Privacy Policy
DevDesk Privacy Policy
DevDesk is an offline-first developer toolbox for Android and Windows. This Privacy Policy explains what information stays on your device and what information is transmitted only when you deliberately use a feature that communicates with another service.
Important: DevDesk does not operate an online account system, advertising service, analytics platform, telemetry service, cloud synchronization service or intermediary API server.
1. Scope and developer information
This Privacy Policy explains how DevDesk, published by Baisalya, accesses, processes, stores, transmits, retains and deletes information when you use the DevDesk application on Android or Windows.
DevDesk is an offline-first developer toolbox. Most app content and settings remain locally on your device.
DevDesk has no DevDesk-operated user account system, advertising, analytics, telemetry, cloud synchronization or application backend. Baisalya does not ordinarily receive your locally stored notes, API workspaces, request history, credentials, settings or app-usage information.
2. Information stored on your device
DevDesk stores information locally only as necessary to provide the features you choose to use. Ordinary application records are stored within the app's private local data area.
Depending on the features you use, local information may include:
- Markdown documents, notes, snippets, favourites and recently used tools.
- Appearance settings, theme preferences and other application preferences.
- API workspaces, collections, environments, request history and response history.
- Locally generated reports, snippets and other developer-tool output.
- Vault entries and values that you choose to mark as protected secrets.
- A local record of the Privacy Policy version you acknowledged and the acknowledgement time.
- Local rating-prompt preferences, launch counters and related user-interface state.
Sensitive information may be redacted from certain portable records where supported. However, automated redaction cannot guarantee that every confidential value will be detected.
3. Credentials and protected values
API credentials and values marked as secrets are separated from ordinary workspace records where the operating system provides an appropriate protection boundary.
- Android: protected secret values are encrypted using a key held by Android Keystore.
- Windows: protected secret values are secured using Windows Data Protection API, also known as DPAPI, for the current Windows user.
- Protected secret values are excluded from DevDesk-generated backups, collection exports, reports, portable request history, generated snippets and clipboard output where those features support protected values.
You are responsible for determining whether information is safe to store, send, copy or export. Do not store production credentials in an unprotected field.
4. User-initiated network activity
DevDesk does not send analytics, telemetry or locally stored content to Baisalya. Network communication occurs only when you use a feature that requires access to another service or page.
User-initiated network activity may include:
- API Tester: sends the URL, HTTP method, headers, authorization information, parameters, cookies and request body that you prepare to the server or service whose URL you choose. DevDesk then receives the response returned by that destination.
- GitHub tools: supported comparison, preview or import actions may fetch public repository metadata, files or archives from GitHub URLs that you choose.
- Link checking: a link-validation feature may send an HTTP request, such as a HEAD request, to the URL that you ask DevDesk to check.
- External destinations: rating, store, support, repository and other external-link actions open the applicable Google Play, Microsoft Store, GitHub or browser destination after you select the action.
DevDesk does not proxy API Tester requests through a DevDesk-operated server.
5. Information received by destination services
A server or service contacted through an action you initiate receives the information required to complete that action.
Depending on what you enter and send, the destination may receive:
- Your device's public IP address.
- The destination URL and request method.
- Headers and authorization information.
- Cookies and query parameters.
- Request-body content.
- Files or other content that you deliberately include.
- Technical connection information normally associated with an HTTP request.
The destination service, network provider, operating system, browser, Google Play, Microsoft Store or GitHub may process information under its own terms and privacy policy.
Review the destination URL before sending a request. Use HTTPS when transmitting sensitive information.
Android production builds block cleartext HTTP connections. The Windows version follows the URL and protocol that you choose.
6. Files, exports, backups and clipboard
DevDesk reads a file only after you select it using the applicable platform file picker or another deliberate file-selection action.
- Android uses document access supplied by the operating system and does not require broad access to all files on the device.
- Windows accesses files and folders at paths selected by you.
Files, reports, backups and exports remain in the location where you choose to save or share them. These exported copies exist separately from DevDesk's private local application data.
Explicit copy actions place selected content in the operating-system clipboard. Clipboard managers, synchronized clipboard services and other applications may be able to access clipboard content according to operating-system behaviour and your device settings.
DevDesk applies conservative redaction to supported portable API history, reports, generated snippets, clipboard output, collection exports and backups. Automated redaction cannot guarantee that every confidential value will be identified. Always review content before saving, copying, exporting or sharing it.
Redaction of stored history, exports and clipboard output does not automatically remove headers, credentials, cookies, parameters or body content from an API request that you deliberately send to a destination server.
Remote images in Markdown previews are blocked so that previewing Markdown does not silently load remote tracking pixels or other remote image resources.
8. Security and platform boundaries
DevDesk uses safeguards that may include:
- Platform-private application storage.
- Protected storage for secret values where supported.
- Guarded file replacement and validated backup imports.
- Bounded network operations and request validation.
- Redaction of supported portable API data.
- Disabled Android application backup and data extraction.
No method of storage, encryption or transmission can provide absolute security.
Device administrators, malware running under your user account, screen capture, clipboard managers, synchronized clipboard services, operating-system backups, compromised devices and the security practices of destination services are outside DevDesk's control.
Android application backup and device-transfer extraction are disabled for DevDesk private application data. Windows application data follows the current Windows user profile and the backup policies configured for that profile or device.
9. Retention and deletion
Local DevDesk records remain on your device until one of the following occurs:
- You delete an individual record using an available app control.
- You use the DevDesk Clear All Data feature.
- You clear DevDesk application data through the operating system.
- You uninstall DevDesk.
- An application limit removes older history or report entries.
Clear All Data cancels active API work and removes known local application records, protected secret records, settings, rating state and the locally stored Privacy Policy acknowledgement record. The Privacy Policy acknowledgement screen may appear again after the reset.
Backups, reports and files that you exported are separate copies. You must delete those copies from their saved or shared locations yourself.
Information already transmitted to a destination service is controlled by that destination service and must be managed or deleted through that service.
DevDesk has no online account to delete and no server-side DevDesk user profile.
10. Children's privacy
DevDesk is a professional developer tool and is not designed or directed specifically toward children.
DevDesk does not knowingly operate an online service that collects children's personal information for advertising, profiling or analytics.
A parent or guardian who believes that a child has submitted personal information directly to the developer may contact the developer using the contact information below.
11. International data transfers
DevDesk does not transfer locally stored information to a DevDesk-operated server.
When you send an API request, open an external service or use a GitHub-related feature, the destination service may process information in a country different from your own. Any such processing is governed by the destination service's infrastructure, terms and privacy policy.
12. Changes to this Privacy Policy
The effective date and policy version appear at the top of this page.
This policy may be updated when DevDesk features, privacy practices, legal requirements or platform requirements change.
When a material in-app Privacy Policy change is introduced, DevDesk may update the policy version and ask you to acknowledge the revised policy before continuing to use the app.
13. Contact, privacy questions and security reports
For privacy questions, data-handling questions or concerns about this Privacy Policy, contact:
Email: baishalya1999@gmail.com
General app-support questions and non-sensitive bug reports may also be submitted through the DevDesk support issue tracker .
Do not include passwords, API tokens, credentials, private request bodies, personal information or confidential business information in a public GitHub issue.
Security vulnerabilities should be reported through a private GitHub security advisory or by email at Click Here .
Do not disclose security vulnerabilities, secret values or exploit details through a public issue.