This Privacy Policy explains what personal data we collect when you use the DeskDash website at https://www.desktop-dashboard.com and the DeskDash desktop application, why we collect it, and what rights you have over it.
It is written to be read, not to be survived. If anything here is unclear, email us at contact@desktop-dashboard.com.
1. Who we are
Nair Development Hub SRL is the data controller for the personal data described in this policy.
- Registered address: Str. Tineretului 63, Chiajna, Ilfov County, Romania
- Company registration number / CUI: 48366031
- Contact for privacy matters: contact@desktop-dashboard.com
We are established in Romania and we process personal data in accordance with the EU General Data Protection Regulation (GDPR).
2. The short version
DeskDash is a desktop application. Most of what it does happens on your computer and stays there.
The application contains no analytics or tracking software, and no crash reporting. There is no reporting request: nothing is ever sent for the purpose of measuring you. We do not know how you have arranged your desktop, what settings you have chosen, or what you have typed into a widget. None of that reaches us.
One exception is noted in Sections 4 and 4.1: the daily licence check carries two numbers, how many widgets you have set up and how many are on screen right now. We use them to tell an install somebody actually uses from one that autostarts into an empty desktop. They are counts. They cannot tell us which widgets you picked, where you put them, or anything they display.
The application talks to our servers for three things only: checking for updates, validating your licence, and browsing or downloading widgets from the marketplace. Downloading a widget is authenticated, so that request necessarily tells us which widget was downloaded (see Section 4.1). Beyond that, it connects only to the specific services a widget you installed needs, directly from your machine.
We do count those three requests, because they arrive at our servers anyway and we need to know basic things about our own product: how many people are running it, on which version, and which widgets get looked at. That counting is described in full in Section 4.1. It adds nothing to what the application sends, it is kept deliberately separated from your identity where the request was anonymous to begin with, and it never touches anything on the list above.
On the website we measure how people move through it: which buy button was pressed, whether the checkout was started, whether it completed. If you buy, that record is linked to your account, so we can see the path from a click on the site to an activated licence.
The rest of this policy sets out the detail.
3. What we collect and why
3.1 On the website and in your account
| What | Why | Legal basis |
|---|---|---|
| Email address (your account identifier) | To create your account, deliver your licence key, sign you in, and contact you about your purchase or about a licence we granted you | Performance of a contract |
| Login codes (six digit, stored as a one way hash) | To sign you in without a password | Performance of a contract |
| Session token (stored as a one way hash) | To keep you signed in | Performance of a contract |
| Purchase record (payment provider, order reference, and the event data the provider sends us) | To confirm your purchase, prevent duplicate processing, and meet accounting obligations | Performance of a contract; legal obligation |
| Licence grant record, where we gave you a licence rather than selling you one (a reference, the date, and the short reason we noted) | To record what entitles your account, and so we can withdraw the licence again. There is no payment provider and no payment data on this record | Performance of a contract |
| Licence key (stored as a one way hash, plus the last four characters so you can recognise it) | To issue and validate your licence | Performance of a contract |
| Device identifier (a one way hash, see Section 6) | To bind one licence to one device and prevent licence sharing | Our legitimate interest in enforcing the terms of sale |
| Publisher handle (if you publish widgets) | To identify you publicly as the author of your widgets | Performance of a contract |
| Email address entered at checkout where the purchase was not completed | So we can follow up if something went wrong with your purchase. You can ask us to stop at any time | Our legitimate interest in completing a transaction you started |
| Your email address in our contact list, labelled with where you stand (signed up, started a purchase, bought) | So we can email you about DeskDash itself: release announcements, important changes, and occasional product news. Every such email has an unsubscribe link, and unsubscribing stops them without affecting your licence or your account email | Our legitimate interest in telling our own customers about our own product; consent where you signed up on the website |
| IP address | Used transiently to apply rate limits and prevent abuse. Raw IP addresses are never stored | Our legitimate interest in protecting the Service |
3.2 If you submit a widget
| What | Why | Legal basis |
|---|---|---|
| Your account email, publisher handle, and submitted files | To review, publish and attribute your widget | Performance of a contract |
| A one way hash of your IP address | To identify abusive submission patterns without storing IP addresses | Our legitimate interest in protecting the Service |
| Screenshots you upload | To display your widget in the marketplace | Performance of a contract |
Note that your publisher handle is public and permanent, and appears in the identifier of every widget you publish.
3.3 If you contact us
When you use the contact form, we receive the email address and message you provide, so that we can reply. Legal basis: our legitimate interest in answering enquiries.
4. What the desktop application sends to us
This is the complete list, including the notes underneath it. There is nothing else.
| Request | When | What it contains |
|---|---|---|
| Update check | On launch and periodically (by default every 24 hours) | Nothing identifying. It is a plain request for a version file. We do not know who asked |
| Update download | Only when a newer version exists, on the direct download channel | Nothing identifying |
| Licence validation | On activation, when you open the marketplace, and once a day otherwise | Your licence key, your device identifier (Section 6), and two numbers: how many widgets you have set up, and how many of those are currently on screen. Just the two counts. Never which widgets, never where they are, never their settings |
| Account lookup | Immediately after a successful validation | Your licence key. We return your email address and publisher handle so the application can display them |
| Marketplace browsing | While the marketplace window is open | Nothing identifying. Browsing is anonymous. It carries a store session token: a random value the application invents when you open the marketplace window, holds only in memory, and forgets when you close it. It is not derived from you, your licence or your machine, and it lets us see that one browsing session looked at four widgets without telling us whose session it was |
| Widget download | When you install or update a widget | Your licence key |
Every one of those requests also carries the application's version number and release channel, in the standard way any program identifies itself when it makes a web request. It tells us that some install is on version 0.1.8 rather than 0.1.5, which is how we know whether an update reached people and when an old version is safe to stop supporting.
We do not receive, at any point: your layout, your settings, the contents of any widget, your IP address in any stored form, or any information about what you do on your computer. The two widget counts above are the single exception, and they are counts and nothing more: from 7 of 9 on screen we cannot tell which widgets you chose, where you put them, what you configured them to show, or what any of them displays.
4.1 What we count, and how it is kept apart
We keep product statistics from the requests in the table above. This section is the whole of what the application produces; what the website produces is Section 8.
From the requests that carry your licence key (validation, account lookup, widget download) we record that a licence checked in, that the marketplace was opened, and which widget was downloaded, against a one way hash of your account identifier, together with the application version and the country the request came from. That hash is the only thing identifying you that reaches our analytics provider: not your email address, not your licence key, not the hash of your licence key, and never your device identifier, which stays reserved for licence enforcement exactly as Section 6 says.
From the requests that do not carry your licence key (browsing and viewing widgets in the marketplace) we record which widget was viewed and what was searched for, against the in-memory store session token, and nothing else.
These two sets of records are deliberately kept unjoinable. A store session token and an account hash never appear on the same record, so there is no path from "this session looked at these widgets" to "this person looked at these widgets".
We do not build a profile of what you have installed, we do not keep a per user browsing history, and we do not use any of it for advertising, for profiling, or for automated decisions about you. Nothing here is sold or shared beyond the provider listed in Section 9.
The two widget counts ride the daily licence check and are recorded against the same account hash. They are never combined with the browsing records above.
Country comes from a coarse country code our hosting provider derives at the network edge. We never store your IP address in any form, which Section 14 commits to.
Because these statistics are derived entirely from requests the application must already make for the Service to work, and because they are pseudonymous and aggregate, we rely on our legitimate interest in understanding and maintaining our own product. You can object to it under Section 12, and you can have it erased: deleting your account submits these records for deletion along with everything else, and in any case none of them is kept longer than 12 months.
5. What stays on your computer
The following is stored locally, on your own machine, and is never transmitted to us:
- Your configuration: layout, displays, themes, preferences, and the settings of each widget. Widget settings can contain things you typed in, such as a name for a greeting, a city for a weather widget, coordinates, habit names, or a folder path. The sole exception, and the only thing ever derived from your configuration, is the pair of widget counts in Section 4: how many exist and how many are on screen. Everything else in this bullet, including which widgets those are, stays on your machine.
- Widget data: whatever a widget saves, such as your to-do items, habit history, or cached results.
- Saved layouts, downloaded marketplace screenshots, and installed widgets and themes.
- Application logs, capped in size and rotated. They record what the application did, and deliberately exclude your licence key, your email address, your device identifier, and the values of any secret you have stored.
- Secrets you supply, such as an API key for a service you use. These are held by Windows Credential Manager, not in our files, and are inserted into requests by the application itself. Widget code never sees them.
The application also reads some information from your computer in order to work, and none of it leaves your machine: your wallpaper (to derive theme colours), your monitor arrangement, desktop item names and paths, media playback information, system statistics including WiFi network names, and system audio reduced to loudness levels only.
On audio specifically: when a widget with the relevant permission is on screen and audio is playing, the application reads the system's audio output and reduces it to a set of loudness values for visualisation. No microphone is ever accessed, no raw audio is retained, and speech cannot be reconstructed from what is produced.
The application never reads window titles, enumerates running processes, captures your screen, accesses your microphone, or reads your clipboard.
6. The device identifier
To enforce one licence per device, the application computes an identifier from a value Windows already stores to identify the installation, combines it with a fixed value, and applies a one way hash. Only the resulting hash is sent to us, and only during licence validation.
- The underlying Windows value never leaves your computer and is never written to disk by us.
- The hash cannot be reversed to recover it.
- We store it only against your licence key, to recognise the device your licence is bound to.
- It is persistent: it normally stays the same across reinstalls of the application and changes only if Windows itself is reinstalled. We therefore treat it as a device identifier for the purposes of this policy.
We use it for licence enforcement and for nothing else. We do not use it to profile you, to link activity across services, or for advertising.
7. Widgets and connections you choose
DeskDash widgets are small programs that run inside the application. Some of them are ours, some are written by other users, and some you may write yourself.
Every widget declares what it needs, including the exact internet addresses it is allowed to contact. When you install a widget from the marketplace, the application shows you that list in plain language before installation and lets you withhold any capability you do not want to grant. The permissions you approve are enforced every time the widget loads. Widgets included with the application are installed alongside it; their permissions are shown in the marketplace listing and in the widget's own manifest.
Where a widget connects to an outside service, that connection is made directly from your computer to that service. It does not pass through us, and we do not see it or log it. What is sent is determined by the widget and by what you configured it to do. For example, a weather widget sends the location you configured to a weather service; a widget for an account you hold sends credentials you supplied to that account's provider.
Because of that:
- The provider you connect to receives data directly from you, and their own privacy policy governs what they do with it.
- Data you enter into a widget stays on your machine unless the widget sends it to one of its declared addresses.
- We review widgets before publication and we constrain what they can reach, but we do not control and cannot guarantee what a third party service does with data it receives.
Widgets we publish ourselves that connect outwards do so only for their stated purpose, and only when you add them. If you want the specifics for a particular widget, its permissions and its exact list of addresses are on its marketplace page before you install it.
8. Cookies and analytics
Cookies. These are the cookies we set. None is an advertising cookie and none is shared with anyone.
| Cookie | What it is for | Kept |
|---|---|---|
dd_session | Keeps you signed in | 30 days |
dd_aid | A random identifier for your browser, so we can count a visit as one journey | 1 year |
dd_exp | Which version of a page you were shown, when we are testing two | 90 days |
dd_src | Which site you first arrived from, so we know where our visitors find us. It holds a page address, not an identifier | 1 year |
dd_ses | Which site brought you back this time. The same kind of value as above, forgotten after 30 minutes of inactivity | 30 minutes |
dd_consent | Your answer to the cookie banner | 1 year |
All six are necessary and cannot be turned off. If you accept optional analytics, PostHog's script also stores its own identifier in your browser; if you decline, it is never created. You can change your answer any time from the "Cookies" link in the footer.
What we measure on the website. We run split tests, showing two versions of a page to compare them. This runs on our servers and continues whether or not you accept optional analytics. To measure success rate for this, we might track CTA clicks or similar actions, not tied to your user specifically.
Where you came from. On your first visit we record the site that linked you to us, taken from the referrer your browser sends and from any campaign tag in the address. We keep the site and the address of the linking page, for example "reddit.com/r/windows/comments/abc", without its query string, so a search term you typed, a session token, or anything else after the "?" is never stored. We record this twice over: once on your first ever visit, which is never changed afterwards, and once for your current visit, which is forgotten after 30 minutes of inactivity. Together they tell us which sites introduce people to us and which bring them back.
We also record that a visit happened, with the page you arrived on. This is a count, not a history: it is one record per visit, not one per page you read.
If you go on to buy, the site you first arrived from is stored with your account, so that we can tell which sites bring us customers. It is included in your data export and it is deleted with your account.
Optional analytics. If you accept, PostHog's script loads in your browser and records page views and clicks. Its requests go to l.desktop-dashboard.com, which forwards to PostHog. If you decline, it does not load.
Product statistics. We use PostHog, hosted in the European Union, for the counts in Section 4.1 and the website records above. Nothing in the desktop application talks to PostHog. We track a couple of metrics on our backend, like how often your device checks if the licence is valid, or if you opened the in-app marketplace in the last few days, and whether we granted or withdrew a licence ourselves. PostHog never receives an IP address from us: every record is sent with the IP field emptied, and the project is configured to discard client IP data.
Website performance and audience. We use Vercel Analytics and Vercel Speed Insights for page load times, error rates, and aggregate traffic, and Ahrefs Web Analytics for which pages get visited and found. All three are cookieless, aggregate only, and not combined with your account.
Legal basis: our legitimate interest in maintaining our product and storefront, and your consent for the optional PostHog script. You can object under Section 12 and withdraw consent at any time from the footer link.
9. Who we share data with
We do not sell personal data, and we do not share it for advertising. We use the following providers to run the Service. Each processes data only on our instructions.
| Provider | What they do | Where |
|---|---|---|
| Vercel | Website and API hosting, content delivery, analytics | United States, with EU processing regions |
| Neon | Database hosting (accounts, licences, marketplace) | European Union |
| Stripe | Payment processing. Where Stripe acts as merchant of record it is the seller for the transaction and processes your payment data under its own privacy policy | United States and European Union |
| Loops | Sending transactional email (login codes, licence keys, contact form relays) and holding our contact list for product email | United States |
| PostHog | Product statistics (Sections 4.1 and 8). Receives a one way account hash, an anonymous session token, or a random browser identifier, never an email address, licence key, device identifier, or IP address | European Union |
| Cloudflare | Storage of marketplace screenshots, and forwarding analytics requests from l.desktop-dashboard.com to PostHog | European Union |
| Ahrefs | Cookieless website analytics: which pages get visited and found | European Union |
| GitHub | Private storage of widget submissions and application releases | United States |
We may also disclose personal data where we are legally required to do so, or where it is strictly necessary to protect the Service, investigate abuse, or establish or defend legal claims.
Services you connect to yourself, through a widget, are not our processors. You choose them, the connection is made from your machine, and their own terms and privacy policies apply.
10. International transfers
Some of our providers are established outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA, we rely on the safeguards available under GDPR Chapter V, which include the European Commission's Standard Contractual Clauses and, where applicable, an adequacy decision covering the recipient.
You may ask us for information about the safeguards applying to a specific transfer by emailing contact@desktop-dashboard.com.
11. How long we keep things
| Data | Retention |
|---|---|
| Account record (email, handle, status) | Until you delete your account |
| Login codes | Expire after 10 minutes and are deleted shortly afterwards |
| Sessions | Expire after 30 days and are deleted shortly afterwards |
| Licence keys and device identifier | For as long as your account exists |
| Purchase records | For as long as required by Romanian tax and accounting law, currently up to 10 years, after which they are deleted |
| Checkout emails where no purchase followed | 12 months, then deleted |
| Your entry in our contact list | Until you delete your account, which removes it. Unsubscribing stops the emails immediately; the record that you unsubscribed is kept so that you are not added back |
| Widget submissions and the associated IP hash | While the submission is under review, and for 12 months afterwards |
| Published widgets and their public listing details | Indefinitely, as public marketplace content. See Section 12 |
| Contact form messages | 24 months |
| Product statistics (Sections 4.1 and 8) | 12 months, then deleted automatically by our analytics provider. Deleting your account submits the records tied to your account hash for deletion at once, along with their history; the provider then purges them in batches, normally within a few days. Website records made before you bought are covered by the same deletion |
| Website records where no purchase followed | 12 months. They are tied to the dd_aid browser identifier and to no account |
| Server and platform logs | As retained by our hosting provider, typically a short rolling window |
12. Your rights
Under GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict or object to processing based on our legitimate interests;
- data portability, that is, receive your data in a machine readable format;
- withdraw consent where processing is based on consent; and
- complain to a supervisory authority.
You can export your data and delete your account directly from your account settings. You can also make any request by emailing contact@desktop-dashboard.com. We will respond within one month.
Two things to know before you delete your account:
- Deleting your account permanently ends your licence. Your licence key is revoked and cannot be reissued, and you lose access to the marketplace and to future downloads. This is explained in our Terms and Conditions, Section 5.1.
- Widgets you have published stay published. Under the marketplace's public content model, a published widget and its listing, including your publisher handle as its author, remain available after your account is deleted, so that copies people have installed keep working. Your account record and the non public parts of your submissions are deleted. If you believe a published widget should also be removed, contact us and we will consider it.
We may also need to retain a minimal record of your purchase where the law requires it, as set out in Section 11.
Supervisory authority. If you are in Romania, you may complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP, https://www.dataprotection.ro). If you are elsewhere in the EU, you may complain to your local authority.
13. Children
DeskDash is not intended for children. You must be at least 16 years old to purchase a licence or create an account. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Security
We take the following measures, among others:
- Login codes, session tokens and licence keys are stored as one way hashes, never in a form we could read or reuse.
- Comparisons of secret values are performed in a way designed to resist timing attacks.
- Raw IP addresses are never stored; where a record is needed for abuse prevention, only a salted hash is kept.
- The device identifier is hashed on your machine before it is sent.
- Secrets you supply to widgets are held by Windows Credential Manager and are never written to our configuration files, our logs, or exposed to widget code.
- Application updates are cryptographically signed and verified before they can be installed.
- Marketplace screenshots are stored in a private bucket and served through a proxy that checks on every request whether the file is still meant to be public.
- Access tokens used by our infrastructure are scoped as narrowly as the platform allows.
No system is completely secure. If you believe you have found a security problem, please email contact@desktop-dashboard.com and give us a reasonable opportunity to fix it before disclosing it publicly.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify you directly where the law requires it.
15. Changes to this policy
We may update this policy. When we make material changes, we will update the "Last updated" date above and, where the change significantly affects you, notify you by email.
16. Contact
For any privacy question, request, or complaint, contact us at contact@desktop-dashboard.com.