Privacy Policy

Last updated: July 20, 2026

Astrodesk("we", "us") is an AI back office for founders: catalog agents and custom agents that connect to your tools, draft work, and run on schedules. This policy explains what data we collect, why, and how you can control it.

1. Information we collect

Account information. When you sign up or sign in, we store your name, email address, and profile image, provided either directly or via a third-party sign-in provider (e.g. GitHub).

Project and agent data. For each project we store the profile and settings you provide, which agents you activate, schedules, drafts and outputs those agents produce (for example social posts, blog drafts, SEO reports, checklists, or custom-agent configs), and related activity so the app can show them back to you.

Connected accounts. If you connect GitHub, a social network (X, Threads, Instagram, Facebook, LinkedIn, TikTok, Reddit), or a tool such as Google Analytics, Search Console, Bing Webmaster, Stripe, Meta Ads, Intercom, PostHog, Sentry, or similar providers, we store the OAuth tokens or API keys (encrypted at rest) needed to act on your behalf within the scopes you grant. Examples: publishing a post you approved, reading search or revenue metrics, or reading repo context for an agent. We only request the minimum permission scopes each feature needs.

Uploaded media. Images and video you upload or generate for posts are stored with our file-hosting provider (UploadThing) and referenced by your account. Deleting a media attachment removes the underlying file.

AI-assisted content. When you use AI features (agent runs, canvas chat, captions, blog drafts, reports, image generation), the text you provide and relevant project context (including data from connections you enabled) are sent to our AI provider (OpenAI) to generate a response. We do not use your content to train third-party models.

Billing information. Payments are processed by Stripe. We store your Stripe customer ID, subscription status, and related billing metadata, but never your full card number. Stripe handles card data directly. New accounts may start with a 14-day trial before a paid subscription.

Usage data. We may log basic technical data (timestamps, error traces, request metadata) to operate and debug the service.

2. How we use your information

  • To provide and operate the features you use (agents, scheduling, analytics, publishing, AI assist).
  • To run agent workflows you enable and to publish or send content only when you (or a schedule you configured) explicitly direct it.
  • To process payments and manage your trial or subscription.
  • To detect, prevent, and fix technical issues or abuse.
  • To communicate with you about your account or changes to the service.

We do not sell your personal data.

3. Third-party services

We rely on the following providers to operate Astrodesk; each processes data under its own privacy policy:

  • Platforms and tools you choose to connect (for example GitHub, X, Meta, TikTok, Reddit, LinkedIn, Google, Bing, Stripe, Meta Ads, Intercom, PostHog, Sentry, and similar)
  • OpenAI: AI text and image generation for agent and assist features
  • Stripe: payment processing
  • UploadThing: file storage for uploaded or generated media
  • Our hosting and database providers

4. Data retention

We retain your account data for as long as your account is active. Disconnecting a connection deletes the associated tokens or keys from our systems. You can delete individual pieces of content (posts, media, agent outputs) at any time; deleting your account removes the rest.

5. Your rights

You can access, correct, export, or delete your data by using the app directly, or by contacting us (below). If you are in the EEA/UK, you have rights under GDPR including access, rectification, erasure, and data portability. If you are a California resident, you have rights under the CCPA.

6. Security

OAuth tokens and API keys are encrypted at rest (AES-256-GCM). Access to production data is restricted to the operators of the service. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your information.

7. Children's privacy

Astrodesk is not directed at children under 13, and we do not knowingly collect data from them.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

9. Contact

Questions about this policy or your data? Contact us at privacy@astrodesk.dev.