Skip to content

Legal

Privacy policy

Last updated 24 September 2026.

1.What we collect

Account data: your name, email address, profile photo and details, the organisations you belong to and your role in each. Your password is stored only as a salted hash.

Content you and your team create: floor layouts, chat messages and direct messages, files uploaded to Drive or attached to work items, tasks and comments, docs, whiteboards, meetings you schedule and their details.

Presence and attendance data, generated as you use the office: which floor, room and seat you are in and when, your status (for example active, away or focused), when you are in a call, and which part of Remote Desk you have open. Your organisation uses this for attendance and day timelines.

Session and device data: for each signed-in session, its IP address, the browser or app and device type, and when it was last used, so you can review and sign out your sessions. For security we also keep records of sign-in attempts and a sample of requests, with IP addresses truncated or hashed, trusted-device records if you choose to skip two-factor codes on a device, and device tokens for push notifications on the mobile app.

Meeting recordings, only when someone in a room starts one. A recording captures the room's audio, the cameras that are switched on and any screen share. Everyone in the room is told when a recording starts, and so is anyone who walks in while it runs. On our hosted service recordings are stored in our cloud storage bucket; on a self-hosted installation they are stored wherever your organisation configures. To make a transcript, audio may also be captured separately for each speaker during the recording.

Transcripts and AI minutes, made after the meeting from a recording: the audio is processed by a speech-to-text provider to produce the transcript, and the transcript by an AI model provider to write the minutes (a summary, decisions and action items).

What you send to AI features: prompts, files and conversations in the AI Workspace and the in-app assistant, which are sent to the AI model provider used for that request.

App activity and screenshots, only if an owner of your organisation switches them on. Both are off by default and both come only from the desktop app. App activity (Windows desktop app) records the name of the application in front and its window title, in blocks of time; it never records keystrokes, clipboard contents or web addresses, and records nothing while you are idle or your screen is locked. Screenshots capture the window in front, or the whole screen if the owner chooses, at an interval the owner sets, and are blurred on your device before upload unless the owner turns blurring off. While either is on, the desktop app shows a monitoring icon, and the notice in Settings, under Security, lists what is collected.

2.Who can see it

Other members of your organisation see what the product shows them: your presence, status and seat on the floor, messages in conversations they are part of, and content shared with them.

Your organisation's owner and admins, and anyone in a role your organisation gives the same permission, can also see attendance records and, where your organisation has switched them on, app activity and screenshots. You can see and delete your own screenshots; you cannot see your own app activity log.

A recording, its transcript and its minutes are available to the people who were in the meeting, its organiser and invitees, anyone the recording is shared with, and people in your organisation who manage meetings.

If your organisation's owner uses the daily operations report, a nightly summary of each member's hours, work and AI usage is emailed to the owner and to the recipients the owner chooses.

A small number of Remote Desk staff can access the service as a user, to provide support and keep the service running. Every such session is clearly labelled and recorded in an audit log.

3.Providers that process data for us

We use a small set of providers to run the service: cloud hosting and file storage, email delivery, push notification delivery for the mobile app, a speech-to-text provider for transcripts, and AI model providers for minutes and AI features. They process data only to provide that part of the service.

The speech-to-text and AI model providers are chosen by whoever operates the service: us on the hosted service, or your organisation when it self-hosts. Remote Desk does not train AI models on your data.

4.What we don't do

Calls are not stored unless someone records them. Audio and video are carried in real time between participants through our media server and are not kept.

We do not sell personal data, run third-party advertising trackers, or build advertising profiles.

5.How we use data

To operate the service: signing you in, carrying your calls, showing presence, storing your messages, files and floors, and producing the recordings, transcripts and minutes you ask for.

To keep it secure and reliable: sign-in records and sampled request logs help us detect abuse and fix faults. To communicate with you: email about your account, such as sign-in codes, invitations and verification links, and the notifications you have turned on.

6.Self-hosted deployments

If your organisation self-hosts Remote Desk, workspace content and operational data stay on infrastructure your organisation controls, and your organisation chooses its storage, email, speech-to-text and AI providers. We receive no data from self-hosted instances.

7.Retention and deletion

Meeting recordings are kept until someone in your organisation who manages meetings deletes them; there is no automatic expiry. Deleting a recording also deletes its transcript and minutes. Audio captured per speaker for transcription is deleted automatically 90 days after the transcript is ready, by default.

App activity and screenshots are deleted automatically after a retention period your organisation's owner sets, between 7 and 365 days (30 days by default). You can delete any of your own screenshots sooner.

Files moved to the trash in Drive are permanently deleted after 30 days. Read notifications are removed after 30 days. Sign-in attempt records are kept for 365 days and sampled request logs for 30 days, by default.

Everything else, including your account, messages, files, docs, tasks and attendance records, is kept until you or your organisation deletes it, or the organisation closes its account. Deleting an organisation deactivates it rather than erasing it immediately. To have an organisation's data, or your own personal data, permanently erased or exported, contact us.

8.Contact

Privacy questions and requests: hello@remotedesk.space. We respond to verified requests within 30 days.