DESKEN

What Desken does with data

The short answer: Desken is a program that runs on your own machine. We operate no server, your texts and sources never pass through us, and you create no account with us. Below are the exceptions that do exist — there are a few, and they should be readable without hunting.

Stays on your machine

Sent to the AI providers — the ones you choose

When you run an AI node, the prompt and the material connected to that node are sent straight from your machine to the provider that node uses, with your own key. It does not go through us. Which providers may receive anything is up to you under Settings → Data protection; in 🛡 Offline mode nothing is sent to a cloud AI provider; only local models run. What the provider then does with the material is governed by their terms — which is precisely why the choice is yours and not ours.

Your voice — only when you press the microphone

In Ask about the canvas you can speak instead of typing. The microphone is only on from the moment you press 🎙 until you pause or press it again. The recording is sent with your own key directly from your machine to Groq or OpenAI (Whisper) to be turned into text, and it is not stored — neither on your machine nor by us. The answer is read aloud in a natural voice: if you have an ElevenLabs key, the text of the answer is sent to ElevenLabs, otherwise to OpenAI, solely to be turned into speech. Without either, or in 🛡 Offline, your computer's own voice reads it and the text never leaves the machine. In Offline the microphone is switched off.

Ask about the canvas — the structure, and the node you ask about

The chat sends the structure of the canvas and the names of the nodes to the model you have chosen. The content of a node — a draft, a fact-check, a source — is sent only when you ask about that particular node, at most two at a time, and the chat shows which ones it read. It passes through the same guard as the nodes' own calls, so Offline and your approved providers apply here too. The conversation is not saved.

Sent to the MCP servers you connect yourself

The MCP connector node fetches material from an MCP server (Model Context Protocol) whose address you enter on the node yourself. What is sent to the server is what is on the node: the name of the tool or resource you have chosen, the arguments you have written and the headers you have added — for instance an access key for the server. Nothing from the rest of the project is sent: no sources, no drafts and no text from other nodes — with one exception that you choose yourself: if you write {{input}} in the arguments, it is replaced with the text from the nodes connected into the MCP node (for example search terms from an AI node), and that text is sent to the server. Without {{input}}, that does not happen. The request goes straight from your machine to the server, not through us.

Like URL and API import, the MCP node counts as bringing data in, so it is not affected by the data protection mode — it also runs in 🛡 Offline if the machine is online. Who runs the server, and what they do with what is sent, depends on the server you choose. A tool call can also make the server do something, depending on the tool, and that happens again on every run. If the address is unencrypted (http://), Desken asks first.

If you choose Sign in (OAuth) instead of headers, Desken also contacts the server’s sign-in service: it fetches the server’s sign-in addresses, registers Desken as a client (the name “Desken” and a return address on your own machine) and opens the server’s own sign-in page in your browser. Your password is typed there and is never seen by Desken. The access key you get back is stored encrypted on your machine and is only sent to the server it belongs to — not to us, and not in the project file. You can sign out on the node, and it is deleted.

Sent to Scite when you use Research search

The Research search node finds scientific articles in Scite. Only the search itself is sent to Scite — a short search string in English, the number of articles and possibly a year. Your text, your sources and your drafts are not sent to Scite. Desken uses your own Scite account: you sign in on Scite’s own page in your browser, your password is never seen by Desken, and the access is stored encrypted on your machine and not in the project file. Scite’s own terms and privacy policy apply to your use of Scite.

If you let Desken write the search from the connected text, the flow’s language model reads the text to write the search string — on the same terms as any other AI node. If you write the search yourself, no text is read. The node is blocked in 🛡 Offline, and in 🔐 Scite must be approved under Data protection. The reply from Scite (titles, abstracts and excerpts) is treated as untrusted text when it is passed on to AI nodes.

Sent to the publisher

Never sent

Your sources, your drafts, your finished texts, your fact-checks and your API keys. They do not pass through us in normal use, and they are not included in crash reports — with the one caveat about minidumps above.

This page is a technical description of what the program actually does — written to be usable by an IT department assessing Desken. It is not a legal data processing agreement; one will be drawn up before sales open. Questions: hej@grumpyproductions.dk.