1. Who is responsible
FlashCat LLC, a Wyoming limited liability company, operates AttackDesk. Contact support@attackdesk.com with privacy questions or requests. This policy covers our marketing website, account hub, managed services, and information received from connected copies of the software.
We act on our own behalf for account administration, billing, security, and operating our business. For customer information processed within a business workspace, that business generally decides the purposes and acts as the controller or business, while we provide the requested processing service. If you are that business’s customer or employee, start with its administrator for requests about its records. We can help identify the appropriate contact.
A self-hosted copy and services you connect directly can have separate operators and privacy practices. This policy does not describe every change a customer makes to the code or replace that customer’s privacy notice.
2. Information you and your organization provide
Account and business information may include name, email, company, role, website, industry, team size, invitations, preferences, and support correspondence. Phone or domain registration may require address, business registration or tax identifiers, authorized representative details, phone numbers, and consent documentation.
Depending on the features used, workspace information can include contacts, leads, deals, appointments, messages, email addresses, phone numbers, call metadata, recordings, transcripts, invoices, files, website and SEO data, prompts, AI outputs, code, and integration settings. We receive this information when you submit it to our hosted services, send it through a managed provider, or share it for support.
Payment information is collected by Stripe through its payment interface. We receive payment and subscription identifiers, status, amounts, receipts, and limited billing details needed to administer purchases. Our application does not receive your full card number or card security code through that interface. Do not send card details in support messages.
3. Technical information and connected copies
When you use our services, our infrastructure and providers can process IP addresses, device and browser information, request times, errors, authentication events, service usage, transaction records, and abuse or security signals.
An account-connected downloaded copy sends check-ins, ordinarily about daily and when its version or integrity state changes. These can include its installation identifier, software version, integrity fingerprint, and counts of projects, users, contacts, companies, deals, messages, appointments, and automations in that installation. These counts can cover the installation as a whole. The check-in itself does not contain the names or message contents of those records.
Downloads can include an installation identifier linked to the downloading account. We use installation records to manage connected copies, updates, compatibility, license integrity, support, and abuse prevention. This account check-in is separate from optional product analytics. Sending a call, email, model request, code upload, or support attachment may transmit actual content even though the check-in sends counts.
4. How information is used
We use information to authenticate people, administer organizations and permissions, provide requested features, route communications and AI requests, manage integrations, process payments and credits, provide updates and support, diagnose problems, prevent fraud and abuse, comply with law, and establish or defend legal claims.
We may communicate about your account, security, purchases, and service changes. Marketing communications are separate and include an unsubscribe option where required. We do not treat a phone registration or a customer’s consent to your messages as permission for our own promotional texts.
Where a legal basis is required, we rely on performance of a contract, legal obligations, legitimate interests such as securing and operating the service, or consent, as appropriate. Customer-directed processing follows the applicable customer agreement and lawful instructions.
5. Providers and other recipients
We disclose information needed by service providers to perform the services we use them for. Depending on your configuration, these include Cloudflare for infrastructure, DNS, storage and email services; Stripe for payments and fraud prevention; Twilio and carriers for phone numbers, calls, messaging and registration; and Resend for account and invitation emails when configured.
Google or GitHub receives authentication information when you choose its sign-in service. Model providers and other integrations you select receive the inputs needed for those requests. SEO, research, analytics, advertising and publishing services can receive the queries, sites, content or account data you connect. Providers may have their own independent obligations and privacy notices.
Your organization’s administrators and the people you authorize can access information according to their roles. Staff can access information needed for support, account administration, security, or legal obligations; code support may involve a branch or archive attached to a request. Do not include unrelated secrets in a support request.
We may disclose information to comply with valid legal process, protect rights and safety, address fraud or security issues, or in a business transaction such as a merger or acquisition, subject to applicable protections. We do not sell personal information or share it for cross-context behavioral advertising in the current service. SMS opt-in information is not sold or shared for unrelated marketing; necessary service processing and legal disclosures still apply.
6. AI, local models, and your own providers
Cloud AI requests can include prompts, uploaded material, tool results, and relevant workspace context. The selected model provider processes that information under the terms applicable to that connection. Do not assume that every provider offers the same retention, training restrictions, location, or deletion controls.
Local-model processing may stay on the machine running the model, but connected tools and remote services can still transmit information. A coding agent with access to your files or database is a separate recipient under the permissions you grant it.
We do not operate a general-purpose model training program using private workspace content. This does not promise that a separately selected provider has no training or retention rights. Choose suitable provider terms and settings before sending sensitive information.
7. Cookies, storage, and analytics
The account app uses cookies and similar storage for sign-in, security, navigation, and preferences. Payment and security providers may use their own identifiers for transaction security and fraud detection. Blocking necessary storage can prevent sign-in or checkout.
The current marketing site does not include advertising pixels or optional product analytics. Hosted CRM builds have optional PostHog analytics and error-reporting code that runs when configured. It can report page activity, events, user or organization identifiers, and errors; session replay may be enabled in those deployments. Local account check-ins are a different mechanism.
Optional analytics and replay should be enabled only with the notices and choices required for the deployment. Hosted browser analytics is configured to respect Do Not Track; server security, account, billing, and necessary service records are not disabled by that signal. Because the current marketing site does not sell or share information for targeted advertising, an opt-out preference signal does not change that practice. Contact us about privacy choices for a particular deployment.
8. Retention, account closure, and copies
We retain information for as long as reasonably needed for the service, the customer’s instructions, support, security, transaction reconciliation, legal recordkeeping, and dispute resolution. The appropriate period depends on the category, purpose, sensitivity, legal requirements, and whether deletion or de-identification is feasible.
Canceling a subscription is not the same as requesting deletion of an account. Ask us about export or deletion before closing a hosted workspace. Backup copies, audit records, billing records, consent evidence, and information needed for legal claims may remain longer where permitted or required. A displayed backup window describes a service benefit only when that backup service is actually enabled; it is not a universal deletion deadline.
We cannot delete copies held on your devices, by a recipient of your message, or by a provider you contract with directly. Organization administrators control business records within their workspace, subject to applicable law and contract.
9. Security and international processing
We use safeguards appropriate to the service, including account permissions and server-side handling of provider credentials. No transmission, computer, or storage system is perfectly secure. Your deployment choices, plugins, permissions, and changes can affect protection. Notify us promptly of suspected unauthorized access; do not email passwords, full payment details, or live API secrets.
We and our providers may process information in the United States and other countries where services operate. Do not assume a specific data residency, certification, transfer mechanism, or regulated-data arrangement unless it is expressly covered by the applicable agreement. Where legally required, appropriate processing and transfer arrangements must be in place before that use.
10. HIPAA and protected health information
AttackDesk is not HIPAA compliant out of the box. The standard service is not approved for protected health information (PHI) governed by the Health Insurance Portability and Accountability Act (HIPAA). Do not send PHI through account forms, support requests, databases, files, calls, recordings, messages, or AI tools under a standard plan.
If your use requires HIPAA support, contact support@attackdesk.com before providing PHI. A separate review, an executed Business Associate Agreement (BAA), and written confirmation of the approved services, configuration, and safeguards are required before that use begins. We may decline a request or limit its scope; requesting or paying for an add-on does not make a service eligible. Describe your requirements without including patient information.
Any approved arrangement applies only to its specified services and providers. Other integrations, AI models, analytics, custom code, and deployments are not automatically covered. Running a copy locally or signing a BAA does not, by itself, establish HIPAA compliance. Each party remains responsible for its applicable legal duties and agreed safeguards; nothing in this policy waives obligations imposed by law.
11. Privacy rights and requests
Depending on the law that applies, you may have rights to access, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; or opt out of certain uses. You may also have a right to appeal a denied request or complain to your local privacy authority. We do not discriminate for exercising a protected privacy right.
Write to support@attackdesk.com with your request and the account or organization involved. We may verify identity and an authorized agent’s authority, using information proportionate to the request. Do not send identity documents unless requested through an appropriate channel. We respond within the period required by applicable law and explain any lawful limitation.
For California residents, the categories described above include identifiers, commercial and payment records, internet activity, professional information, and content that may include audio or sensitive information supplied by a customer. The collection sources, purposes, recipients, and retention criteria are described in this policy. CCPA rights and obligations apply where its requirements are met; this notice does not claim that every visitor or customer is subject to the same law.
12. Children and updates
AttackDesk accounts are intended for adults using business software, not for children under 18. Do not knowingly provide children’s personal information through a use we have not agreed to support. Contact us if you believe a child has provided information inappropriately.
We may update this policy to reflect the service and applicable obligations. The version date identifies the text in use. We provide additional notice or obtain consent when required for a material change; a policy update alone does not authorize a retroactive new use where consent is required.
Questions? support@attackdesk.com