MyndDesk
Terms of Use Back to home
Privacy Policy

Privacy
Policy

What MyndDesk collects, why, and how you stay in control of it — written in plain language, covering every feature in the product today.

Last updated: August 5, 2026Version 2.1Applies platform-wide

The short version

We collect what’s needed to run your workspace — your account, the content you create, and (only if your org enables it) your location for attendance. We never sell your data, and Pip AI only sees what a query needs to answer it.

On this page

  1. 01Who this policy covers
  2. 02Information we collect
  3. 03How we use it, and the AI assistant
  4. 04Who we share information with
  5. 05Who inside your organization can see what
  6. 06Cookies & local storage
  7. 07How long we keep data
  8. 08How we protect it
  9. 09Your rights and choices
  10. 10Children’s privacy
  11. 11International data transfers
  12. 12Changes to this policy
01

Who this policy covers

This Privacy Policy explains how MyndDesk collects, uses, and protects information across our marketing site and the dashboard application — attendance, tasks, projects, notes, calendar, clients, and the Pip AI assistant.

MyndDesk is a multi-tenant workspace: your data lives inside an organization, and what a teammate can see within that organization depends on their role. Section 5 explains exactly how that works.

02

Information we collect

We collect information in three ways: what you give us, what your device sends automatically, and what your organization’s admin configures.

Account & profile

Full name, email address, password (stored as a salted hash — we never see or store it in plain text), phone number, job title, and profile photo. Creating an organization adds its name, URL slug, website, country, and phone number.

Content you create

Tasks, notes, projects, client records, calendar events, decisions, time logs, and any files or comments you add to them. This is your operational data — we store it so the product works, not to read it ourselves.

Location, only for Attendance

If your organization enables the Attendance feature and you grant your browser’s location permission, we read your device’s GPS position (roughly every 5 minutes while the tab is active) to calculate your distance from your office and drive automatic clock-in/out. Nothing is read if the feature is off or permission is denied.

Pip AI conversations

When you message the assistant, your prompt and a snapshot of the dashboard data needed to answer it (e.g. your task list) are sent to our AI provider for that single request. See Section 3 for how this is handled.

Automatic & device data

Sign-in sessions, IP address, browser and device type, and basic usage events (pages viewed, features used) if you’ve allowed analytics cookies. See Section 6.

Share-link attribution

When someone uses a MyndDesk share control or opens one of its unique links, we record the selected channel, source page, time, referring domain when supplied, IP address, approximate IP-based location, browser, operating system, device type, link visits, and whether that visit results in a verified account. We cannot see the recipient, private message, contact list, or destination selected from a device’s general share menu.

Waitlist & contact forms

If you join our early-access waitlist: name, company, role, phone number, email, and where you heard about us. This never requires an account.

03

How we use it, and the AI assistant

We use information to operate and secure the platform: authenticate you, enforce your organization’s roles and permissions, run the features you turn on (Attendance, notifications, invitations), send you transactional email and SMS, and fix bugs.

Pip AI is powered by a cloud model we call through NVIDIA’s inference API. Each query sends only what’s needed to answer it — your message plus the relevant slice of your own dashboard data — for that single exchange. We don’t persist assistant conversations on our servers beyond the request, and neither we nor our AI provider use your data to train models.

We do not sell your personal information, and we do not use your operational data (tasks, notes, client records) for advertising.

04

Who we share information with

We share information only where it’s needed to run the service:

  • Inside your organization — following the role visibility described in Section 5, never beyond your organization’s boundary.
  • Service providers — our AI inference provider (NVIDIA) for assistant queries, our SMS provider for time-off and task alerts, our email/SMTP provider for transactional messages, and our IP geolocation provider for approximate share-link location when that integration is enabled. Each only receives what a specific feature needs to function.
  • Webhooks your admin configures — if an organization owner or admin sets up outbound webhooks, attendance events (clock-in, clock-out) are forwarded, HMAC-signed, to the URL they specify. That destination is outside our control — treat it as your organization’s own integration.
  • Legal & safety — if required to comply with law, enforce our Terms, or protect the rights and safety of our users.

We do not sell personal information to third parties, and we have no advertising or data-broker relationships.

05

Who inside your organization can see what

MyndDesk enforces role-based visibility on every organization-scoped record:

  • Owner & Admin see every record in the organization, whether or not it was shared with them.
  • Manager sees everything too, but can only edit or delete records they created (or, for tasks, are assigned to).
  • Member sees their own records plus anything explicitly shared or assigned to them.
  • Guest is read-only, and only for what’s been explicitly shared.

This is enforced the same way on our servers as in the interface — a Member’s private note is never returned to another Member’s session, regardless of what the screen shows.

06

Cookies & local storage

We use three categories of cookies and local storage, matching the choices in our cookie banner:

Strictly essential — always on

Keeps you signed in and your session secure. Without these the app cannot function, so they cannot be turned off.

Performance & analytics — optional

Helps us see which parts of the product are slow or confusing, in aggregate. Off by default until you opt in.

Personalization — optional

Remembers your theme, sidebar layout, and assistant preferences between visits. Off by default until you opt in.

You can change your choice at any time from the cookie settings link in the footer, or by clearing your browser’s local storage for this site.

07

How long we keep data

We keep information for as long as it’s needed for the purpose it was collected:

  • Account & organizational data — for as long as your account or organization exists, plus a reasonable window for backups and legal obligations after deletion.
  • Notifications — read notifications are cleared after 7 days, all notifications after 30 days, as a routine housekeeping policy.
  • Location readings — used to compute a live presence state; historical attendance logs are retained per your organization’s own policy, set by your admin.
  • Pip AI queries — not persisted server-side beyond the request that generated the response.
  • Share-link telemetry — raw IP addresses are removed after 30 days. Hashed identifiers, approximate location, channel, device, click, and registration attribution may be retained in aggregate to measure platform growth and prevent abuse.
08

How we protect it

Passwords are hashed, never stored or logged in plain text. Sessions use signed, HTTP-only cookies alongside bearer tokens for API access, so session tokens aren’t reachable from page scripts. Every request is scoped to your organization on the server — widening a query never lets it cross a tenant boundary. Administrative tooling capable of touching raw database tables is restricted to platform super-admins only, never regular organization owners or admins.

No system is perfectly secure. If you discover a vulnerability, please report it to the contact below before disclosing it publicly.

09

Your rights and choices

Wherever you’re located, you can ask us to:

  • Access or export the personal data we hold about you.
  • Correct inaccurate profile information — most of this you can edit directly from Settings.
  • Delete your account, or ask your organization’s owner to remove you from an organization.
  • Withdraw consent for Attendance location tracking (by disabling it or revoking browser permission) or for optional cookies at any time.

If data-protection law where you live (such as the GDPR or CCPA/CPRA) gives you additional rights — like lodging a complaint with a supervisory authority — those rights apply in full; nothing here limits them. Contact us using the details at the bottom of this page to exercise any of these.

10

Children’s privacy

MyndDesk is a workplace tool intended for users 18 and older, consistent with our Terms of Use. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we’ll remove it.

11

International data transfers

Because MyndDesk is used by distributed teams, your information may be processed in a country other than the one you live in — including wherever our hosting, database, and service providers operate. Where required, we rely on appropriate contractual safeguards to protect data that crosses borders.

12

Changes to this policy

We review this policy regularly and will update the “Last updated” date whenever it changes. For material changes — anything that meaningfully affects how we handle your data — we’ll post a notice in the app ahead of the change taking effect.

Questions about your data?

Reach out any time — whether it’s a rights request, a security report, or you just want clarity on how something works.

privacy@agbedus.com
© 2026 MyndDesk. All rights reserved.Terms of Use