Legal

Privacy Policy

Last updated September 10, 2026

Desk Envoy ("we", "our", or "us") is an experimental hobby product. It lets you hire AI envoys that chat on the web, send and receive email, talk in Slack and over iMessage, remember context, run scheduled routines and watches, and use an isolated cloud computer plus optional connected apps. This policy describes how we handle personal information while providing that service (the "Service").

The Service is not a consumer product with a service-level commitment. We may change, pause, or shut it down at any time. Do not submit data you cannot afford to lose.

1. Information We Collect

We collect information you provide and information created as you use the Service:

  • Account and waitlist: name, email address, authentication credentials and session data, optional waitlist notes, and admin role or disable status.
  • Workspace content: envoy names, roles, avatars, chat messages, email threads sent to a envoy inbox, Slack messages and iMessage texts a envoy is asked to handle, long-term memory, routines and watches, and files created or stored on a envoy's cloud computer. Chat, email, Slack, and iMessage attachments are read for the current reply and discarded; history keeps file names, not file bytes.
  • Connected apps: if you connect Gmail, GitHub, Notion, Linear, or similar tools, we store enough to keep the connection and retrieve only what a envoy requests through that app. Slack bot tokens are stored encrypted in our database. Other app credentials are held by the connection provider, not copied into model prompts.
  • Secrets vault: API tokens, passwords, and similar credentials you store or provide on a secret card are encrypted at rest with ENCRYPTION_KEY. A secret can be used only by envoys you grant. Raw values are injected only into the tool or computer execution path. They are not placed in model prompts, tool-result text returned to the model, activity logs, or chat message bodies.
  • Usage and spend: model, computer, email, Slack, and iMessage usage events, estimated cost, and monthly spend limits used to pause work when a cap is reached.
  • Technical data: IP address, browser and device data, request logs, and security events used to operate the Service, prevent abuse, and enforce rate limits.

2. How We Use Information

  • Provide, operate, secure, and debug the Service, including running models, computers, email, Slack, iMessage, and connected apps on your behalf.
  • Authenticate accounts, send waitlist and account email, and enforce two-factor authentication for operators.
  • Enforce usage and spend limits, including pausing envoy computers when a monthly cap is reached.
  • Respond to support requests and protect the Service from abuse.

We do not sell personal information. We do not use Customer Data to train public foundation models. Model providers still process prompts and outputs under their own terms.

3. Processors and Connected Services

Desk Envoy runs on third-party infrastructure. Those providers process data as needed to deliver their features. Their policies apply in addition to this one. Categories of processors we use today include:

  • Cloud hosting: application delivery and edge caching.
  • Managed database: accounts, envoys, messages, memory metadata, and usage.
  • Operational cache: rate limits, webhook deduplication, and similar keys.
  • Authentication: sessions and email one-time codes.
  • Email delivery: account email, waitlist email, and envoy inboxes on our email domain (not yours).
  • Language models: replies and embeddings through the model router you select.
  • Isolated cloud computers: a private desktop (browser, files, and terminal) for each envoy.
  • Connected apps: optional links to tools such as Gmail, GitHub, Notion, and Linear. Slack bot tokens are stored encrypted when you install Slack.
  • iMessage line: inbound and outbound texts on the shared iMessage line, including sender handles and message content, processed to route messages to the right envoy.
  • Web search: public search when an envoy looks something up.

When a envoy uses a connected app, that app's provider (for example Google or GitHub) also receives the data the envoy reads or writes there. Review those providers before connecting them. We cannot control how they retain or use that data.

4. AI Processing

Prompts, retrieved memory, email, Slack and iMessage text, files on an envoy computer, and connected-app results may be sent to the model provider you selected in order to generate a reply or take a tool action. Vault secrets and login passwords are excluded from that model context. Mutating tool calls can wait for an approval card before they run. File diffs shown in chat are a UI over structured change data, not an extra copy of your files sent to a third party. Output can be wrong, incomplete, or unsafe to act on. You are responsible for reviewing it.

5. Security and Retention

We use access controls, encrypted Slack tokens and vault secrets, signed inbound webhooks, and rate limits. Approval cards gate sends, writes, destructive computer work, connecting, and payment-like actions. No method of transmission or storage is completely secure. We do not guarantee that data will remain available, uncorrupted, or recoverable. Hobby infrastructure can fail, pause, or be deleted.

You can disconnect apps, delete envoys (which deletes that envoy's history, memory, and computer), and close your account from dashboard settings (password required). We keep records as long as needed to operate the Service, enforce limits, and debug incidents, then delete or anonymize them when they are no longer needed — or sooner if we shut the hobby project down.

6. Your Choices

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal data. Email the address we use to send you Desk Envoy account messages to make a request. We may need to verify it is you.

7. Children

The Service is not directed to children under 18. Do not create an account or submit personal information on behalf of a minor.

8. Changes

We may update this policy as the hobby product changes. The "Last updated" date above will change when we do. Continued use after an update means you accept the revised policy.

9. Contact

Questions about this policy: reply to a Desk Envoy account email or use the support address shown in the dashboard.