Privacy policy

Private by default, explicit where data leaves the device.

This policy explains what Signal Desk reads, why it reads it, what is stored, and the controls available to the owner.

Scope

Signal Desk is a private, locally installed Windows application intended for use by its owner. It has no developer-operated account system, analytics service, advertising system, or inbox backend. The public pages on this domain do not accept forms or intentionally collect personal information. Cloudflare may process ordinary request metadata when serving these pages under its own policies.

Google user data

When you connect a Gmail account, Signal Desk requests only https://www.googleapis.com/auth/gmail.readonly. It uses that access to retrieve the connected address, unread inbox message identifiers, labels, sender and recipient headers, subject, received time, snippet, and message text so it can display and prioritize unread mail. It cannot send, delete, archive, modify, or mark messages as read.

Every fetched email is first scored locally. If you configure and enable Google Gemini classification, ambiguous emails are sent directly from the desktop app to the Google Gemini API. The request contains the local priority assessment, sender, subject, snippet, labels, received time, and up to 8,000 characters of message text. This transfer happens only to produce the importance label requested by the user. Signal Desk does not send Gmail data to any other AI provider.

Signal Desk does not use Google user data for advertising, audience profiling, credit decisions, or sale. The developer does not receive or manually read connected Gmail content. Signal Desk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Telegram and Discord

Telegram API credentials and the authorized session are used to obtain unread direct-message summaries. Telegram message content is processed locally and is not sent to Gemini. Discord activity is limited to active notifications made available by Windows and, if separately configured, messages visible to an official Discord bot. Signal Desk does not extract Discord user tokens or access personal Discord history through unsupported methods.

Storage, security, and retention

OAuth client details, Google refresh tokens, the Gemini API key, Telegram API details and session, optional Discord bot configuration, and identifiers for already-seen Discord notifications are stored in an encrypted local vault. Electron secure storage uses Windows operating-system protection for the encryption key. Message content is used for the live dashboard and is not intentionally written into that encrypted settings vault.

Connection material remains until you disconnect the service, remove Signal Desk's local application data, or uninstall and delete that data. Google, Telegram, Discord, Gemini, Cloudflare, and your operating system may retain data under their own policies. No security design can guarantee absolute protection, but Signal Desk minimizes persisted data and refuses to save secrets as plaintext when OS-backed protection is unavailable.

Your choices and deletion controls

  • Revoke Signal Desk under your Google Account's third-party connections to stop Gmail access.
  • Terminate the Signal Desk Telegram authorization from Telegram's active sessions.
  • Remove any optional Discord bot from servers and revoke its token.
  • Disable or remove the Gemini key to keep all email ranking local.
  • Delete Signal Desk's local application-data folder to erase its encrypted vault from this PC.

Because Signal Desk does not operate a remote user database, there is no separate remote Signal Desk account to delete.

Policy changes

If Signal Desk's data handling changes, this page and its last-updated date will be revised before the new handling is enabled.