Legal
Privacy policy
Last updated September 30, 2026
What Aiden Wu collects, what it's used for, who else handles it, and how to have it removed. Short version: we keep what it takes to run your help desk, and nothing is sold.
Two kinds of data
Your team's account: names and email addresses of the people on your team, the team name, billing contact and plan, and basic records of use (sign-ins, AI usage counts) that keep the service working and billed correctly.
Your customers' conversations: the emails and chat messages your customers send, the files attached to them, your team's replies and notes, and data you import from another help desk. For this data, your business is in charge (the “controller”) and we process it only on your instructions, to run the service for you (as “processor”).
What we use it for
- Running the help desk: receiving and sending email, showing chats, storing tickets and attachments.
- AI answers to customers, when your team has them on. They are on for new teams, and an admin can switch them off in Settings.
- Other AI features your team uses: reply drafts and summaries, writing and updating macros, and the AI test drive. These send ticket messages to our AI provider even when automatic AI answers are off.
- Billing your team (Stripe sends receipts and payment notices), and emailing admins when the AI allowance is 80% and 100% used.
- Keeping the service secure and fixing problems.
We don't sell data, show ads, or use your conversations to train AI models. Anthropic, which provides the AI, doesn't train its models on data sent through its API.
Who else handles it
These companies process data for us, each only for the part of the service listed:
- VercelHosting and running the app
- NeonThe database where tickets, messages and attachments are stored
- ClerkSign-in and team membership
- StripePayments and invoices (card details go to Stripe, never to us)
- ResendSending and receiving email
- AnthropicThe AI (ticket messages, your team's notes, macros and help articles, sent when an AI feature runs)
Most of these are in the United States. Where data moves across borders, we rely on these providers' standard contractual safeguards.
Cookies
We use cookies to keep you signed in. On our own website, a first-party cookie called fd_src notes where you came from (a campaign tag or the site that linked to us). If you sign up, it's saved with your team so we can see which sources bring sign-ups. It lasts 90 days and isn't shared. The website chat widget keeps a conversation token in the visitor's browser so they can come back to the same chat. There are no advertising cookies.
How long we keep it
We keep your data while your team has an account, including after a trial ends or a plan is cancelled, so you can export it or come back. Ask us to delete it and we'll do so within 30 days, apart from records the law requires us to keep, such as invoices. People who joined the waitlist can ask to be removed at any time.
Your rights
You can see, correct, export or delete your data. Most of it you can export yourself from Settings. For anything else, including a customer of one of our teams asking about their messages (we'll pass that to the team, since it's their data), email flatdeskmain@gmail.com. If you're in the EU or UK, you can also complain to your local data protection authority.
Security
Data is encrypted in transit and at rest by our hosting and database providers. Attachments can be downloaded only by your team, and by the chat visitor they were sent to. API keys for importing from another help desk are encrypted while an import runs and erased when it ends. To stop spam, the chat widget, satisfaction ratings and waitlist count requests by a one-way hash of the sender's IP address. We store the hash, not the address.
Changes and contact
If we change this policy in a way that matters, we'll email team admins before it takes effect. Questions go to flatdeskmain@gmail.com. See also our terms of service.