Skip to content
EditDesk
Features Pricing FAQ How it works
Sign in Open the desk
Features Pricing FAQ How it works Sign in Open the desk

Legal

Privacy Policy

Last updated: 26 July 2026. This policy explains how EditDesk handles personal data. Have it reviewed for your specific hosting, analytics, and company details before launch.

1. Who is responsible

The operator of EditDesk (“we”, “us”) is the data controller for personal data collected through this website and the EditDesk admin service, unless we process data solely as a processor for a customer under a separate written agreement.

If you are an agency using EditDesk for client work, you are typically the controller for your clients’ personal data; we process that data on your instructions to provide the Service.

2. Data we collect

Depending on how you use EditDesk, we may process:

  • Account data: name, email address, password (hashed), and profile settings.
  • Workspace data: clients, agents, job inputs/outputs, schedules, usage metrics, delivery metadata, review tokens, and related logs.
  • Credentials you store: LLM API keys, WordPress application passwords, webhook secrets, and similar secrets (encrypted at rest where the product supports it).
  • Content you submit: keywords, briefs, source URLs, uploaded images, brand voice rules, and editorial notes.
  • Technical data: IP address, browser/user agent, timestamps, and security logs needed to operate and protect the Service.
  • Communications: emails you send us, and system emails we send (for example job failure or client approval notices).

We do not intentionally collect special-category data. Please do not submit sensitive personal data in briefs unless necessary and lawful.

3. Why we use data (purposes & lawful bases)

  • Provide the Service (contract): accounts, jobs, delivery, review links, schedules, support.
  • Secure and improve the Service (legitimate interests): abuse prevention, debugging, reliability.
  • Billing and administration (contract / legitimate interests): invoices, plan limits, usage reporting.
  • Legal compliance (legal obligation): where required to retain or disclose information.
  • Marketing communications (consent or soft opt-in where permitted): only if we send them; you can opt out.

4. BYOK and third-party processors

When you run a job, prompts and related content are sent to the LLM and other providers you configure (for example OpenAI, Azure OpenAI, Anthropic, Google Gemini, WordPress, Unsplash, your webhook endpoint, or your email provider). Those providers process data under their own terms and privacy policies. Choose providers appropriate for your clients and region.

We also use infrastructure needed to host EditDesk (for example web hosting, database, queue/cache, and transactional email). Contact us for a current subprocessor list if you need it for client DPAs.

5. Client review links

Review links use a secret token. Anyone with the link can view the package until it expires or is invalidated. Share links only with intended recipients. Do not post them publicly.

6. Cookies and similar tech

The admin Service uses cookies/session storage required for authentication and security. The marketing site may use essential cookies only unless we add analytics later (in which case we will update this policy and, where required, ask for consent).

7. Retention

  • Account and workspace data are kept while your account is active and for a reasonable period afterward for backups, disputes, and legal requirements.
  • Job logs and outputs may be retained to provide history inside your desk; you can request deletion subject to technical and legal limits.
  • Security logs are kept for a limited period appropriate to abuse investigation.

8. Security

We use reasonable technical and organisational measures, including encrypted storage of secrets where implemented, access controls, and SSRF safeguards for URL fetching. No method of transmission or storage is perfectly secure. You must use strong passwords, protect API keys, and rotate credentials if exposure is suspected.

9. International transfers

If you or your configured providers process data outside the UK/EEA, transfers may occur. LLM and CMS providers often process data in the United States or other regions. You are responsible for assessing transfer risk for your clients when selecting providers and destinations.

10. Your rights

If UK/EU GDPR applies to you as an individual, you may have rights to access, rectify, erase, restrict, object, or port personal data, and to complain to a supervisory authority (in the UK, the ICO).

To exercise rights related to data we control, contact the EditDesk operator using the details on this site or your onboarding correspondence. If you are an end client of an agency using EditDesk, contact that agency first.

11. Children

EditDesk is a business tool and is not directed at children. We do not knowingly collect personal data from children.

12. Changes

We may update this Privacy Policy by posting a new version with a revised date. Material changes will be highlighted where practical.

13. Contact

Privacy questions: contact the EditDesk operator via the details published on this website or your service agreement.

EditDesk

The BYOK content ops desk for agencies. Research, draft, client-approve, and deliver, without runaway API spend.

Product

Features Pricing FAQ Open the desk

Legal

Terms Privacy

© 2026 EditDesk

Approve before live. Keys stay yours.