Privacy Policy
This Privacy Policy explains what personal data Desklight ("we", "us") collects when you use the Desklight platform (the "Service"), how we use it, who we share it with, and your rights. We aim to be plain about it.
1. Data we collect
1.1 Account data
When you sign up we collect your email address, name (if provided), and a hashed password. If you sign in via a third-party identity provider, we receive whatever profile fields you authorize (typically email and name).
1.2 Workspace data
Inside the Service you create brands, posts, calendar entries, knowledge base entries, and team members. We store this data so the Service works. We also store any files, documents, photos, or brand assets you upload or generate.
1.3 Generated content
When you ask Allie or any AI agent to generate text, images, or video, we store the prompt, the output, and minimal metadata (model used, generation time) for delivery and revision history.
1.4 Connected services
If you connect a third-party service, we store the connection metadata and an OAuth token issued to us. Some connections use the provider's API directly and others use our connector provider, Composio. We use those tokens only for features you invoke, posts you approve or schedule, and optional publishing automations you explicitly enable. Tokens can be revoked at any time from Connectors in the app or from the third-party provider's settings.
Connectors fall into two groups:
- Storage and design — Dropbox, Google Drive, OneDrive, Figma. We store the OAuth token, your selected root folder (if any), and minimal file metadata (name, modified date, ID) for files you reference. We don't bulk-import file contents.
- Social publishing — Facebook, Instagram, Threads, LinkedIn, X, TikTok, YouTube, Pinterest. See section 1.5 below.
1.5 Social publishing platforms (Meta, LinkedIn, X, TikTok, YouTube, Pinterest)
When you connect a social account, we receive a limited, scoped set of data from that platform. We use it to identify and display the destination you select, show connected-account activity you request, publish posts you approve or schedule, run optional publishing automations you explicitly enable, and show the result of a publish. Facebook Page activity and Threads post history are retrieved only when you open that connection's details; Desklight does not persist those activity responses in its database.
| Platform | What we receive | What we do with it |
|---|---|---|
| Facebook (Meta) | OAuth access token; businesses and Pages you can access; Page IDs, names, profile metadata, and Page access token; recent Page post text, media, timestamps, and permalinks; and up to five recent comments per displayed post, including commenter ID, name, text, and timestamp | Let you select the correct Page; show recent Page activity and comments on demand; and create, edit, or delete a Page post when you request it. |
| Instagram (Meta) | OAuth access token, IG Business account ID, linked Facebook Page ID, IG media IDs after publish | Publish images, videos, and captions to the IG Business account. Read back the resulting media ID + permalink. |
| Threads (Meta) | OAuth access token; your Threads user ID and username; and your recent Threads post IDs, text, media type, media or thumbnail URL, timestamp, and permalink | Show your connected profile and recent posts on demand, publish text and media posts to your profile, and return the resulting post ID and permalink. |
| OAuth access token and your LinkedIn member URN | Publish posts to your personal feed. | |
| X | OAuth access token, your X user ID and handle | Publish posts. |
| TikTok | OAuth access token, your TikTok user ID and display name | Publish posts. |
| YouTube | OAuth access token, channel ID, channel display name | Upload videos with title, description, and thumbnail. |
| OAuth access token, your Pinterest account ID, board IDs, Pin IDs returned after publish | Create and schedule image Pins to the boards you select. Read back the resulting Pin ID and URL. |
We do not read your inbox, scrape your followers, republish connected-account data as new content, publish outside a post or automation you approve or enable, or use connected-platform data for advertising or training. Our use of information received from Meta APIs adheres to the Meta Platform Terms, including the Limited Use requirements. Desklight's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google's own handling of your data is governed by the Google Privacy Policy. Data obtained from Google APIs is never used to create, train, or improve any machine-learning or artificial-intelligence model.
You can revoke a single platform connection at any time from Connectors → Disconnect inside Desklight, or from the platform's own app-permissions settings. Disconnecting deletes the stored OAuth token and clears provider-account and target metadata immediately. A minimal record that the integration is disconnected may remain for security and operational history.
When Meta or Threads sends Desklight a valid signed data-deletion callback, we immediately revoke that connection and delete its token, selected publishing destinations, platform post identifiers and links, publishing-attempt receipts, and short-lived cached publishing responses. For retry safety and operational proof, we retain a minimized receipt containing a one-way HMAC of the platform identity and the internal workspace IDs affected. Terminal receipts are deleted after 90 days; the raw app-scoped platform user ID is not stored in the receipt.
To delete all data Desklight has received from connected platforms (along with the rest of your workspace), follow the steps in our Data Deletion page.
1.6 Billing data
Payments are processed by Stripe, Inc. We never see or store your full card number. We retain Stripe customer IDs, subscription IDs, plan tier, and high-level billing status (current/past due/canceled) for billing purposes.
1.7 Usage data
We collect basic logs about how the Service is used: timestamps, IP addresses, requested URLs, error events, and feature interactions. Logs are used to operate, secure, and improve the Service.
1.8 Cookies
We use a small number of strictly-necessary cookies to keep you signed in and to remember your UI preferences (theme, sort order, sidebar state). We do not use third-party advertising or cross-site tracking cookies.
2. How we use data
| Purpose | Legal basis (GDPR) |
|---|---|
| Operate and provide the Service | Contract |
| Process payments and manage subscriptions | Contract |
| Send transactional email (assignments, approvals, billing, role changes, password resets) | Contract / Legitimate interest |
| Detect and prevent abuse, fraud, or security incidents | Legitimate interest |
| Improve features and fix bugs | Legitimate interest |
| Comply with law (tax, accounting, lawful requests) | Legal obligation |
| Marketing email (only if you opt in or are an existing customer) | Consent / Legitimate interest |
We do not sell or rent your personal data. We do not use your User Content to train AI models — yours or anyone else's.
3. AI subprocessors
To deliver the Service we send your prompts and content to AI APIs operated by third parties. The current list:
| Subprocessor | Purpose |
|---|---|
| Anthropic, PBC | Claude — text reasoning, voice extraction, copy drafting |
| OpenAI, L.L.C. | Embeddings, optional image generation |
| Google LLC (Gemini API) | Image / video generation, brand-extraction vision |
| Replicate, Inc. | Hosted video model inference |
| Stripe, Inc. | Payment processing |
| Supabase, Inc. | Database, file storage, authentication |
| Resend Inc. | Transactional email delivery |
| Composio, Inc. | Third-party OAuth + connector tools |
| AgentMail, Inc. | Email handling for AI agents |
| Railway Corp. | Application hosting |
| Netlify, Inc. | Marketing site hosting |
| Functional Software, Inc. (Sentry) | Error monitoring, when enabled |
Each subprocessor has its own privacy and data-retention practices. Its public policies and the service terms applicable to Desklight also govern its processing.
4. Data retention and deletion
We retain workspace data while that workspace is active. A workspace administrator can delete one workspace through Settings → Danger zone → Delete workspace. If a login belongs to multiple workspaces, that action affects only the named workspace. To request deletion of your login profile and data across every workspace, or if you cannot sign in, follow the verified-request path in our Data Deletion instructions.
When you click Delete, your workspace is locked and enters a 28-day recovery window. During that window you can sign back in and click Restore, or email privacy@desklight.ai to waive recovery and request immediate erasure. If you do not restore, the remaining two days are an operations buffer: in the open beta, final database and object-storage erasure is operator-verified and processed no later than 30 days after the request; it is not represented as an unattended automatic purge.
The deletion includes any data Desklight received from connected social platforms (Facebook, Instagram, Threads, LinkedIn, X, TikTok, YouTube, Pinterest), including OAuth tokens, Page IDs, board/Pin IDs, media IDs, and connection metadata. Certain billing and transaction records may be retained after workspace erasure only where required or permitted by applicable tax, accounting, fraud-prevention, or dispute-resolution obligations.
We retain a minimal record of deletion requests and their completion to demonstrate compliance, for up to three years. This record identifies the request and its outcome; it does not retain the workspace content that was erased.
5. Sharing data
We share personal data only with:
- Subprocessors listed above, strictly to deliver the Service;
- Your authorized teammates inside your workspace;
- Authorities, when legally required, with a valid subpoena, court order, or other lawful process — and we will notify you unless prohibited.
6. International transfers
Our subprocessors may process data in countries other than the one where you live, as described in their applicable terms and privacy materials. Where data-protection law requires a transfer safeguard, Desklight uses the legally applicable mechanism documented for that service and deployment.
7. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your data ("right to erasure");
- Export your data in a machine-readable format ("data portability");
- Object to or restrict certain processing;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@desklight.ai. We will respond within the period required by applicable law.
8. Security
We take reasonable measures to protect your data, including TLS in transit, application-layer AES-256-GCM encryption for stored OAuth credentials, tenant-scoped access controls, and server-only service credentials. No system is perfectly secure; if we discover a breach affecting your personal data, we will notify you and the appropriate authorities as required by law.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@desklight.ai and we will delete it.
10. California residents (CCPA / CPRA)
California residents have additional rights, including the right to know what personal data we collect, the right to delete it, the right to correct it, the right to opt out of "sale" or "sharing" (we do neither), and the right to non-discrimination for exercising these rights. To exercise your rights, email privacy@desklight.ai. The categories of personal information we collect, our sources, business purposes, and disclosures are described above.
11. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will notify you by email or in the Service at least fourteen (14) days before it takes effect.
12. Contact
Privacy questions or requests: privacy@desklight.ai.
General support: support@desklight.ai.