DevDesk Privacy Policy
Effective date: 20 August 2026 Policy version: 2026-08-20.1
DevDesk is a local-first developer workspace for Android and Windows. This policy explains what stays on your device, what is sent when you use a network feature, and how Android and Windows check for app updates.
DevDesk has no account, advertising, analytics, telemetry, cloud sync, or DevDesk-operated backend. Optional local feature packs are handled by Google Play or Microsoft Store.
1. Scope and developer information
This Privacy Policy explains how DevDesk, published by Baisalya, accesses, processes, stores, transmits, retains, and deletes information on Android and Windows.
DevDesk is a local-first developer workspace. It has no DevDesk-operated user account, advertising, analytics, telemetry, cloud synchronization, or application backend. Optional local feature-pack purchases are processed by Google Play or Microsoft Store under that Store provider's terms.
2. Information stored on your device
DevDesk stores information locally only to provide features you choose to use. Ordinary application records are stored in the app-private local data area.
- Markdown documents, notes, snippets, favourites, recent tools, onboarding state, manual preferences, and appearance settings.
- Registered local workspaces, folder metadata, indexes, drafts, links, backlinks, tags, frontmatter, graph state, and structured-knowledge validation results.
- AI work-session metadata, durable run checkpoints, local change-proposal links, terminal safety classifications/reasons, and bounded redacted stdout/stderr from approved project-verification commands or explicitly approved AI terminal commands. H.4 bounded terminal plans do not create a separate transcript or hidden command log: each completed plan step is retained only as the same bounded/redacted command evidence already used by single terminal commands. H.6 may additionally retain a bounded recovery checkpoint containing redacted plan-step metadata, plan/prefix fingerprints, and an internal workspace/chat-bound recovery token so already-passed steps can be safely skipped after a failure or restart; this recovery token is not a user credential or provider continuation token and is removed when the checkpoint is dismissed, completed, or superseded. While a terminal command is actively running, a bounded redacted live tail is kept in memory for the current chat; H.3 terminal session-permission grants are also memory-only and are revoked by a chat switch/new chat or app restart. The selected autonomy profile may be kept as a local preference, but the session grant itself is not persisted. Durable AI run records keep only the bounded redacted evidence already described. These records stay in DevDesk private local storage and are excluded from supported portable exports.
- J1-J3 Browser Agent sessions use a temporary isolated Microsoft Edge profile while active. The profile is separate from the user's normal browser profile and is deleted on a best-effort basis when the session closes; browser-control state is not included in supported portable exports.
- API workspaces, collections, environments, request history, response history, examples, assertions, extraction rules, and reports.
- A local record of the Privacy Policy version you acknowledged and the acknowledgement time.
- Local rating-prompt preferences, optional update-reminder preferences, and the last verified required-update metadata when an installed build must be updated.
- Local notifications, read state, AI routine names, schedules, enabled state, and reviewable routine prompts.
3. Credentials and protected values
API credentials, AI provider credentials, and values marked as secrets are separated from ordinary workspace records where the operating system provides an appropriate protection boundary.
- Android protected values use encryption with a key held by Android Keystore.
- Windows protected values use Windows Data Protection API (DPAPI) for the current Windows user.
- Protected values are excluded from supported DevDesk-generated portable backups and exports. Automated redaction is conservative and cannot guarantee that every confidential value will be detected.
- Provider continuation values, transient tool arguments/results, and private model reasoning are not exported as a portable AI transcript.
4. Network activity
DevDesk does not transmit analytics or locally stored content to Baisalya. Network communication is limited to the actions and checks described below.
- API Workspaces send the URL, method, headers, authorization information, parameters, cookies, body, and deliberately attached content to the server whose URL you choose.
- Supported GitHub comparison, preview, or import actions fetch public repository information from GitHub URLs you choose.
- Link validation sends a request to the URL you ask DevDesk to check.
- AI Workbench sends the messages, selected project context, bounded tool results, and repair evidence needed for a request directly to the AI provider or compatible local endpoint you configure. DevDesk does not proxy that request through a Baisalya-operated service.
- AI Harness sends a bounded device file or image only after you explicitly attach it and send the request. Image input requires a model that advertises vision support. Image bytes are transient request input and are not persisted in DevDesk chat history or backups.
- The optional AI Agent Connector accepts authenticated loopback requests from a compatible client on the same device. That client and its configured model provider determine where permitted connector context is processed.
- External MCP tools connect to the server you configure. Only explicitly trusted read-only tools are exposed by the current workbench policy; the server still receives the request needed to perform a permitted tool call.
- When you explicitly enable the J1-J3 Browser Agent, loopback development URLs can be opened in its isolated visible browser. Public HTTP/HTTPS navigation additionally requires the External research & MCP permission and connects directly from your device to the destination website. The Browser Agent does not reuse your normal Edge cookies, passwords, or signed-in state. J2 can read bounded semantic control labels/state and perform user-approved semantic interactions; typed values are not returned in tool results, and password/file/payment/OTP-marked fields are blocked.
- Rating, store, website, downloads, support, privacy, repository, and release actions open the external destination you select.
- After privacy acknowledgement and onboarding, the Android or Windows app may download a small public JSON release manifest from the official DevDesk GitHub Pages site. The installed package name, version, and build number are compared locally and are not added to the manifest request.
- After privacy acknowledgement and onboarding, DevDesk contacts the installed platform Store to restore owned packs and request localized product details. It also contacts the Store when you purchase or manually restore a pack. Google Play or Microsoft may receive ordinary Store account, device, payment, and transaction information under their own privacy terms. DevDesk receives the product and license result but does not receive your full payment-card details.
5. Information received by destination services
A destination contacted by your action receives the information needed to complete that action. Depending on the feature, this can include your public IP address, request URL, headers, cookies, body content, attached files, and normal technical connection information.
The public release-manifest host receives normal connection information associated with downloading a static file, such as an IP address and standard HTTP metadata. It does not receive your DevDesk documents, API workspace contents, credentials, or local build comparison result.
DevDesk sends API and AI provider requests directly from your device and does not proxy them through a DevDesk-operated server. An AI provider, compatible endpoint, MCP server, API destination, or website you choose receives the permitted request content and normal connection information under its own terms and privacy policy.
6. Updates and release downloads
On Android and Windows, DevDesk uses the public release manifest for the current platform to determine whether the installed build is current, whether an update can be postponed, or whether a build that is two or more release builds behind must be updated before the tools remain available.
A failed first-time update check does not lock the app. A mandatory update is enforced only after a valid manifest has been downloaded from the fixed HTTPS DevDesk website address. DevDesk does not silently download or install an update.
Google Play, Microsoft Store, GitHub Releases, and the DevDesk website are external destinations. APK and Windows download integrity information may be published as SHA-256 checksums.
7. Files, folders, exports, backups, and clipboard
DevDesk reads a file or folder only after you select it through the applicable platform picker or another deliberate selection action. Android does not request broad access to all files.
Files, recovery copies, reports, backups, and exports remain wherever you save them. Copies outside DevDesk private storage must be managed and deleted by you.
Explicit copy actions place selected content in the operating-system clipboard. Clipboard managers and synchronized clipboard services are outside DevDesk control.
Redaction of stored history, exports, or clipboard output does not remove headers, credentials, cookies, files, parameters, or body content from an API request that you deliberately send.
Remote images in Markdown preview are blocked so that opening a note does not silently load tracking pixels.
Notification and AI routine records are ordinary local app data and may be included in a DevDesk backup. This release does not request access to notifications from WhatsApp, Facebook, or other applications and does not silently reply or post.
8. Sharing, sale, and third-party software
Baisalya does not sell user data. DevDesk does not share local content with advertisers, data brokers, or a DevDesk-operated service.
The current release does not include advertising, analytics, Firebase, social-login, or cloud-sync SDKs. It includes official Google Play Billing on Android and Windows Store APIs on Windows for optional local feature packs. These Store components operate when product availability, purchase, or restoration is checked.
DevDesk does not sell AI conversation or workspace content. Context is sent only to the provider, endpoint, MCP server, or browser destination selected for the feature you deliberately use.
9. Security and platform boundaries
DevDesk uses platform-private storage, protected secret storage where supported, guarded file replacement, validated backup imports, bounded network operations, release-manifest origin validation, and conservative redaction. No security control is absolute.
Device administrators, malware, screen capture, clipboard managers, synchronized clipboard services, compromised devices, operating-system backups, and destination-service security are outside DevDesk control.
Android application backup and device-transfer extraction are disabled for DevDesk private application data. Windows data follows the current Windows user profile and its configured backup policy.
Approved Windows terminal commands and project checks run with the current Windows user's authority. DevDesk permission and classification controls are not an operating-system sandbox. Parallel implementation workers remain in isolated Git worktrees and require a reviewed integration proposal.
Browser Agent uses a visible isolated Edge profile, blocks automated sensitive-field entry, and supports explicit user-control handoff. No browser isolation or automatic redaction mechanism can guarantee that a destination page is trustworthy.
10. Retention and deletion
Local records remain until you delete an available record, use Clear All Data, clear DevDesk data through the operating system, uninstall DevDesk, or an application limit removes older history.
Clear All Data removes known DevDesk-private records, AI sessions and memories, protected secret records, settings, rating state, update-reminder and required-release state, onboarding state, and the local policy acknowledgement. Exported files, selected external project folders, and information already sent to another service are separate and are not deleted.
Clear All Data also removes local Notification Center records and AI routines. Transient image attachment bytes are discarded after their request and are not retained as a separate DevDesk record.
Information already sent to a destination service must be managed through that service. DevDesk has no online account or server-side user profile to delete.
11. Children and international processing
DevDesk is a professional developer tool and is not directed specifically toward children.
When you contact an external API, GitHub, Google Play, the DevDesk websites, or another external destination, that service may process connection information in a country different from your own.
12. Changes and contact
The effective date and policy version appear at the top of this policy. A material in-app privacy change can update the version and require a new acknowledgement.
Privacy questions: baishalya1999@gmail.com.
General support: DevDesk support issue form. Never post passwords, tokens, private request bodies, personal information, or confidential source code in a public issue.
Security vulnerabilities: private GitHub security advisory or baishalya1999@gmail.com. Do not publish vulnerability details in a public issue.
DevDesk • Android package com.baishalya.devdesk • Support • Privacy email