Privacy Policy

DevDesk Privacy Policy

Effective date: 24 July 2026  •  Policy version: 2026-07-24

DevDesk is an offline-first developer toolbox for Android and Windows. This Privacy Policy explains what information stays on your device and what information is transmitted only when you deliberately use a feature that communicates with another service.

Important: DevDesk does not operate an online account system, advertising service, analytics platform, telemetry service, cloud synchronization service or intermediary API server.

1. Scope and developer information

This Privacy Policy explains how DevDesk, published by Baisalya, accesses, processes, stores, transmits, retains and deletes information when you use the DevDesk application on Android or Windows.

DevDesk is an offline-first developer toolbox. Most app content and settings remain locally on your device.

DevDesk has no DevDesk-operated user account system, advertising, analytics, telemetry, cloud synchronization or application backend. Baisalya does not ordinarily receive your locally stored notes, API workspaces, request history, credentials, settings or app-usage information.

2. Information stored on your device

DevDesk stores information locally only as necessary to provide the features you choose to use. Ordinary application records are stored within the app's private local data area.

Depending on the features you use, local information may include:

Sensitive information may be redacted from certain portable records where supported. However, automated redaction cannot guarantee that every confidential value will be detected.

3. Credentials and protected values

API credentials and values marked as secrets are separated from ordinary workspace records where the operating system provides an appropriate protection boundary.

You are responsible for determining whether information is safe to store, send, copy or export. Do not store production credentials in an unprotected field.

4. User-initiated network activity

DevDesk does not send analytics, telemetry or locally stored content to Baisalya. Network communication occurs only when you use a feature that requires access to another service or page.

User-initiated network activity may include:

DevDesk does not proxy API Tester requests through a DevDesk-operated server.

5. Information received by destination services

A server or service contacted through an action you initiate receives the information required to complete that action.

Depending on what you enter and send, the destination may receive:

The destination service, network provider, operating system, browser, Google Play, Microsoft Store or GitHub may process information under its own terms and privacy policy.

Review the destination URL before sending a request. Use HTTPS when transmitting sensitive information.

Android production builds block cleartext HTTP connections. The Windows version follows the URL and protocol that you choose.

6. Files, exports, backups and clipboard

DevDesk reads a file only after you select it using the applicable platform file picker or another deliberate file-selection action.

Files, reports, backups and exports remain in the location where you choose to save or share them. These exported copies exist separately from DevDesk's private local application data.

Explicit copy actions place selected content in the operating-system clipboard. Clipboard managers, synchronized clipboard services and other applications may be able to access clipboard content according to operating-system behaviour and your device settings.

DevDesk applies conservative redaction to supported portable API history, reports, generated snippets, clipboard output, collection exports and backups. Automated redaction cannot guarantee that every confidential value will be identified. Always review content before saving, copying, exporting or sharing it.

Redaction of stored history, exports and clipboard output does not automatically remove headers, credentials, cookies, parameters or body content from an API request that you deliberately send to a destination server.

Remote images in Markdown previews are blocked so that previewing Markdown does not silently load remote tracking pixels or other remote image resources.

7. Sharing, sale and third-party software

Baisalya does not sell user data.

DevDesk does not share locally stored content with advertisers, data brokers or a DevDesk-operated service. User-initiated transfers described in this policy are sent only to the destination service selected by you or to the external page that you choose to open.

DevDesk does not include advertising, analytics, Firebase, social-login or payment SDKs.

Flutter packages used for local storage, file selection, package information, protected platform storage, HTTP requests, archive handling and URL launching operate when the corresponding app feature requires them.

8. Security and platform boundaries

DevDesk uses safeguards that may include:

No method of storage, encryption or transmission can provide absolute security.

Device administrators, malware running under your user account, screen capture, clipboard managers, synchronized clipboard services, operating-system backups, compromised devices and the security practices of destination services are outside DevDesk's control.

Android application backup and device-transfer extraction are disabled for DevDesk private application data. Windows application data follows the current Windows user profile and the backup policies configured for that profile or device.

9. Retention and deletion

Local DevDesk records remain on your device until one of the following occurs:

Clear All Data cancels active API work and removes known local application records, protected secret records, settings, rating state and the locally stored Privacy Policy acknowledgement record. The Privacy Policy acknowledgement screen may appear again after the reset.

Backups, reports and files that you exported are separate copies. You must delete those copies from their saved or shared locations yourself.

Information already transmitted to a destination service is controlled by that destination service and must be managed or deleted through that service.

DevDesk has no online account to delete and no server-side DevDesk user profile.

10. Children's privacy

DevDesk is a professional developer tool and is not designed or directed specifically toward children.

DevDesk does not knowingly operate an online service that collects children's personal information for advertising, profiling or analytics.

A parent or guardian who believes that a child has submitted personal information directly to the developer may contact the developer using the contact information below.

11. International data transfers

DevDesk does not transfer locally stored information to a DevDesk-operated server.

When you send an API request, open an external service or use a GitHub-related feature, the destination service may process information in a country different from your own. Any such processing is governed by the destination service's infrastructure, terms and privacy policy.

12. Changes to this Privacy Policy

The effective date and policy version appear at the top of this page.

This policy may be updated when DevDesk features, privacy practices, legal requirements or platform requirements change.

When a material in-app Privacy Policy change is introduced, DevDesk may update the policy version and ask you to acknowledge the revised policy before continuing to use the app.

13. Contact, privacy questions and security reports

For privacy questions, data-handling questions or concerns about this Privacy Policy, contact:

Email: baishalya1999@gmail.com

General app-support questions and non-sensitive bug reports may also be submitted through the DevDesk support issue tracker .

Do not include passwords, API tokens, credentials, private request bodies, personal information or confidential business information in a public GitHub issue.

Security vulnerabilities should be reported through a private GitHub security advisory or by email at Click Here .

Do not disclose security vulnerabilities, secret values or exploit details through a public issue.