CaseDesk
  • How it works
  • Pricing
  • Enterprise
Sign in Get started
Home / Privacy Policy

Privacy Policy

Last updated: July 2026

1. What CaseDesk is

CaseDesk is a private AI control plane. Your organisation connects a Kubernetes cluster, GPU VM, or approved provider account that it controls. CaseDesk supplies compatible APIs, policy controls, and operational evidence; your organisation selects the runtime region and retains responsibility for the provider account.

2. Information we collect

  • Account: email address and hashed password.
  • Payment: billing details are processed and stored by Stripe. CaseDesk stores only the payment references and prepaid-credit records needed to operate the service; we never see or store your card number.
  • API usage: request count, token counts, model identifiers, and timestamps. Used for billing, rate limiting, and capacity planning. No prompt or response content is logged.
  • Deployment metadata: cluster region, model name, deployment status, and endpoint identifiers.
  • Web server logs: IP address, timestamp, HTTP method and path. Retained for 30 days.

3. Prompt and inference data

CaseDesk does not log, store, or inspect the content of your API requests or model responses. Inference runs at the connected provider or customer-controlled endpoint.

4. How we use your information

  • Authenticate you and operate your account.
  • Operate your CaseDesk account, connections, and platform controls.
  • Calculate CaseDesk platform charges and prepaid credit usage.
  • Send transactional emails (deployment status, billing receipts).

We do not sell your data, use it for advertising, or share it with third parties except as required by law or to operate the service (Stripe for payments).

5. Data residency and GDPR

Your inference workload runs in the provider account and region your organisation selects. For NHS and regulated healthcare deployments, Enterprise engagements include an architecture review to map the connected deployment to the organisation's data-handling requirements.

6. Data retention and deletion

You can delete your account at any time from your account settings. On deletion, your deployment is terminated, usage records are anonymised within 30 days, and your account data is permanently removed. Stripe retains billing records in accordance with their own retention policy.

7. Security

All connections are served over HTTPS with HSTS enforced. API keys are hashed before storage. Your organisation controls workload isolation and encryption at rest in its provider environment; CaseDesk documents the required connection and access controls during onboarding.

8. Cookies

CaseDesk uses a single session cookie to keep you signed in. We do not use tracking cookies, advertising cookies, or third-party analytics.

9. Contact

Questions about this policy or data subject requests: privacy@getcasedesk.com

CaseDesk

Private AI control plane for software teams. Customer-controlled runtime and regional governance.

Platform
Find My Platform Dedicated Hardware Pricing Developer Sandbox Sign in
Use Cases
Code assistance Document processing Data analysis Internal Q&A NHS and healthcare Third-party tools
Company
About us Why CaseDesk Enterprise sales Contact Privacy policy Terms of service
© 2026 CaseDesk. All rights reserved.
Privacy Terms LinkedIn GitHub