Where and how
ComputerOpen Settings, then Legal and Privacy Policy, section on data storage. PhoneOpen Settings, then Legal and Privacy. The primary database is PostgreSQL on Supabase, hosted in the United States, encrypted at rest with AES-256; files such as logos and PDF reports are in Supabase Storage in the United States; the assistant's short-term memory is in Upstash Redis in the United States. Every table is isolated per business at the database level, so one business can never read another's rows. Provider backups rotate on the provider's schedule — typically up to thirty days — and residual copies age out of them after that.
Where and how
ComputerOpen Settings, then Legal and Privacy Policy, section 4. PhoneOpen Settings, then Legal and Privacy. No and no. Your data is not sold, licensed or shared for advertising. What you type to Des, and the documents you attach, go to Anthropic's Claude API for that one request and are not retained by Anthropic for training under its API data policy; DeskOps does not use your business data to train any model either. Voice audio streams to ElevenLabs for speech and is not kept on our servers; the text transcript stays on your account and is purged on a rolling ninety-day schedule.
Where and how
ComputerOpen Settings, then Security shows your sessions, nothing there is a DeskOps employee. Connection credentials — Stripe, Square, QuickBooks, your bank — are encrypted before they are stored and are never visible to any DeskOps employee, never sent to the browser and never logged. Support access to an account, when it happens, is logged server-side. Contractor taxpayer identification numbers are encrypted so that no signed-in session, including your own, can read the full number; only the last four digits ever appear in the app.
Who in my business can see what
ComputerOpen Settings, then Team & seats and Access & permissions. No. Wealth, Foresight, Taxes, The Record, Businesses, Boost, Messaging and Settings are owner-only pages; a manager, bookkeeper or technician never sees them, and a link to one bounces them back. Field seats are narrower still: their own jobs, the schedule and Ask Des, with every money page off limits. Des follows the same lines — asked about revenue, pay or taxes, it tells a technician plainly that those are the owner's.
Who in my business can see what
ComputerOpen Get Paid, open a sent invoice or quote, then the customer link. PhoneOpen Get Paid, the invoice or quote, then the link. Only what that document is for. A pay link shows the invoice and a way to pay it; a quote link shows the quote and a way to accept or decline; an arrival page shows when the crew is coming; a booking page shows your services and open times. None of them carry your other customers, your numbers, or a way into DeskOps — the link is the whole handshake, there is no sign-in behind it, and a mistyped link shows a plain "this link isn't working" page rather than anyone's data.
Leaving
ComputerOpen Settings, then Data & privacy and Delete account, watch it at /data-deletion-status. Deletion is confirmed in writing, then the account is deactivated at once: sign-in is disabled for you and your team, every connected payment and accounting integration is revoked at the provider and its token erased, and the assistant's memory is cleared. The records underneath are kept only in a deactivated, inaccessible state for the retention periods the Privacy Policy names — billing and tax records up to seven years, because the law requires it — and for nothing else. Documents you uploaded for Des are not removed automatically; delete them from Settings first or ask for erasure. Export everything before you start: deletion is not reversible.