Privacy

What we hold, and why

WhoseDesk holds other companies' working data. This page says exactly what that means: what is collected, who else touches it, how long it stays, and how to get it back.

Last updated 2026-08-14 · applies to whosedesk.app and the WhoseDesk apps

1. Who we are

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], trading as WhoseDesk. Privacy questions go to privacy@whosedesk.app and reach a person, not a queue.

If you are in the UK or EU and need a named data-protection contact for a records request, use the same address and say so — it will be routed to [NAMED DP CONTACT].

2. Two different roles, and which one applies to you

This matters more than it sounds, because it decides who you ask for what.

3. What we collect

CategoryWhat it actually isWhere it comes from
Account Name, email address, avatar URL, role, organisation name and slug You, your admin's invitation, or your identity provider
Sign-in Session records (an opaque token, stored hashed), the IP address and browser user-agent at sign-in, sign-in attempt timestamps, and — only if you set them — a password hash and an encrypted two-factor secret Your browser or app at each sign-in
Identity provider For Google sign-in: your Google account identifier, verified email and, for Workspace accounts, your domain. For Enterprise single sign-on: the subject identifier and email your own provider asserts Google, or your employer's provider
Content Card titles, pass notes, comments, due dates, labels, time entries and file attachments Your organisation's members
Usage Last-seen timestamps and an event record of work moving between people — which is the product, not analytics Your use of the service
Billing Your Stripe customer and subscription identifiers, plan, seat count and subscription status Stripe, when you subscribe

We never see card numbers. Payment details go directly to Stripe and are never transmitted to or stored on our servers. What we hold is an identifier and a status.

No analytics, no advertising, no third-party trackers. There is no Google Analytics, no advertising pixel and no session-replay tool in the product or on this site. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

4. Why we hold it

5. Who else processes it

Every sub-processor, in full. This is the list procurement reviews ask for.

ProcessorWhat forWhat reaches them
Amazon Web Services
us-east-1, United States
Hosting, database, file storage, background jobs, and the sending of transactional email (Amazon SES) Everything the service holds
Stripe Payments and subscription management Billing contact details and payment details, which you give to Stripe directly
Google "Continue with Google" sign-in only Only the sign-in exchange itself. Your boards are never sent to Google.
Anthropic The in-app help assistant Only the text you type into the help widget, together with our product manual. Your cards, comments and attachments are not sent, and the assistant has no access to them. If you would rather not use it, email support instead.
Apple, Google and Mozilla push services Delivering push notifications to the device you enabled them on The notification text — typically a card title and who passed it
Your own identity provider
Enterprise single sign-on only
Authenticating your people Nothing of ours. Your provider tells us who you are; we tell it nothing about your work.

We will update this page before adding a sub-processor, and organisations on annual plans can ask to be notified when we do.

6. Where it is stored

In the United States, in Amazon Web Services' us-east-1 region. Backups are held in the same region.

If your organisation is in the UK or EEA, this is an international transfer, and it is made under [TRANSFER MECHANISM — Standard Contractual Clauses / UK IDTA / adequacy]. [Confirm with counsel before selling into the EU or UK.]

7. How long we keep it

Plainly, including where the answer is not yet what we want it to be.

8. Your rights

Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, take it elsewhere in a portable form, object to processing based on legitimate interests, or complain to a regulator.

Ask your own organisation first for anything on the boards. Your admins can export the whole organisation from Settings, correct your details, and deactivate or remove your account. For requests about the account layer — or if your organisation cannot help — write to privacy@whosedesk.app. We answer within 30 days, and usually far sooner.

Exercising a right never costs you access to the service.

9. How it is protected

Specifics, because "bank-level security" means nothing:

What we do not claim: we hold no SOC 2, ISO 27001 or equivalent certification, and we will not imply otherwise on a sales call. If your procurement process requires one, tell us before you buy rather than after.

10. When our staff can see your data

Rarely, and never invisibly.

We will tell an organisation's owners if we have impersonated one of their users other than at their own request. [Confirm this commitment before publishing — it is one we intend to keep, not a legal requirement.]

11. Children

WhoseDesk is a workplace tool. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will remove it.

12. Changes to this policy

We will post the new version here with a new date. If a change materially affects your rights or how we use your data, we will email the owners of every organisation 30 days before it takes effect, so there is time to object or leave.