Privacy Policy

Last updated: 14 August 2026

GrelDesk works entirely on your device and needs no account. Your workspace — panels, layouts, notes, themes and settings — is stored in your browser and is never sent to us unless you turn on a feature that requires it. This policy explains exactly which features do that, and what they send.

1. Who we are

GrelDesk is produced by Grinning Elephant, LLC ("we", "us"). If you have a question about this policy or your data, contact us at privacy@grel.ai.

2. What stays on your device

By default, everything. The following never leaves your browser and we have no copy of it:

This is stored using your browser's IndexedDB and local storage. Uninstalling the extension or clearing site data removes it.

3. Chrome sync (optional)

If you enable it, your settings and theme choice are synchronised across your own devices using Chrome's built-in storage.sync. That data travels through your own Google account, not through us, and we cannot read it.

4. If you create an account (optional)

An account exists to give you a backup you can restore. Creating one stores:

DataWhyKept for
Email addressSign-in and account recoveryUntil you delete the account
Password (hashed with scrypt — never the password itself)Sign-inUntil you delete the account
Sign-in sessionKeeping you signed inUntil it expires or you sign out

If you register but never confirm your email address, the unconfirmed address and the abandoned account are deleted automatically.

Workspace backups

With an account, GrelDesk can upload a copy of your workspace so you can restore it later. The backup is the same data described in section 2, uploaded as a file to Microsoft Azure Blob Storage and stored privately — public access to the storage container is disabled, and each download requires a short-lived signed link issued to you.

We keep a limited number of recent backups, and how many depends on your plan. Older ones are deleted automatically as new ones are taken.

Signing in with Google or Microsoft

If you choose this, we receive your account identifier and email address from the provider. If you also grant access to Calendar or Tasks so the matching widgets can work, we store the resulting access tokens encrypted (AES-256-GCM) and use them only to fetch the data those widgets display. You can disconnect at any time, which deletes the stored tokens.

Payments

Premium subscriptions are handled by Stripe. Stripe processes your card details — we never see or store them. We keep a Stripe customer reference and your subscription status so we know whether your account is premium.

5. Usage measurement

So we can tell roughly how much GrelDesk is being used, the app records one record per browser profile per day. It contains a random identifier the app generates for that browser profile, which browser it is, the times you opened it that day, and the IP address the request came from. If you are signed in, the record is linked to your account; if you are not, it is anonymous.

This is deliberately coarse. It is not per-click analytics, it does not record what you do inside the app, and there is no advertising or third-party tracking in GrelDesk. The IP address is the one your connection presents to our server — we do not use any third-party service to look it up.

If you delete your account, usage records are unlinked from you but the anonymous row remains.

6. Other network requests

Some features fetch data from third parties when you use them. These requests are made by your browser and are limited to a per-widget allowlist:

ServiceWhenWhat it sees
Google favicon serviceShowing launcher iconsThe site addresses of your launchers
wttr.inWeather widgetThe location you set
Google MapsMaps widgetStandard Google Maps embed data

Some plugins call services using credentials you supply (for example an API key you enter). Those requests go directly from your browser to that service and do not pass through us.

7. What we never do

8. Your choices and rights

Depending on where you live you may have additional rights over your personal data, including access, correction and erasure. Contact us at the address above and we will act on it.

9. Children

GrelDesk is not directed at children under 13, and we do not knowingly collect their data.

10. Where data is stored

Account data is stored in a PostgreSQL database hosted in the United States (aws-us-east-1) and backups in Microsoft Azure Blob Storage. If you use GrelDesk from outside the United States, your data is transferred there.

11. Changes to this policy

If we change how data is handled we will update this page and change the date at the top. If the change is significant we will say so in the app.