Privacy Policy
Last updated 29 September 2026
Third-party notices · GDPR and data requests
Early-access requests
If you join the early-access list, we store your email address, signup time and consent version for beta and launch notifications. A signup does not create an account. You can request removal by contacting privacy@primaldesk.com.
What we process
Account records include your email address, display name, password hash (if you use a password), linked sign-in provider and provider account ID, verification status and account timestamps. Authentication records include hashed refresh credentials, device or browser type, IP address, user agent and expiry. Host records include machine name, device identifiers and public key, owner and member relationships, access decisions, network candidates, certificate fingerprints, agent version and configuration saved in your account. We also keep subscription and billing records where applicable; connection authorization and session audit records such as the host, authorized user, client address, start and end times; and administrative and security events. The early-access list is separate from an account.
Why we process it
We use identity and authentication data to create and protect accounts, verify sign-ins and recover access (service delivery and security). Host identities, memberships, access rules and short-lived connection tickets let you authorize the correct users and operate separate Windows sessions (service delivery). Configuration and status reports let owners administer hosts and troubleshoot failures (service delivery and legitimate interest in reliability). Session and security logs help investigate misuse, maintain service integrity and respond to incidents (legitimate interest in security). Subscription records support entitlements and, when payments become available, accounting and legal obligations. Beta email and optional website analytics rely on separate consent, which you can withdraw. We do not use remote desktop content or host security rules for advertising.
Host configuration and session content
The host keeps its protected local settings on the Windows machine. When you save configuration in the account, the desired configuration is also stored by the cloud service and sent to that host. Cloud access lists, host memberships and connection tickets are processed to authorize users. Desktop video, audio, input and clipboard content are handled by the client and host for the session; a relay may carry encrypted traffic when a direct route is unavailable. The account service does not store a recording of your desktop session.
Retention
When you delete an account, we revoke its host access and active sign-in sessions, remove its password hash, and replace its email address and display name with deletion markers. Related operational and audit records may remain for security, dispute resolution and legal compliance; deletion does not necessarily erase those records immediately. Billing records, where present, may be retained when required by law. You can ask privacy@primaldesk.com about a specific record or retention period.
Your rights
From Account → Privacy you can export a portable JSON copy and request erasure. You may also request correction, restriction, or object to processing by contacting privacy@primaldesk.com.
Essential cookies
PrimalDesk uses a strictly necessary HttpOnly refresh cookie for authentication. We also store your analytics choice in pd_analytics_consent for 180 days, shared between primaldesk.com and docs.primaldesk.com. Rejecting analytics does not prevent you from using the service.
Microsoft Clarity
With your consent, we use Microsoft Clarity on our public website and documentation to understand navigation, clicks and scrolling through heatmaps and session replays. Clarity receives usage, browser and device information and uses cookies such as _clck and _clsk to associate visits. These recordings concern website interactions, not your remote desktop. We do not load Clarity on Workspace, account, authentication or device-authorization pages. Forms are masked.
Microsoft and your data
Microsoft processes information collected through Clarity under the Microsoft Privacy Statement, including for its own purposes described there, such as providing and improving services and advertising. Our integration grants analytics storage only; advertising storage is denied. Microsoft may process data outside your country. Read Microsoft’s cookie documentation for details of the cookies and their purposes.
Google Tag Manager
With your consent, the public website loads Google Tag Manager to manage analytics tags. Google Analytics, when configured in that container, measures page views and usage and may store _ga cookies. Advertising consent remains denied. See Google’s Privacy Policy. Google tags are not loaded on account, authentication or Workspace pages.
Your analytics choice
Clarity and Google Tag Manager are not loaded until you select Accept. Select Reject to keep analytics off. You can change or withdraw your choice at any time using . Withdrawal stops collection on the current page by reloading it, removes first-party Clarity and Google Analytics cookies, and is checked by other open public-site and docs tabs. It does not retroactively delete information already collected; contact privacy@primaldesk.com about data requests.
Website and documentation analytics
Your consent applies to both the public PrimalDesk website and its documentation on this browser. It is separate from early-access email consent. Clearing cookies or using another browser may cause us to ask again. We do not load the reference template’s Webflow analytics.