Privacy Policy
GreenDesk is built and operated by one person, Ashley Lewis, not a company. There's no data-broker relationship, no ad network, and nothing here is sold. Short version: I collect your email address to know whose books are whose, the manuscript text you write (which you can end-to-end encrypt so I can't read it), and whatever a payment or feedback form sends me. Questions or deletion requests go to [email protected].
Account & identity
GreenDesk has no password of its own. Signing in on the web happens through Cloudflare Access (OAuth or an emailed PIN), which hands the app your verified email address — that's the only account field GreenDesk stores. The Windows and Android apps can't run that login flow themselves, so after one interactive sign-in the server issues a signed token containing that same email, valid for 90 days, so the app can stay signed in.
If you connect an AI agent (for example Claude, via GreenDesk's MCP server) to your account, that connection is authorized the same way — a token tied to your email — and gives that agent the access to your books that you granted it.
What I collect
- Email address — your account identity, from Cloudflare Access.
- The books you write — chapters, titles, and inspiration notes. You can turn on end-to-end encryption for any book (see below); until you do, it's stored as plain text tied to your account.
- Billing records — if you buy tokens or lifetime access, Stripe (web/desktop) or RevenueCat/Google Play Billing (Android) tells the server your email, what you bought, and a transaction ID. GreenDesk's server never sees or stores your card number.
- Feedback you send — bug reports and suggestions are stored anonymously: not tied to your account or email, just the message, an attached client log, and non-identifying client context, so I can fix what broke.
- Cloud backup links you opt into — if you link a book to Google Drive or OneDrive, that chapter's text is sent to Google or Microsoft each time you push or pull it. The desktop and Android apps store a refresh token for that link on the server; the web app's Google link happens entirely in your browser and never touches the server.
- Ordinary web traffic — like any web server, requests to GreenDesk pass through standard connection logging (IP address, timestamp, request path) as a normal part of running the service. This isn't used for tracking or profiling.
GreenDesk does not run any analytics, advertising, or crash-reporting SDK, and doesn't request camera, location, or contacts access on Android.
End-to-end encryption
Any book can be encrypted with a passphrase, entirely on your device (the browser's own WebCrypto, never sent anywhere). Once encrypted, the server only ever stores ciphertext — I don't have the passphrase and can't read the content or title. Losing the passphrase is serious: GreenDesk gives you five one-time recovery codes when you turn encryption on, but if you lose both the passphrase and every recovery code, that book's content is unrecoverable — there's no back door I can use to get it back for you.
Encryption covers cloud storage only. It doesn't extend to text you send to a language model for a suggestion — see AI processing below.
AI processing
GreenDesk suggests, it never writes into your manuscript on its own — nothing an AI produces is added to your book unless the suggestion is generated through one of the two paths below, and how that text is handled differs between them:
- Your own model (default) — point GreenDesk at a model running on your own machine or network (LM Studio, Ollama, llama.cpp) or at your own cloud API key (OpenAI, Anthropic, OpenRouter, Gemini, etc.). In this path your device talks to that model directly — the manuscript text goes straight from you to wherever you pointed it, and GreenDesk's server never sees it. Your API key stays on your device.
- GreenDesk's hosted model — every account starts with a free balance of tokens redeemable against a language model I run myself (not a third-party AI cloud). Using it sends the manuscript text you're continuing from through GreenDesk's server to that model, and the suggestion returned is saved as part of that book on the server.
An end-to-end-encrypted book can never use the hosted model — that's enforced by the server, not just this policy, because sending encrypted content there would mean decrypting it first. Encrypted books can only be continued with your own local or BYO model.
Third-party services
These process data on GreenDesk's behalf, each governed by its own privacy policy:
- Cloudflare — sits in front of the web app for authentication and network security, and sees all traffic to it. See Cloudflare's privacy policy.
- Stripe — processes web/desktop payments; handles your card details directly. See Stripe's privacy policy.
- RevenueCat & Google Play Billing — process Android in-app purchases. See RevenueCat's and Google Play's own privacy policies.
- Google Drive & Microsoft OneDrive — only if you link a book to one, to back up or sync that chapter's text.
If you connect a third-party AI agent (like Claude, via MCP) to GreenDesk, whatever that agent does with the books it can access is governed by that provider's own privacy policy, not this one.
Where your data lives
GreenDesk's storage and its hosted language model both run on infrastructure I operate directly, not a third-party cloud database or AI API. Traffic to the app is routed through Cloudflare, which terminates TLS in front of it.
Cookies
The only cookie GreenDesk's web app sets is Cloudflare Access's authentication cookie, which keeps you signed in. There's no advertising or analytics cookie, and no cross-site tracking.
Data retention & deletion
You can delete your entire account yourself, at any time, from within the app. This immediately and permanently removes every book you own, its encryption keys, your token balance, any lifetime-access flag, your Google/OneDrive link, and any AI-agent access you'd granted — there's no recovery period, so it can't be undone once confirmed. Stripe keeps its own record that a payment occurred, separately from anything identifying you inside the app, as required for accounting. If you'd rather have it done for you, or run into trouble, email [email protected] and I'll delete it by hand.
You can also export any book you own to a .docx or .pdf file from within the app at any time, independent of account deletion.
Children's privacy
GreenDesk isn't directed at children and doesn't knowingly collect information from anyone under 13. There's no age-verification step, so if you believe a child has created an account, email [email protected] and it will be removed.
Your rights
Wherever you are, you can delete your account yourself as described above, or email [email protected] to ask what's stored under your email, correct it, or have it deleted for you.
Changes to this policy
If what GreenDesk collects or how it's used changes materially, this page will be updated and the effective date above will change.
Contact
Ashley Lewis — [email protected]