Last updated: July 2026
CaseDesk is a private AI control plane. Your organisation connects a Kubernetes cluster, GPU VM, or approved provider account that it controls. CaseDesk supplies compatible APIs, policy controls, and operational evidence; your organisation selects the runtime region and retains responsibility for the provider account.
CaseDesk does not log, store, or inspect the content of your API requests or model responses. Inference runs at the connected provider or customer-controlled endpoint.
We do not sell your data, use it for advertising, or share it with third parties except as required by law or to operate the service (Stripe for payments).
Your inference workload runs in the provider account and region your organisation selects. For NHS and regulated healthcare deployments, Enterprise engagements include an architecture review to map the connected deployment to the organisation's data-handling requirements.
You can delete your account at any time from your account settings. On deletion, your deployment is terminated, usage records are anonymised within 30 days, and your account data is permanently removed. Stripe retains billing records in accordance with their own retention policy.
All connections are served over HTTPS with HSTS enforced. API keys are hashed before storage. Your organisation controls workload isolation and encryption at rest in its provider environment; CaseDesk documents the required connection and access controls during onboarding.
CaseDesk uses a single session cookie to keep you signed in. We do not use tracking cookies, advertising cookies, or third-party analytics.
Questions about this policy or data subject requests: privacy@getcasedesk.com