Data handling
What Deskhand stores, and what happens to it
Deskhand holds the records your agents write: contacts, companies, deals, notes and tasks, plus the log of who changed what. This page lists exactly what that is.
What is stored
| Data | Why | Form |
|---|---|---|
| Your sign-in email | To send your sign-in link and identify your workspace | Plain text |
| Agent keys | To authenticate your agents | SHA-256 hash and a short visible prefix. The full key is shown once at creation and is not recoverable |
| Contacts, companies, deals, notes, tasks | The records your agents and you maintain | Rows scoped to your workspace |
| Audit log | To show who changed what, and to make changes reversible | Append-only entries with before and after values |
Where it lives
On Cloudflare infrastructure (Workers and D1). Sign-in links are sent through a transactional email provider. Both are named in the privacy policy, which also states the legal basis and retention for each kind of data.
What we do not do
- We do not sell your data or use it to train AI models.
- We do not enrich your contacts from other sources.
- We do not read your records except to operate the service or when you ask for support.
The contacts your agents store
The people in your CRM are your contacts, and you decide what your agents record about them. Deskhand processes that data on your behalf to run the service. Keep to what you could explain to the person if they asked.
Leaving
Your data is yours. We never sell it or use it to train models.
- Bring it in: import a CSV, with HubSpot and Attio exports mapped for you. You see a preview first, and each import can be undone in one click.
- Take it out: Settings downloads everything as one JSON file, or any record type as CSV. Agent keys are stored as hashes and are not part of it.
- Delete it: Settings deletes your account and everything in the workspace, immediately and for good.