DeskyAI gives you a private AI assistant for your business numbers. To do that, you connect your own tools — accounting, e‑commerce, advertising — and we read that data on your behalf so the assistant can answer your questions. This policy explains exactly what we collect, why, how we protect it, and the control you have over it. In plain terms: your data is yours, we hold as little as we can, we never sell it, and connected data is accessed read‑only.
01Who we are
DeskyAI ("DeskyAI", "we", "us") is a business‑analytics product operated from Sydney, Australia. You can reach us about anything in this policy, including privacy requests, at support@deskyai.com.
This policy covers our website at deskyai.com and the DeskyAI application.
02Information we collect
Account information
When you sign up we collect your name, email address, business name, industry, and a securely hashed password. We use this to create and operate your account and to communicate with you about the service.
Data from services you connect
DeskyAI only accesses third‑party data that you explicitly connect through a secure authorisation (OAuth) flow. Depending on what you connect, this may include:
- Accounting (e.g. Xero): invoices, bills, payments, contacts, and financial reports.
- E‑commerce (e.g. Shopify): orders, products, customers, and inventory.
- Advertising (e.g. Google Ads): campaign and ad‑group performance metrics such as spend, impressions, clicks, conversions, and conversion value.
All connected data is accessed on a read‑only basis. DeskyAI cannot create, edit, or delete anything in your connected accounts.
Usage and technical data
We collect basic operational data needed to run the service securely and reliably — for example, log‑in sessions and error logs. We do not use third‑party advertising trackers.
03How we use your information
We use the information above solely to provide and improve the DeskyAI service:
- To answer your questions and generate reports, charts, and dashboards from your own connected data.
- To operate, secure, and maintain your private workspace.
- To communicate with you about your account, including verification emails and important service notices.
We do not sell your data, we do not use it to serve advertising, and we do not use your business data to train machine‑learning models.
04Google user data
DeskyAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect a Google service (such as Google Ads), DeskyAI requests read‑only access to the specific data needed to provide the feature you asked for. We use Google user data only to display and analyse your advertising performance inside your own DeskyAI workspace. We do not transfer this data to third parties except as required to run the service or by law, we do not use it for advertising, and we do not allow humans to read it except where you give explicit consent, where it is necessary for security or to comply with law, or where the data has been aggregated and anonymised. You can revoke DeskyAI's access to your Google account at any time from the DeskyAI sidebar or via your Google Account permissions page; doing so deletes the associated data as described in section 07.
05How your data is stored and protected
Each customer is provisioned an isolated private workspace. Your connected business data is synced into that workspace as a read‑only snapshot so the assistant can answer questions quickly.
Access credentials (OAuth tokens) for your connected services are stored encrypted and are never placed on the workspace itself — meaning the assistant can read your data snapshot but holds no ability to act on your upstream accounts. Passwords are stored only as salted PBKDF2 hashes. Data is transmitted over encrypted (HTTPS/TLS) connections.
06Service providers
We use a small number of trusted infrastructure providers to operate DeskyAI. They process data only on our instructions and only to provide their service:
- Anthropic — the AI model that powers your assistant.
- Cloudflare — website hosting, edge security, and our application database.
- DigitalOcean — the private workspace servers.
- Resend — transactional email (e.g. verification codes).
We do not sell, rent, or trade your personal information to anyone.
07Data retention and deletion
We keep your data only while your account is active or as needed to provide the service.
- Disconnecting a service removes its stored access credentials and deletes the associated synced data from your workspace.
- Deleting your account removes your account information and de‑provisions your workspace and its data.
To request deletion, contact support@deskyai.com.
08Your rights
You may access, correct, export, or delete your personal information, and withdraw consent for any connected service at any time. To exercise these rights, use the in‑app controls or email support@deskyai.com. We will respond within a reasonable timeframe and in accordance with the Australian Privacy Act and other applicable laws.
09Cookies
We use only the cookies and local storage necessary to keep you signed in and to operate the application. We do not use advertising or cross‑site tracking cookies.
10Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "last updated" date above and, where appropriate, notify you. Continued use of DeskyAI after a change means you accept the revised policy.
11Contact us
Questions or privacy requests: support@deskyai.com, DeskyAI, Sydney, Australia.