Privacy Policy
Last updated 2026-08-20
This Privacy Policy explains how DeskQ (https://deskq.app) collects, uses, and shares information when you use our website, operator iOS/Android app, and product-trained support platform (the "Service"). By using the Service you agree to this policy. For questions, use our contact form or the chat desk on this site.
1. Who we are
DeskQ provides product-trained AI support desks you can train from a website URL, embed on your product, and connect to human handoff tickets by email. Operators can also sign in to the DeskQ iOS and Android app to answer tickets and live chats. We are the controller of personal data we process for our own accounts, billing, and marketing site. When you use DeskQ to support your end users, you are typically the controller of visitor chat and ticket content; we process that data on your behalf to provide the Service.
2. Information we collect
Account data. Name, email address, password (stored hashed), and optional profile details you provide when you sign up or that an admin provisions for you.
Billing data. Subscription plan, Stripe customer and subscription identifiers, and payment history. Card numbers are processed by Stripe; we do not store full card details on our servers.
Product usage. Desks you create, knowledge sources (e.g. trained URLs, FAQs, GitHub repos you connect), chat conversations, tickets, notification preferences, and usage meters (AI replies, desks) for plan limits.
Visitor / end-user data (your customers). Messages sent through the embed, optional name and email from handoff forms, page URL, and technical metadata needed to run the chat (e.g. visitor id, user agent). Content depends on what visitors and your team write.
Communications. Messages you send to support or via contact forms, and transactional email events (delivery, bounces) from our email provider.
Technical & analytics data. IP address, browser type, device information, approximate location from edge headers, pages visited, and product events. We use Google Analytics 4 only after you accept optional analytics on the website, plus first-party visit logging (hashed daily unique visitors) to understand traffic.
3. How we use information
- Provide, secure, and improve the Service
- Authenticate users and protect against abuse
- Process subscriptions and send billing receipts or failures
- Deliver transactional email (welcome, password reset, tickets, onboarding)
- Run AI replies for your desks using the models you select and the knowledge you attach
- Measure product and marketing performance
- Comply with law and enforce our Terms of Service
4. AI processing
Chat messages and knowledge you configure may be sent to third-party AI providers (for example xAI / Grok) to generate replies. Do not put secrets you cannot share with those processors into training content or chat. You are responsible for having a lawful basis to process your end users' data through DeskQ and any AI model you enable.
5. How we share information
We share data with service providers that help us operate the Service, including:
- Hosting & database (e.g. Vercel, Neon)
- Payments (Stripe)
- Email (Resend)
- AI inference (xAI and any model provider you configure)
- Analytics (Google Analytics 4), only if you accept optional analytics cookies
- Push delivery for the operator app (Expo / Apple / Google), if you enable notifications
We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale. We do not sell personal information for money, and we do not share it for cross-context behavioral advertising as defined under the CCPA/CPRA in exchange for valuable consideration.
6. Cookies and similar technologies
Essential: a session cookie (website) or a bearer token in the operator app's secure storage so you stay signed in. Optional: Google Analytics cookies, off until you tap Accept analytics on the website. First-party visit metrics may use hashed technical identifiers without advertising cookies. Blocking session cookies will prevent website sign-in. The iOS/Android app does not use advertising identifiers (IDFA) or App Tracking Transparency.
7. Operator mobile app
The DeskQ iOS and Android app is for operators (account holders), not visitors. It stores a session token on-device and, if you enable push, an Expo push token so we can notify you of new tickets or chats. You can turn those notifications off in the app or system settings. Billing and plan changes are not sold in the app — manage them on https://deskq.app.
8. Data retention
We keep account and product data while your account is active and as needed for billing, security, and legal obligations. You may delete your account from the website account page or from the operator app (More → Delete account). That signs you out, cancels paid subscriptions, and starts a 30-day purge. Residual backups may persist for a limited period. Chat and ticket data is retained for the life of your account unless you delete specific records or your account.
9. Security
We use industry-standard safeguards (HTTPS, hashed passwords, access-controlled infrastructure). No method of transmission or storage is 100% secure; use strong passwords and protect API keys and embed keys.
10. International transfers
We and our processors may process data in the United States and other countries. Where required, we rely on appropriate transfer mechanisms provided by our vendors.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. California residents may have rights under the CCPA/CPRA (including to know, delete, and correct). To exercise rights, use our contact form or account deletion in the product. We will not discriminate against you for exercising privacy rights.
12. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children.
13. Changes
We may update this policy from time to time. The "Last updated" date at the top will change. Material changes may be communicated by email or an in-product notice.
14. Contact
Privacy requests: contact form or the chat desk on this site. Related: Terms of Service.
This policy is provided for transparency and product compliance (e.g. Stripe). It is not formal legal advice. Have counsel review if you operate in regulated markets.