Privacy policy
Last updated 27 September 2026
This policy explains what personal data Deskburg handles, why, who else sees it, and the rights you have. Ferskfra AS is the data controller. Contact us at support@deskburg.com.
1. What we collect
- Account: your email address and your password (stored only as a secure hash), and when you signed up.
- Your office: the agents you hire and how you set them up, tasks, transcripts of the agents' work, results and files they create, the notes agents keep in their notebooks, files you upload, skills, pinboard notes, desk links and office layouts.
- Keys and connections: API keys for AI providers and secrets for MCP servers, encrypted before they're stored. We show only the last four characters of a key.
- Usage and billing: how much work agents did and what it cost, your budget, your plan and credit balance, and your Stripe customer number. We never see or store your card details.
- Technical data: our hosting providers log requests, including IP address and browser, to run and protect the service.
2. Why we use it
- To provide Deskburg to you under our terms: your account, your office and running your agents (contract).
- To bill you and keep the records the law requires (contract and legal obligation).
- To keep Deskburg secure, prevent abuse and fix problems (legitimate interest).
- To send emails you need, such as confirming your address or resetting your password (contract). We don't send marketing emails.
We don't sell your data, we don't show ads, and we don't use your content to train AI models.
3. What happens when an agent works
To do a task, an agent sends the task, its instructions, the files and links you gave it, and the results of its tools to the AI provider it runs on: Anthropic (Claude), OpenAI or Google (Gemini).
With your own key, that's under your agreement with the provider. With Deskburg credit, it goes through Vercel AI Gateway on our account. Either way, the provider's own terms and privacy policy apply to what they receive.
When agents search or read the web, that happens through the AI provider. When they use an MCP server you connected, that server receives the tool request.
With the workshop switched on, a Claude agent runs code in Anthropic's sandbox (no internet access). Files it makes there are copied to Deskburg and then deleted from Anthropic; Anthropic keeps sandbox data for up to 30 days.
4. Who else handles your data
- Supabase: database, sign-in and file storage, in the EU (Ireland).
- Brevo: sends account emails such as address confirmation and password reset (EU, France).
- Vercel: hosts the app and runs Vercel AI Gateway for credit (United States and worldwide).
- Stripe: payments. Stripe sells your subscription and credit as merchant of record, so it is responsible for the payment data it collects.
- The AI providers and MCP servers you choose to use (section 3).
Our service providers only process data on our instructions, under data processing agreements.
5. Transfers outside the EU/EEA
Some of these providers are based in, or process data in, the United States. Where that happens, the transfer is protected by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
6. How long we keep it
- Your account and office: as long as you have an account.
- When you delete your account, your office, files and login are deleted straight away. Copies in backups disappear as the backups are replaced on their normal cycle.
- Records we must keep for accounting: as long as accounting law requires.
- Hosting logs: a short time, as set by our hosting providers.
7. Cookies
Deskburg only uses what it needs to work: a sign-in cookie that keeps you logged in, and a small note in your browser that remembers which agent results you've already seen. To know how many people visit, we count page views per page and day, without cookies and without storing your IP address or any identifier; browsers that send Global Privacy Control aren't counted. No advertising and no tracking, so there's nothing to consent to. Stripe's checkout pages set their own cookies.
8. Your rights
You can ask to see the data we hold about you, get a copy of it, correct it, or have it deleted. You can also object to or ask us to limit how we use it.
The quickest way to delete everything is Settings → Delete account. For anything else, write to support@deskburg.com and we'll answer within a month.
If you think we handle your data wrongly, you can complain to Datatilsynet or to the data protection authority where you live.
9. Security
Everything is sent over encrypted connections. API keys and server secrets are encrypted before storage and only decrypted on our servers at the moment an agent needs them; they are never sent to your browser. Each office's data is kept apart in the database, so no one else can read it. Files agents create are downloaded as attachments and never run on our site.
10. Children
Deskburg is for people aged 18 and over. We don't knowingly collect data about children.
11. Changes
If we change this policy in a way that matters, we'll tell you by email or in the app before the change takes effect.
12. Contact
Privacy questions and requests: support@deskburg.com.
Ferskfra AS · Org. no. 936 787 207 · Ekebergveien 5b, 0192 Oslo, Norway