Privacy
WhoseDesk holds other companies' working data. This page says exactly what that means: what is collected, who else touches it, how long it stays, and how to get it back.
Last updated 2026-08-14 · applies to whosedesk.app and the WhoseDesk apps
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], trading as WhoseDesk. Privacy questions go to privacy@whosedesk.app and reach a person, not a queue.
If you are in the UK or EU and need a named data-protection contact for a records request, use the same address and say so — it will be routed to [NAMED DP CONTACT].
This matters more than it sounds, because it decides who you ask for what.
| Category | What it actually is | Where it comes from |
|---|---|---|
| Account | Name, email address, avatar URL, role, organisation name and slug | You, your admin's invitation, or your identity provider |
| Sign-in | Session records (an opaque token, stored hashed), the IP address and browser user-agent at sign-in, sign-in attempt timestamps, and — only if you set them — a password hash and an encrypted two-factor secret | Your browser or app at each sign-in |
| Identity provider | For Google sign-in: your Google account identifier, verified email and, for Workspace accounts, your domain. For Enterprise single sign-on: the subject identifier and email your own provider asserts | Google, or your employer's provider |
| Content | Card titles, pass notes, comments, due dates, labels, time entries and file attachments | Your organisation's members |
| Usage | Last-seen timestamps and an event record of work moving between people — which is the product, not analytics | Your use of the service |
| Billing | Your Stripe customer and subscription identifiers, plan, seat count and subscription status | Stripe, when you subscribe |
We never see card numbers. Payment details go directly to Stripe and are never transmitted to or stored on our servers. What we hold is an identifier and a status.
No analytics, no advertising, no third-party trackers. There is no Google Analytics, no advertising pixel and no session-replay tool in the product or on this site. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Every sub-processor, in full. This is the list procurement reviews ask for.
| Processor | What for | What reaches them |
|---|---|---|
| Amazon Web Services us-east-1, United States |
Hosting, database, file storage, background jobs, and the sending of transactional email (Amazon SES) | Everything the service holds |
| Stripe | Payments and subscription management | Billing contact details and payment details, which you give to Stripe directly |
| "Continue with Google" sign-in only | Only the sign-in exchange itself. Your boards are never sent to Google. | |
| Anthropic | The in-app help assistant | Only the text you type into the help widget, together with our product manual. Your cards, comments and attachments are not sent, and the assistant has no access to them. If you would rather not use it, email support instead. |
| Apple, Google and Mozilla push services | Delivering push notifications to the device you enabled them on | The notification text — typically a card title and who passed it |
| Your own identity provider Enterprise single sign-on only |
Authenticating your people | Nothing of ours. Your provider tells us who you are; we tell it nothing about your work. |
We will update this page before adding a sub-processor, and organisations on annual plans can ask to be notified when we do.
In the United States, in Amazon Web Services' us-east-1 region.
Backups are held in the same region.
If your organisation is in the UK or EEA, this is an international transfer, and it is made under [TRANSFER MECHANISM — Standard Contractual Clauses / UK IDTA / adequacy]. [Confirm with counsel before selling into the EU or UK.]
Plainly, including where the answer is not yet what we want it to be.
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, take it elsewhere in a portable form, object to processing based on legitimate interests, or complain to a regulator.
Ask your own organisation first for anything on the boards. Your admins can export the whole organisation from Settings, correct your details, and deactivate or remove your account. For requests about the account layer — or if your organisation cannot help — write to privacy@whosedesk.app. We answer within 30 days, and usually far sooner.
Exercising a right never costs you access to the service.
Specifics, because "bank-level security" means nothing:
What we do not claim: we hold no SOC 2, ISO 27001 or equivalent certification, and we will not imply otherwise on a sales call. If your procurement process requires one, tell us before you buy rather than after.
Rarely, and never invisibly.
We will tell an organisation's owners if we have impersonated one of their users other than at their own request. [Confirm this commitment before publishing — it is one we intend to keep, not a legal requirement.]
WhoseDesk is a workplace tool. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will remove it.
We will post the new version here with a new date. If a change materially affects your rights or how we use your data, we will email the owners of every organisation 30 days before it takes effect, so there is time to object or leave.