RunDesk is a trade name of A. I. Tech Inc., a corporation registered in Ontario, Canada, located in Thorndale, Ontario. In this policy, “we,” “us,” and “our” refer to A. I. Tech Inc. operating as RunDesk.
This policy explains what personal information we collect, how we use it, how it is stored and protected, and your rights regarding your data.
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy law.
Privacy Officer
Our Privacy Officer is responsible for our compliance with this policy and with PIPEDA. You may contact our Privacy Officer at:
Compliance Officer, A. I. Tech Inc.
Email: compliance@rundesk.co
Location: Thorndale, Ontario, Canada
What We Collect and Why
When you visit our website
What: Basic analytics data including pages visited, browser type, and approximate location (country/region).
Purpose: To understand how visitors use our website and improve its functionality.
Legal basis: Implied consent for non-sensitive, non-identifying analytics data.
We do not use this data to identify you personally. We use privacy-respecting analytics that do not track you across other websites.
When you submit the intake form
What: Your name, email address, phone number, company name, industry, team size, assistant preferences, and any additional context you share about your business.
Purpose: To configure your AI employee and determine the appropriate service plan for your needs.
Legal basis: Express consent provided by submitting the form.
When you become a client
What: Payment information processed through our payment processor, including billing address and payment method.
Purpose: To process subscription payments and top-up purchases.
Legal basis: Contractual necessity for providing the service.
We do not store your credit card number, bank account details, or other payment credentials on our servers. Our payment processor handles all payment processing in compliance with PCI-DSS standards.
When you connect your Google account
What: OAuth authorization tokens granting your AI employee access to specific Google Workspace services.
Purpose: To enable your AI employee to manage your email, calendar, and files on your behalf.
Legal basis: Express consent provided during the onboarding process.
During onboarding, you may authorize your AI employee to access your Google account. We request the minimum set of permissions needed, and no others. The complete list is:
- Sign-in and basic profile (
openid,userinfo.email,userinfo.profile): your name, email address, and profile picture, used to identify the account you connected - Google Calendar (
calendar): view, create, and modify calendar events and check availability - Gmail — send only (
gmail.send): send a message on your behalf, and only after you have seen the draft and explicitly approved it. This permission does not allow reading, searching, or listing your mail. - Google Drive — app files only (
drive.file): access only the files your AI employee itself creates, in a dedicated folder. This permission does not give access to your existing Drive contents.
Your AI employee does not read your Gmail through Google's API. We do not request any Gmail read permission — not gmail.readonly, not gmail.modify, and not full Gmail access. If you want your assistant to see incoming mail, that happens through optional forwarding, described in the next section, and it is entirely under your control.
We also do not request access to Google Docs, Google Sheets, Google Contacts, or your Drive as a whole. Your AI employee will never delete calendar events or files it created without listing exactly what will be removed and obtaining your explicit confirmation, and will never send an email without showing you the draft and receiving your approval.
You authorize access directly through Google's OAuth system. We do not see or store your Google password. You can revoke access at any time through your Google account settings at myaccount.google.com/permissions.
Incoming email (forwarded copies)
What: Copies of incoming messages you choose to forward to a RunDesk-operated address.
Purpose: To let your AI employee see incoming mail without holding a Gmail read permission.
Legal basis: Express consent — you set this up yourself and control it.
Because we deliberately do not request a Gmail read permission, your AI employee has no way to read your inbox through Google. If you want it to see incoming mail, you may optionally set up forwarding in your own email settings so that a copy of incoming messages is sent to a RunDesk-operated address in the form <client>@rundesk.co. That is a forwarding mailbox we operate through an email-infrastructure provider. Your AI employee reads those forwarded copies.
The original message always remains in your own inbox — forwarding sends a copy and changes nothing about your mail. You set this up, you control it, and you can turn it off at any time from your email provider's settings, which stops new copies immediately.
Retention: forwarded copies are retained for up to 30 days and then automatically deleted by a daily job. The forwarding mailbox itself is deleted when you disable forwarding or close your account.
When you connect your Microsoft 365 account
What: Delegated Microsoft Graph permissions granting your AI employee access to your Microsoft 365 account.
Purpose: To enable your AI employee to work with your email and calendar on your behalf.
Legal basis: Express consent provided during the onboarding process.
If you use Outlook or Microsoft 365, you may authorize your AI employee through Microsoft Graph. The permissions we use are:
- Mail: read your messages, and — only where you have asked us to enable it — draft and send messages, which always requires your explicit approval first
- Calendar: view, create, and modify calendar events and check availability
- Sign-in (
User.Read): your name and email address, used to identify the account you connected
Access is read-only by default. The ability to send or draft is enabled for a client only on request. Unlike Google, Microsoft Graph is how your assistant reads incoming mail on this provider, so mail forwarding is not required.
You authorize access directly through Microsoft's consent system. We do not see or store your Microsoft password. You can revoke access at any time from your Microsoft account at myapps.microsoft.com.
When you connect another email provider (IMAP / SMTP)
What: An app-specific password for a mailbox that is not Gmail or Microsoft 365.
Purpose: To let your AI employee read, and where supported send, mail on that account.
Legal basis: Express consent provided during the onboarding process.
For mailboxes hosted elsewhere — Zoho, Fastmail, a hosting provider, and similar — there is no OAuth system to authorize against. In that case you provide an app-specific password generated by your provider, which lets your AI employee connect directly over IMAP to read mail and, where your provider supports SMTP, send mail with your explicit approval.
We ask for an app-specific password rather than your account password so the credential is scoped to mail access alone and can be revoked on its own. Credentials are stored encrypted. You can revoke access at any time by deleting that app password in your provider's settings, which takes effect immediately and does not affect your main account password.
Other services you connect
Depending on the accounts and services you connect, your assistant may access your email, calendar, files, and CRM or contact records to perform the tasks you request. You choose which services to connect and can disconnect any of them at any time. Your use of any connected third-party service remains governed by that provider's own terms and privacy policy.
When you use your AI employee
What: Your conversations with your AI assistant, including messages, requests, and any content you share.
Purpose: To provide the AI employee service, including responding to your requests, maintaining conversation memory, and executing tasks on your behalf.
Legal basis: Contractual necessity and express consent.
Your conversation data is stored on your dedicated, isolated server. Your conversation data is not shared with other clients, used for marketing, or sold to third parties.
Your chosen messaging channel
What: The messages you exchange with your AI employee, as they pass through the messaging platform you selected.
Purpose: To deliver your messages to your AI employee and its replies back to you.
Legal basis: Contractual necessity — you choose the channel during onboarding.
You talk to your AI employee through a messaging channel you choose: Telegram, WhatsApp, Slack, or Discord. Your messages travel over that platform and are processed by its operator under that operator's own privacy policy and terms, not ours. We receive and store the conversation on your dedicated server as described above, but we do not control how the messaging platform itself handles your data in transit. If this matters to you, review the privacy policy of the channel you pick — they are linked in the subprocessor table below — and choose accordingly.
WhatsApp specifically: if you choose WhatsApp, you may opt to have your AI employee connect as a linked device on your own WhatsApp account, in the same way WhatsApp Web does. In that configuration the assistant operates through your account rather than a separate business number, and it is configured to respond only to you, the account owner. This is your choice and you can unlink the device at any time from WhatsApp's “Linked devices” screen.
Voice messages
What: The audio of any voice message you send your AI employee.
Purpose: To convert your speech to text so your AI employee can act on it.
Legal basis: Express consent — this applies only if you send voice messages.
If you send a voice message rather than typing, the audio is sent to our subprocessor Groq for speech-to-text transcription, and the resulting text is handled the same way a typed message would be. If you never send voice messages, no audio ever leaves your instance.
Consent for AI Processing
By subscribing to RunDesk, you expressly consent to the processing of your messages, emails, calendar data, files, and other content by third-party AI model providers for the purpose of powering your AI employee's responses and actions.
You may withdraw this consent at any time by cancelling your subscription. Withdrawal of consent may require termination of the service, as AI processing is essential to the functioning of your AI employee.
How Your Data Is Processed by AI Providers
Your AI employee uses large language models from third-party providers to process your requests. When you send a message to your assistant or when your assistant accesses your email, calendar, or files, the relevant content is sent to one of these providers for processing.
Current AI model providers include:
- Anthropic (Claude) — anthropic.com/privacy
- OpenAI (GPT) — openai.com/privacy
- Google (Gemini) — ai.google.dev/terms
We select providers that offer enterprise-grade data processing agreements, that process data solely for the purpose of generating responses, and that do not use your data to train their models through API access. We may change providers or add additional providers from time to time. Material changes to our provider list will be communicated to active clients via email.
Limited Use of Google and Microsoft Data
RunDesk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through these permissions is:
- used only to provide and improve the user-facing features you have asked your AI employee to perform
- never used for advertising of any kind
- never sold or transferred to third parties, except as required to provide the service, or as required by law
- never used to train generalized AI or machine learning models
- never read by humans, except with your explicit consent, to resolve a specific support issue you have raised, or as required by law
We make the same commitment for data obtained through Microsoft Graph and for mail accessed over IMAP. We request the least access needed for the features you have asked for, each connected account is authorized and revoked separately, and sending a message always requires your explicit approval.
Cross-Border Data Transfers
Your data may be transferred to and processed in the United States by our AI model providers, messaging platforms, and backup storage, and by our hosting provider where your instance is located there. By using the RunDesk service, you consent to this transfer. We ensure that all providers maintain privacy protections consistent with Canadian privacy law through their data processing agreements and privacy policies.
The server hosting your AI employee is located in North America — either the United States or Canada, depending on which host your instance was provisioned on. Intake form submissions are stored in a database hosted in North America with encryption at rest. Encrypted backups are held by a cloud storage provider.
How We Store and Protect Your Data
Each client's AI employee runs on dedicated, isolated infrastructure. Your data is completely separated from every other client's data. All connections to your AI employee are encrypted using WireGuard tunnels. There are no open ports exposed to the public internet.
Your AI employee and its data run on managed virtual private servers we operate through third-party hosting providers in North America, not on our website hosting. Your instance, its configuration, its conversation history, and its stored credentials all live there, on infrastructure dedicated to your account.
Intake form submissions are stored with encryption at rest. OAuth tokens are stored locally within your isolated container with restricted file permissions. Encrypted backups of your configuration and data are held by a cloud storage provider.
What Our Team Can See
Our operations team monitors the technical health of your AI employee. This includes metrics such as uptime, error counts, resource usage, and message volume (for example, “47 messages processed today”). Our team does not read the content of your conversations with your assistant or access your email, calendar, files, or other connected accounts.
Your assistant's configuration
Your AI employee is configured by our team using the information you provide at intake — its role, personality, working style, and standing instructions. These configuration files are written and maintained by us, and they are separate from your conversations and connected accounts. As part of the managed service, we review and update them so your assistant keeps improving after launch.
We may apply what we learn about technique across the accounts we manage — how instructions are best structured, which reminder patterns work, how a briefing is best formatted. We do not copy your business information, your clients' details, or any content from your account into another client's configuration, and we do not read your conversations in order to do this.
How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Active client data (conversations, files, memory) | For the duration of your subscription |
| Data after cancellation | Deleted within 30 days |
| Encrypted backups after cancellation | Deleted within 30 days |
| Intake form submissions (non-clients) | Deleted after 90 days |
| Payment and billing records | 7 years (as required by Canadian tax law) |
| Operational logs (no personal information) | 90 days |
If you request a copy of your conversation history before cancellation, we will provide it in a standard format.
Data Breach Notification
In the event of a breach of security safeguards that creates a real risk of significant harm to you, we will:
- Notify you as soon as feasible to allow you to take steps to mitigate potential harm
- Report to the Office of the Privacy Commissioner of Canada as required by PIPEDA
- Notify any other organizations that may be able to reduce the risk of harm
- Take immediate steps to contain the breach, investigate its cause, and prevent recurrence
We maintain records of all data breaches for a minimum of 24 months, regardless of whether they trigger notification, as required by PIPEDA.
Your Rights
Under PIPEDA and applicable Canadian privacy law, you have the right to:
- Access the personal information we hold about you
- Correct any inaccurate personal information
- Request deletion of your personal information (subject to legal retention requirements)
- Withdraw consent for data processing (which may require cancellation of the service)
- Request a copy of your data in a portable format
- Challenge our compliance with this policy
To exercise any of these rights, contact our Privacy Officer at compliance@rundesk.co. We will respond to your request within 30 days.
If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Cookies
Our website uses minimal cookies necessary for the website to function. We do not use advertising cookies or tracking pixels. We do not sell your data to advertisers.
Subprocessors
We use third-party providers to deliver the service. Which of them apply to you depends on the services, messaging channel, and email providers you configure — no client uses all of them. By category:
- AI / LLM providers — process your requests and generate your assistant's responses
- Cloud hosting and storage providers — run your assistant instance and hold encrypted backups
- Email-infrastructure providers — operate the forwarding mailbox and deliver our notification email
- Messaging-platform providers — carry your conversations, based on the channel you use
- A payment processor — handles subscription billing
Two providers are named here because you authorize them directly and their permissions are documented above: Google and Microsoft, where you connect a Google or Microsoft 365 account.
The specific named list of our subprocessors is available to clients on request and in our Data Processing Agreement. We notify active clients of material changes to that list.
Children
RunDesk is a business service and is not intended for use by individuals under the age of 18.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to active clients via email at least 30 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
Contact
For privacy-related questions, requests, or complaints:
Compliance Officer, A. I. Tech Inc.
Email: compliance@rundesk.co
Location: Thorndale, Ontario, Canada