Privacy policy
Effective 19 August 2026 · Last updated 6 October 2026
desq is a tool for general contractors and builders. It reads the paperwork behind a construction job and turns it into a dated, cited record. Doing that means handling documents and correspondence that are commercially sensitive, and in some cases privileged. This page says plainly what we do with them.
We do not sell your data, we do not share it with advertisers, and we do not use it to train general purpose AI models.
1. Who we are
desq is operated by desq, Inc., a Delaware corporation. You can reach a human at hello@desq.ai for any question in this policy, including a request to delete your data.
2. What data desq holds
Data you give us directly
- Account details: your name, work email address, and the company you work for.
- Project information you enter: job names and numbers, parties, cost codes, dates.
- Documents you upload or photograph: contracts, change orders, invoices, receipts, lien waivers, pay applications, meeting minutes, schedules and so on.
Data that arrives at an intake address
Each project can have its own forwarding address. Anything sent to it is recorded, including messages that match no project and messages with nothing attached. We keep the sender, recipients, subject, date, message body and attachments. We deliberately record deliveries we could not route, because a document that arrives and vanishes silently is worse than one that never arrives.
Data from accounts you connect
If you connect a mailbox, a file storage folder, a calendar or an accounting system, desq reads what you have selected. Section 4 covers this in detail and is deliberately kept separate from everything else on this page.
Data we collect automatically
Server logs for security and debugging: IP address, timestamp, and which part of the application was called. This website sets no cookies, loads no fonts or scripts from third parties, and runs no analytics or advertising trackers of any kind. The application itself uses a single cookie to keep you signed in.
3. What we do with it
We use your data to run desq for you, and for nothing else. Specifically:
- To extract facts from documents and place them, with a citation, into your job record.
- To generate registers, reports and meeting packets you ask for.
- To detect duplicates, so the same invoice arriving twice is not counted twice.
- To keep the service secure, diagnose faults, and meet legal obligations.
We do not use your data for advertising, we do not sell or rent it, and we do not share it with anyone except the sub-processors listed in section 6.
4. How desq handles data from connected accounts
This section covers data obtained through Google APIs, Microsoft Graph, and other systems you explicitly connect. It is set out separately from our general practices on purpose.
Google user data
desq's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means:
- We request the narrowest scopes that let the feature work, and we ask for access to files and folders you select rather than to your whole account wherever the API allows it.
- We use Google user data only to provide and improve the features you connected it for, visible to you inside desq.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with the law.
- We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
- No human at desq reads your Google user data except with your explicit consent for a specific support issue, where required for security, or where the law requires it.
Microsoft data
Where you connect a Microsoft 365 or Outlook account, desq reads only the mail folders, file folders and calendars you select, using delegated permissions granted by you or your administrator. The same limits above apply: we use it to provide the features you connected it for, we do not sell it, and we do not train models on it. You or your administrator can withdraw consent at any time from your Microsoft account, and desq stops reading immediately.
Accounting data
Where you connect an accounting system, desq reads it and does not write to it.
Tokens
Access credentials for connected accounts are stored encrypted, are readable only by the server processes that need them, and are never exposed to the browser or to other customers. Disconnecting an account deletes them.
5. Automated processing, and the person in front of it
desq uses large language models to read documents and correspondence and to propose facts for your job record. Three things about that are worth stating clearly.
- desq files only what the documents account for. Most figures and facts extracted from a document are held for review and do not affect any financial total until a person confirms them. Where the documents account for every part of an item, such as a payment whose bank memo names the job, desq may file it on its own. It records why, anyone on your account can undo it, and desq stops filing that kind of item on its own once a person reverses one. desq never writes to your accounting software.
- Untrusted documents are treated as untrusted. An invoice or an email arriving from outside your company is data, not instruction. desq applies protections against prompt injection and does not let the content of a document direct what the system does.
- Your data does not train anyone's model. Content you connect or upload is not used to train or improve general purpose models, ours or a vendor's.
6. Who else touches it
desq runs on infrastructure operated by other companies. Each one is bound by contract to process your data only on our instructions.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage, authentication | United States |
| Postmark | Inbound and outbound email | United States |
| Anthropic | Language model processing of documents | United States |
| Netlify | Hosting for this website and the desq web app. Requests to the app pass through it, including some that carry job data; it does not store your documents. | United States |
We will update this list before adding a new sub-processor that handles customer content.
7. How long we keep it
A construction record is useful precisely because it accumulates, so by default we keep your job data for as long as your account is active. That said:
- You can delete individual documents and records at any time from within desq.
- You can ask us to delete your account and everything in it by writing to hello@desq.ai. We will do so within 30 days and confirm when it is done.
- Disconnecting a connected account deletes its stored credentials immediately.
- Backups are retained for a limited period and are overwritten on a rolling basis.
One deliberate exception: because desq is built to preserve a correction rather than overwrite it, deleting a record removes it from your registers but the fact that something was recorded and later removed remains in the audit history. That is the point of an audit history. If you need a record fully expunged, write to us and say so.
8. Security
- Data is encrypted in transit and at rest.
- Access is enforced at the database row level, so one customer's data is not reachable from another customer's session.
- Credentials for connected accounts are held in a dedicated secrets store, separate from application data.
- Write access to the historical record is restricted to server side processes. Application history is append only and cannot be silently rewritten, including by us.
No system is perfectly secure. If you believe you have found a vulnerability, write to hello@desq.ai and we will respond.
9. Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to certain processing. Write to hello@desq.ai and we will act on it. We will not charge you for it and we will not make the service worse for you because you asked.
desq is operated from the United States and your data is processed there.
10. Children
desq is a business tool and is not directed at anyone under 18.
11. Changes
If we change this policy in a way that materially affects how we handle your data, we will tell you by email before it takes effect rather than quietly changing the date at the top.