GreenDesk

Privacy Policy

GreenDesk is built and operated by one person, Ashley Lewis, not a company. There's no data-broker relationship, no ad network, and nothing here is sold. Short version: I collect your email address to know whose books are whose, the manuscript text you write (which you can end-to-end encrypt so I can't read it), and whatever a payment or feedback form sends me. Questions or deletion requests go to [email protected].

Account & identity

GreenDesk has no password of its own. Signing in on the web happens through Cloudflare Access (OAuth or an emailed PIN), which hands the app your verified email address — that's the only account field GreenDesk stores. The Windows and Android apps can't run that login flow themselves, so after one interactive sign-in the server issues a signed token containing that same email, valid for 90 days, so the app can stay signed in.

If you connect an AI agent (for example Claude, via GreenDesk's MCP server) to your account, that connection is authorized the same way — a token tied to your email — and gives that agent the access to your books that you granted it.

What I collect

GreenDesk does not run any analytics, advertising, or crash-reporting SDK, and doesn't request camera, location, or contacts access on Android.

End-to-end encryption

Any book can be encrypted with a passphrase, entirely on your device (the browser's own WebCrypto, never sent anywhere). Once encrypted, the server only ever stores ciphertext — I don't have the passphrase and can't read the content or title. Losing the passphrase is serious: GreenDesk gives you five one-time recovery codes when you turn encryption on, but if you lose both the passphrase and every recovery code, that book's content is unrecoverable — there's no back door I can use to get it back for you.

Encryption covers cloud storage only. It doesn't extend to text you send to a language model for a suggestion — see AI processing below.

AI processing

GreenDesk suggests, it never writes into your manuscript on its own — nothing an AI produces is added to your book unless the suggestion is generated through one of the two paths below, and how that text is handled differs between them:

An end-to-end-encrypted book can never use the hosted model — that's enforced by the server, not just this policy, because sending encrypted content there would mean decrypting it first. Encrypted books can only be continued with your own local or BYO model.

Third-party services

These process data on GreenDesk's behalf, each governed by its own privacy policy:

If you connect a third-party AI agent (like Claude, via MCP) to GreenDesk, whatever that agent does with the books it can access is governed by that provider's own privacy policy, not this one.

Where your data lives

GreenDesk's storage and its hosted language model both run on infrastructure I operate directly, not a third-party cloud database or AI API. Traffic to the app is routed through Cloudflare, which terminates TLS in front of it.

Cookies

The only cookie GreenDesk's web app sets is Cloudflare Access's authentication cookie, which keeps you signed in. There's no advertising or analytics cookie, and no cross-site tracking.

Data retention & deletion

You can delete your entire account yourself, at any time, from within the app. This immediately and permanently removes every book you own, its encryption keys, your token balance, any lifetime-access flag, your Google/OneDrive link, and any AI-agent access you'd granted — there's no recovery period, so it can't be undone once confirmed. Stripe keeps its own record that a payment occurred, separately from anything identifying you inside the app, as required for accounting. If you'd rather have it done for you, or run into trouble, email [email protected] and I'll delete it by hand.

You can also export any book you own to a .docx or .pdf file from within the app at any time, independent of account deletion.

Children's privacy

GreenDesk isn't directed at children and doesn't knowingly collect information from anyone under 13. There's no age-verification step, so if you believe a child has created an account, email [email protected] and it will be removed.

Your rights

Wherever you are, you can delete your account yourself as described above, or email [email protected] to ask what's stored under your email, correct it, or have it deleted for you.

Changes to this policy

If what GreenDesk collects or how it's used changes materially, this page will be updated and the effective date above will change.

Contact

Ashley Lewis — [email protected]