Last updated: 14 August 2026
GrelDesk works entirely on your device and needs no account. Your workspace — panels, layouts, notes, themes and settings — is stored in your browser and is never sent to us unless you turn on a feature that requires it. This policy explains exactly which features do that, and what they send.
GrelDesk is produced by Grinning Elephant, LLC ("we", "us"). If you have a question about this policy or your data, contact us at privacy@grel.ai.
By default, everything. The following never leaves your browser and we have no copy of it:
This is stored using your browser's IndexedDB and local storage. Uninstalling the extension or clearing site data removes it.
If you enable it, your settings and theme choice are synchronised across your
own devices using Chrome's built-in storage.sync. That data travels
through your own Google account, not through us, and we cannot read it.
An account exists to give you a backup you can restore. Creating one stores:
| Data | Why | Kept for |
|---|---|---|
| Email address | Sign-in and account recovery | Until you delete the account |
| Password (hashed with scrypt — never the password itself) | Sign-in | Until you delete the account |
| Sign-in session | Keeping you signed in | Until it expires or you sign out |
If you register but never confirm your email address, the unconfirmed address and the abandoned account are deleted automatically.
With an account, GrelDesk can upload a copy of your workspace so you can restore it later. The backup is the same data described in section 2, uploaded as a file to Microsoft Azure Blob Storage and stored privately — public access to the storage container is disabled, and each download requires a short-lived signed link issued to you.
We keep a limited number of recent backups, and how many depends on your plan. Older ones are deleted automatically as new ones are taken.
If you choose this, we receive your account identifier and email address from the provider. If you also grant access to Calendar or Tasks so the matching widgets can work, we store the resulting access tokens encrypted (AES-256-GCM) and use them only to fetch the data those widgets display. You can disconnect at any time, which deletes the stored tokens.
Premium subscriptions are handled by Stripe. Stripe processes your card details — we never see or store them. We keep a Stripe customer reference and your subscription status so we know whether your account is premium.
So we can tell roughly how much GrelDesk is being used, the app records one record per browser profile per day. It contains a random identifier the app generates for that browser profile, which browser it is, the times you opened it that day, and the IP address the request came from. If you are signed in, the record is linked to your account; if you are not, it is anonymous.
This is deliberately coarse. It is not per-click analytics, it does not record what you do inside the app, and there is no advertising or third-party tracking in GrelDesk. The IP address is the one your connection presents to our server — we do not use any third-party service to look it up.
If you delete your account, usage records are unlinked from you but the anonymous row remains.
Some features fetch data from third parties when you use them. These requests are made by your browser and are limited to a per-widget allowlist:
| Service | When | What it sees |
|---|---|---|
| Google favicon service | Showing launcher icons | The site addresses of your launchers |
| wttr.in | Weather widget | The location you set |
| Google Maps | Maps widget | Standard Google Maps embed data |
Some plugins call services using credentials you supply (for example an API key you enter). Those requests go directly from your browser to that service and do not pass through us.
Depending on where you live you may have additional rights over your personal data, including access, correction and erasure. Contact us at the address above and we will act on it.
GrelDesk is not directed at children under 13, and we do not knowingly collect their data.
Account data is stored in a PostgreSQL database hosted in the United States (aws-us-east-1) and backups in Microsoft Azure Blob Storage. If you use GrelDesk from outside the United States, your data is transferred there.
If we change how data is handled we will update this page and change the date at the top. If the change is significant we will say so in the app.