's.

3. AI subprocessors

To deliver the Service we send your prompts and content to AI APIs operated by third parties. The current list:

SubprocessorPurpose
Anthropic, PBCClaude — text reasoning, voice extraction, copy drafting
OpenAI, L.L.C.Embeddings, optional image generation
Google LLC (Gemini API)Image / video generation, brand-extraction vision
Replicate, Inc.Hosted video model inference
Stripe, Inc.Payment processing
Supabase, Inc.Database, file storage, authentication
Resend Inc.Transactional email delivery
Composio, Inc.Third-party OAuth + connector tools
AgentMail, Inc.Email handling for AI agents
Railway Corp.Application hosting
Netlify, Inc.Marketing site hosting
Functional Software, Inc. (Sentry)Error monitoring, when enabled

Each subprocessor has its own privacy and data-retention practices. Its public policies and the service terms applicable to Desklight also govern its processing.

4. Data retention and deletion

We retain workspace data while that workspace is active. A workspace administrator can delete one workspace through Settings → Danger zone → Delete workspace. If a login belongs to multiple workspaces, that action affects only the named workspace. To request deletion of your login profile and data across every workspace, or if you cannot sign in, follow the verified-request path in our Data Deletion instructions.

When you click Delete, your workspace is locked and enters a 28-day recovery window. During that window you can sign back in and click Restore, or email privacy@desklight.ai to waive recovery and request immediate erasure. If you do not restore, the remaining two days are an operations buffer: in the open beta, final database and object-storage erasure is operator-verified and processed no later than 30 days after the request; it is not represented as an unattended automatic purge.

The deletion includes any data Desklight received from connected social platforms (Facebook, Instagram, Threads, LinkedIn, X, TikTok, YouTube, Pinterest), including OAuth tokens, Page IDs, board/Pin IDs, media IDs, and connection metadata. Certain billing and transaction records may be retained after workspace erasure only where required or permitted by applicable tax, accounting, fraud-prevention, or dispute-resolution obligations.

We retain a minimal record of deletion requests and their completion to demonstrate compliance, for up to three years. This record identifies the request and its outcome; it does not retain the workspace content that was erased.

5. Sharing data

We share personal data only with:

6. International transfers

Our subprocessors may process data in countries other than the one where you live, as described in their applicable terms and privacy materials. Where data-protection law requires a transfer safeguard, Desklight uses the legally applicable mechanism documented for that service and deployment.

7. Your rights

Depending on where you live, you have the right to:

To exercise any of these rights, email privacy@desklight.ai. We will respond within the period required by applicable law.

8. Security

We take reasonable measures to protect your data, including TLS in transit, application-layer AES-256-GCM encryption for stored OAuth credentials, tenant-scoped access controls, and server-only service credentials. No system is perfectly secure; if we discover a breach affecting your personal data, we will notify you and the appropriate authorities as required by law.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@desklight.ai and we will delete it.

10. California residents (CCPA / CPRA)

California residents have additional rights, including the right to know what personal data we collect, the right to delete it, the right to correct it, the right to opt out of "sale" or "sharing" (we do neither), and the right to non-discrimination for exercising these rights. To exercise your rights, email privacy@desklight.ai. The categories of personal information we collect, our sources, business purposes, and disclosures are described above.

11. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we will notify you by email or in the Service at least fourteen (14) days before it takes effect.

12. Contact

Privacy questions or requests: privacy@desklight.ai.
General support: support@desklight.ai.


Terms of Service · Refund Policy · Data Deletion · Home