DevDesk · Privacy

Product website · Privacy and security guide

DevDesk Privacy Policy

Effective date: 20 August 2026 Policy version: 2026-08-20.1

DevDesk is a local-first developer workspace for Android and Windows. This policy explains what stays on your device, what is sent when you use a network feature, and how Android and Windows check for app updates.

DevDesk has no account, advertising, analytics, telemetry, cloud sync, or DevDesk-operated backend. Optional local feature packs are handled by Google Play or Microsoft Store.

1. Scope and developer information

This Privacy Policy explains how DevDesk, published by Baisalya, accesses, processes, stores, transmits, retains, and deletes information on Android and Windows.

DevDesk is a local-first developer workspace. It has no DevDesk-operated user account, advertising, analytics, telemetry, cloud synchronization, or application backend. Optional local feature-pack purchases are processed by Google Play or Microsoft Store under that Store provider's terms.

2. Information stored on your device

DevDesk stores information locally only to provide features you choose to use. Ordinary application records are stored in the app-private local data area.

3. Credentials and protected values

API credentials, AI provider credentials, and values marked as secrets are separated from ordinary workspace records where the operating system provides an appropriate protection boundary.

4. Network activity

DevDesk does not transmit analytics or locally stored content to Baisalya. Network communication is limited to the actions and checks described below.

5. Information received by destination services

A destination contacted by your action receives the information needed to complete that action. Depending on the feature, this can include your public IP address, request URL, headers, cookies, body content, attached files, and normal technical connection information.

The public release-manifest host receives normal connection information associated with downloading a static file, such as an IP address and standard HTTP metadata. It does not receive your DevDesk documents, API workspace contents, credentials, or local build comparison result.

DevDesk sends API and AI provider requests directly from your device and does not proxy them through a DevDesk-operated server. An AI provider, compatible endpoint, MCP server, API destination, or website you choose receives the permitted request content and normal connection information under its own terms and privacy policy.

6. Updates and release downloads

On Android and Windows, DevDesk uses the public release manifest for the current platform to determine whether the installed build is current, whether an update can be postponed, or whether a build that is two or more release builds behind must be updated before the tools remain available.

A failed first-time update check does not lock the app. A mandatory update is enforced only after a valid manifest has been downloaded from the fixed HTTPS DevDesk website address. DevDesk does not silently download or install an update.

Google Play, Microsoft Store, GitHub Releases, and the DevDesk website are external destinations. APK and Windows download integrity information may be published as SHA-256 checksums.

7. Files, folders, exports, backups, and clipboard

DevDesk reads a file or folder only after you select it through the applicable platform picker or another deliberate selection action. Android does not request broad access to all files.

Files, recovery copies, reports, backups, and exports remain wherever you save them. Copies outside DevDesk private storage must be managed and deleted by you.

Explicit copy actions place selected content in the operating-system clipboard. Clipboard managers and synchronized clipboard services are outside DevDesk control.

Redaction of stored history, exports, or clipboard output does not remove headers, credentials, cookies, files, parameters, or body content from an API request that you deliberately send.

Remote images in Markdown preview are blocked so that opening a note does not silently load tracking pixels.

Notification and AI routine records are ordinary local app data and may be included in a DevDesk backup. This release does not request access to notifications from WhatsApp, Facebook, or other applications and does not silently reply or post.

8. Sharing, sale, and third-party software

Baisalya does not sell user data. DevDesk does not share local content with advertisers, data brokers, or a DevDesk-operated service.

The current release does not include advertising, analytics, Firebase, social-login, or cloud-sync SDKs. It includes official Google Play Billing on Android and Windows Store APIs on Windows for optional local feature packs. These Store components operate when product availability, purchase, or restoration is checked.

DevDesk does not sell AI conversation or workspace content. Context is sent only to the provider, endpoint, MCP server, or browser destination selected for the feature you deliberately use.

9. Security and platform boundaries

DevDesk uses platform-private storage, protected secret storage where supported, guarded file replacement, validated backup imports, bounded network operations, release-manifest origin validation, and conservative redaction. No security control is absolute.

Device administrators, malware, screen capture, clipboard managers, synchronized clipboard services, compromised devices, operating-system backups, and destination-service security are outside DevDesk control.

Android application backup and device-transfer extraction are disabled for DevDesk private application data. Windows data follows the current Windows user profile and its configured backup policy.

Approved Windows terminal commands and project checks run with the current Windows user's authority. DevDesk permission and classification controls are not an operating-system sandbox. Parallel implementation workers remain in isolated Git worktrees and require a reviewed integration proposal.

Browser Agent uses a visible isolated Edge profile, blocks automated sensitive-field entry, and supports explicit user-control handoff. No browser isolation or automatic redaction mechanism can guarantee that a destination page is trustworthy.

10. Retention and deletion

Local records remain until you delete an available record, use Clear All Data, clear DevDesk data through the operating system, uninstall DevDesk, or an application limit removes older history.

Clear All Data removes known DevDesk-private records, AI sessions and memories, protected secret records, settings, rating state, update-reminder and required-release state, onboarding state, and the local policy acknowledgement. Exported files, selected external project folders, and information already sent to another service are separate and are not deleted.

Clear All Data also removes local Notification Center records and AI routines. Transient image attachment bytes are discarded after their request and are not retained as a separate DevDesk record.

Information already sent to a destination service must be managed through that service. DevDesk has no online account or server-side user profile to delete.

11. Children and international processing

DevDesk is a professional developer tool and is not directed specifically toward children.

When you contact an external API, GitHub, Google Play, the DevDesk websites, or another external destination, that service may process connection information in a country different from your own.

12. Changes and contact

The effective date and policy version appear at the top of this policy. A material in-app privacy change can update the version and require a new acknowledgement.

Privacy questions: baishalya1999@gmail.com.

General support: DevDesk support issue form. Never post passwords, tokens, private request bodies, personal information, or confidential source code in a public issue.

Security vulnerabilities: private GitHub security advisory or baishalya1999@gmail.com. Do not publish vulnerability details in a public issue.


DevDesk • Android package com.baishalya.devdeskSupportPrivacy email