Privacy notice
Written to be read, not to impress. This notice describes what the app actually does with your data - every service that touches it, named - and nothing more.
Last updated: 22 July 2026
Who runs this
ButlerDesk is operated by Nick Rogerson, a sole operator based in Manchester in the United Kingdom. Contact us through the contact form.
What we receive
- Your sign-in details: your email address, and either a password - stored by Supabase only in hashed form, so the password itself is never visible to anyone - or, if you sign in with Google, the email address Google confirms for you.
- What you enter in the app: client names and engagement terms, the meeting notes you paste, transcript files, meeting recordings you upload for transcription, CSV files you choose to import, and your time entries. You choose what goes in; redacted or placeholder details work fine and are encouraged.
- Contact-form messages if you write to us from the site.
- Sign-up location details: your public IP address and the approximate country and city Vercel derives from it. These are associated with your account and included in an operator alert for service monitoring and abuse detection; the location is not used for advertising or profiling.
Basic, cookie-consent-gated analytics run on the public marketing pages only. No analytics touch the contents of your client records, notes, or transcripts.
Where it is stored and what processes it
Your material is shared only with the service providers needed to run ButlerDesk, each doing one job:
- Supabase (database and file storage, hosted in AWS us-east-1, USA). Holds your account, sign-up IP and approximate location, client records, meeting recaps, drafts, time entries, and uploaded transcript files and recordings. Everything is encrypted at rest, access-controlled row by row to your sign-in, and never publicly accessible. Uploaded files live in a private folder only your account can read.
- Vercel (hosting, USA). Runs the website and app.
- OpenAI (meeting processing). When you submit a meeting, the notes or transcript are sent through the OpenAI API to produce the recap, next actions, follow-up draft, and suggested time entry. OpenAI states that data submitted through its API is not used to train its models by default and may be retained for up to 30 days for service operation and abuse monitoring.
- OpenAI (recording transcription). When you upload a meeting recording, the file is sent through the OpenAI API to create a transcript with speaker labels. The resulting transcript is stored on your meeting record so you can edit it. OpenAI states that audio-transcription API data is not used to train its models and lists no abuse-monitoring or application-state retention for this endpoint.
- OpenAI (AI-assisted CSV interpretation). Your CSV stays in your browser when the standard parser can read it. Only when that parser finds no usable rows is the file sent through the OpenAI API for interpretation. The request disables response storage, and the inferred entries come back as a preview; the original file is not stored by ButlerDesk. OpenAI states that API data is not used to train its models by default and may be retained for up to 30 days for service operation and abuse monitoring.
- Google (optional sign-in).If you choose "Sign in with Google", Google confirms your identity and shares your email address with us. Nothing else about your Google account is accessed, and none of your client material touches Google.
- Amazon SES (email delivery). Sends account emails - email confirmation and password-reset links - contact-form correspondence, and operator sign-up alerts containing the sign-up IP and approximate location. Emails never contain your uploaded files.
- Stripe (payments). If you subscribe, your card details go to Stripe directly and are never seen or stored here. We hold only your subscription status.
Your material is not posted, resold, used for advertising, or used to train AI models. Follow-up email drafts are exactly that - drafts. Nothing is ever sent to your clients by ButlerDesk, automatically or otherwise.
How long it is kept
- While your account is active, your records stay until you delete them or your account. Your sign-up IP and approximate location stay until the account is deleted.
- There is no automatic deletion. Your records are kept for as long as you keep your account, so they are there when you come back - subscribed or not. When you want them gone, you delete them yourself, immediately, from Settings (see below). Export first if you want a copy.
- Ordinary email correspondence is retained as email normally is; you can ask for that to be deleted too.
Export and deletion - self-serve
- Export:Settings → "Download everything" gives you one JSON file with all your clients, engagements, meetings (including recaps and drafts), and time entries. Any time, no questions.
- Deletion:Settings → "Delete account" removes your account, every database row, and every uploaded file - immediately and permanently. Nothing else is required, though the contact form reaches us too, and any request is actioned promptly and confirmed.
- You can run ButlerDesk entirely on synthetic or redacted data.
What this notice is not
No claim is made here to enterprise security certifications or audited compliance programmes - ButlerDesk is a small, independent product, and pretending otherwise would be dishonest. That is exactly why it is built so you control what goes in, can see everything it holds, and can remove all of it yourself in one click.