Privacy Policy
Effective date: 29 July 2026
Deski ("Deski", "we", "us") is a local-first desktop time-tracker. Our guiding principle is simple: your data stays on your device. This policy explains, in plain language, exactly what we do and don't hold — for the Deski desktop app, for signing in and billing, and for this website.
1. The short version
- The Deski app collects no personal data and sends nothing to us. All your tracking and time blocks stay in a local file on your own device.
- The only personal data we hold is your email address — used to sign you in and check your subscription, or, if you asked to be told about the launch, to hold your place on the waitlist.
- Payments are handled by Freemius. Your card and billing details go to Freemius, never to us.
- You can erase everything we hold at any time from within the app.
2. Data the Deski app stores (on your device only)
To show you your time blocks, charts and tags, Deski records the following locally, in a single SQLite database file on your computer:
- Time blocks — start/end times of tracked sessions, and whether they were automatic or manual.
- Activity tallies — counts of mouse and keyboard activity used to gauge focus.
- Your labels — tag names, colours, and any session names you add.
- Your settings — preferences such as theme, date format, and tracking options.
This information is never uploaded. It remains under your control on your machine.
3. Privacy safeguards built into tracking
Deski is deliberately designed to capture as little as possible:
- Keyboard tracking is count-only. Deski records how often you type — it never records which keys you press. There is no keylogging.
- No mouse coordinates. Deski records that a click or movement happened, never where on screen your pointer was.
- Secure deletion. When you clear your data, it is securely removed from disk, not merely hidden.
- You choose what to track. Mouse and keyboard tracking can each be turned off in Settings.
4. Signing in
To use your subscription, you sign in with your email address. There are no passwords: we email you a 6-digit code to confirm it's you.
- Your email is the only personal detail we store for your account. We use it to sign you in, to check whether your subscription is active, and to send you service messages about your account — for example a change to the price, an update to the Terms, a security notice, or news that the service is being discontinued. These are not marketing emails: they are part of running your subscription, so you cannot unsubscribe from them while you have an account. We will never send you marketing without your separate, explicit opt-in. (If you joined the waitlist or applied to the beta, see Section 8 — that is a separate purpose you opted into.)
- Sign-in codes expire after 15 minutes.
- Sign-in sessions expire after 90 days of inactivity, after which you'll sign in again.
Legal basis: we process this data because it is necessary to provide the service you signed up for (performance of a contract, Art. 6(1)(b) GDPR). Security and abuse-prevention processing (Section 7) relies on our legitimate interest (Art. 6(1)(f) GDPR).
5. Payments
Payments are handled by Freemius, which acts as our Merchant of Record. When you subscribe, your card details, billing address and tax information are collected and held by Freemius — they never pass through us and we never store them. Freemius's handling of that data is covered by their own privacy policy.
6. This website
This site is hosted on Cloudflare Pages and uses Cloudflare Web Analytics, a privacy-first measurement tool that uses no cookies and does no cross-site tracking. We use it only to see rough visitor numbers.
The homepage includes a demo video that plays via YouTube's privacy-enhanced mode (youtube-nocookie.com). Nothing is requested from YouTube or Google when you visit the page — their player, and their privacy policy, apply only if you press play.
Service providers (subprocessors)
A few trusted providers process data on our behalf, each under their own agreements and privacy policies:
- Freemius — payments & Merchant of Record (privacy policy).
- Postmark (an ActiveCampaign service) — transactional email delivery, used only to send sign-in codes and account emails (privacy policy).
- Fly.io — hosts the sign-in service (privacy policy).
- Upstash — managed Redis database (provisioned via Fly.io, EU region) holding sign-in session state with automatic expiry, and waitlist/beta-application entries (privacy policy).
- Cloudflare — website hosting & DNS, and Turnstile, the bot check on our waitlist and beta-application form. To tell a person from a script, Turnstile processes your IP address and browser signals at the moment you submit the form. It does not use tracking cookies and is not used to profile or advertise to you (privacy policy).
International transfers: the sign-in service runs in the EU (Frankfurt). Some providers above (e.g. Freemius, Postmark, Cloudflare) may process data in the United States; where they do, transfers are protected by recognised safeguards such as the EU–US Data Privacy Framework and/or Standard Contractual Clauses, per each provider's terms.
7. Retention & security
- Sign-in sessions expire after 90 days of inactivity; sign-in codes after 15 minutes.
- If you cancel, any feedback you leave is stored pseudonymously — tied to a one-way hash of your email, not the email itself.
- Operational monitoring: we may view aggregate counts of active sessions (e.g. how many users are signed in) to operate the service. These are internal figures derived from the sign-in data above — no email or other personal detail is exposed — and are never shared.
- Waitlist & beta applications are kept until Deski launches plus six months, or until you remove yourself — whichever comes first. Unconfirmed signups are discarded automatically after 24 hours. See Section 8.
Security & abuse prevention
To protect the sign-in service from abuse, we rate-limit and detect brute-force attempts. For this we process source IP addresses only as a salted hash — the raw IP is never stored or logged. This hashed data is held in memory briefly (up to one hour) and, on a blocked attack, written to short-lived server logs. Legal basis: our legitimate interest in the security of the service.
The waitlist and beta-application form is additionally protected by Cloudflare Turnstile, a bot check that runs when you submit it. Turnstile processes your IP address and browser signals to tell a person from a script; it sets no tracking cookies and is not used to profile or advertise to you. Legal basis: our legitimate interest in keeping the form free of automated abuse.
8. Waitlist & beta applications
Before launch you can ask us to tell you when Deski is ready (waitlist), or ask to be one of the early testers (beta application). Both are entirely optional, and separate from having a Deski account.
- What we collect — your email address. If you apply to the beta, also the short note you write about how you'd use Deski. That's all: no name, no company, no tracking of how you found us.
- Double opt-in — we email you a confirmation link and store nothing against your address until you click it. If you never confirm, the pending signup is deleted automatically within 24 hours.
- We do not store your IP address for this. The confirmation click, and its timestamp, is our record that you agreed.
- What we send you — the confirmation email, then a single announcement when Deski launches (waitlist) or an invitation if you're selected (beta). We never sell or share your address.
- Marketing is optional and separate — the form has an unticked box you may use to ask for occasional product news and tips. Leaving it unticked changes nothing about your place on the list; you still get the launch announcement. If you tick it, you can withdraw at any time using the unsubscribe link in those emails, and that does not remove you from the waitlist.
Legal basis: your consent (Art. 6(1)(a) GDPR) — given by clicking the confirmation link, and separately by ticking the marketing box if you choose to.
Withdrawing consent: every email we send you includes a one-click removal link that deletes your address immediately — no sign-in, no reply, no questions. If you were also on the beta tester list, that access is revoked at the same time. You can equally write to [email protected]. Withdrawing consent does not affect processing carried out beforehand.
9. Your rights
Your on-device data is always yours to view, export or delete from within the app — it never reaches us. For the little we do hold (your email, sign-in sessions, pseudonymized feedback), you have the following rights, most of which you can exercise yourself:
- Access (Art. 15 GDPR) — ask us for a copy of the personal data we hold about you. Given how little we store, this is typically just your email address and session dates.
- Rectification (Art. 16) — have incorrect data corrected. To change your sign-in email, delete your data and sign in with the new address.
- Erasure (Art. 17) — self-service: when cancelling in the app (Settings → Account), tick "Also delete my account data now" to erase every session, sign-in code, rate-limit entry and feedback row we hold for you. Sign-in data also expires automatically after 90 days of inactivity. You can also email us.
- Restriction of processing (Art. 18) and objection (Art. 21) — you may object to, or ask us to restrict, processing based on our legitimate interests (the security processing in Section 7).
- Data portability (Art. 20) — receive the data you provided in a machine-readable format. (Your tracking data is already fully portable: it lives in a local file on your device.)
- Complaint (Art. 77) — lodge a complaint with a data-protection supervisory authority, for example the authority in your EU member state of residence.
To exercise any of these, email [email protected] from the address associated with your account and we will respond within one month.
- To stop billing, cancel your subscription. For rights over billing data (card, invoices, tax records), contact Freemius — as Merchant of Record they are the controller of that data and retain invoices as required by law.
10. Children's privacy
Deski is not directed to children and we do not knowingly collect information from them.
11. Changes to this policy
We may update this policy as the app evolves. When we do, we will revise the "Effective date" above. Material changes will be reflected on this page.
12. Contact & data controller
The data controller for the processing described in this policy (except billing data, where Freemius is the controller) is the operator of Deski: Hadhi Tech, Dar es Salaam, Tanzania.
Questions about this policy, and requests to exercise your rights, can be sent to [email protected].
See also our Terms & Conditions.