Privacy Policy

Last updated: June 2026

This policy covers both the CoolDesk browser extension and the CoolDesk Windows desktop app. Everything runs locally and no sign-up or account is required. Data only leaves your device in three opt-in or opt-out cases: an anonymous usage ping, optional cloud AI using your own key, and Team Sharing when you choose to share with others. Website traffic is covered separately under Website Analytics.

Overview

CoolDesk helps you organise browser tabs, desktop apps, links, and notes by project — all in one place. This policy explains what data we access, how it stays on your device, and your rights as a user.

Core principle: your browsing data stays on your device by default, and CoolDesk does not operate servers that store your personal data. Anything only leaves your device in three cases you control: the opt-out anonymous usage ping, the optional cloud AI mode you turn on with your own key, and Team Sharing when you choose to share a Space with others — all described below.

Information We Collect

CoolDesk stores data locally on your device using Chrome's built-in storage. This includes:

  • Browsing history — limited to 30 days, max 1,000 items, used for Spotlight search
  • Bookmarks — for workspace organisation
  • Open tabs — to enable quick access and workspace grouping
  • Notes — text you explicitly save within the extension
  • Workspace configurations — project names, saved URLs, and preferences
  • Page engagement signals — for pages you visit, the extension measures simple interaction metrics: time on page, scroll depth, and the number of clicks, key-presses, and form submissions, plus how often you return to a site. These are counts and event types only — it does not record the text you type, your form values, keystrokes, or page content. Used to rank and auto-categorise URLs so Spotlight and workspaces surface the sites that matter to you.

All of this is stored on your device (Chrome storage and, if you use the desktop app, mirrored to it locally on the same machine). None of it is transmitted to CoolDesk's servers or any third party.

How We Use Your Data

Locally stored data powers these features:

  • GlobalSpotlight (Alt+K) — searches your tabs, history, bookmarks, notes, and workspaces instantly
  • Workspaces — groups your saved URLs and apps by project
  • Smart Tab Management — auto-groups open tabs by domain or project
  • Smart ranking & categorisation — uses the on-page engagement signals above to rank your most-used sites and auto-categorise URLs, so the most relevant results appear first
  • Notes — quick capture on new tab, including voice dictation stored locally
  • AI SmartWorkspace — suggests project groupings from your activity. It runs on a local AI model by default; an optional cloud mode uses an API key you provide (see AI Features)

All processing happens on your device.

Chrome Permissions

CoolDesk requests the following Chrome permissions and uses them only as described:

  • tabs — read open tabs for workspace grouping and Spotlight search
  • history — read recent browsing history (30 days) for search suggestions
  • bookmarks — read bookmarks for workspace organisation
  • storage — save your workspaces, notes, and preferences locally
  • newtab override — replace the new tab page with the CoolDesk dashboard
  • content scripts — a lightweight script runs on the web pages you visit to measure the on-page engagement signals described above (click/scroll/time counts). It reads interaction counts only — not page content, form values, or what you type — and never sends them off your device.

Aside from the engagement-measuring content script above, we do not request broad host permissions or use page access to read your page content. We request no permission beyond what is necessary for the described features.

Windows Desktop App

The optional CoolDesk Windows app (currently in beta) extends Spotlight search to include your running Windows applications (e.g. VS Code, Slack, Postman).

No account, sign-up, or login is required. The app runs entirely on your machine — your apps, windows, workspaces, and notes never leave your device.

  • The app reads the list of currently running processes and open windows (including window titles) from the Windows OS
  • It can derive the names and paths of project folders you currently have open — parsed from the window titles of code editors, terminals, and File Explorer (e.g. a VS Code or terminal path). It may check the folder on disk to resolve the project root, but it does not read your file contents or index your drive
  • This information is used to surface running apps and open folders in Spotlight, to focus the window you pick, and — only if you choose — to save an app or folder into a workspace, which is stored locally
  • App names, window titles, and folder paths are never sent to CoolDesk's servers. The one exception is if you enable cloud AI, in which case they may be sent to your chosen AI provider — see AI Features

The Windows app is not required. The browser extension works fully without it. By default the only data it sends off your device is the anonymous usage ping described below — and that can be turned off. Optional cloud AI is the only other case where data leaves your device, and only when you enable it.

AI Features (Bring Your Own Key)

CoolDesk's AI workspace suggestions can run in two modes, and you choose which:

  • Local AI (default, fully private) — a model running locally on your machine. Nothing leaves your device.
  • Cloud AI (optional, your own key) — you connect your own OpenAI or Anthropic API key. CoolDesk does not provide, resell, or proxy an AI service; requests go directly from your device to the provider you chose, billed to your own account.

When you use cloud AI:

  • The context needed for the suggestion — such as your workspace names, open tabs, recent history titles and URLs, running app and window titles, and open project folder names — is sent to your chosen provider to generate the response, and is then handled under that provider's privacy policy (OpenAI / Anthropic).
  • Your API key is stored locally and encrypted at rest (Windows DPAPI). It is never transmitted to CoolDesk.
  • Cloud AI is off until you add a key. CoolDesk never sends your AI context to its own servers in either mode.

Team Sharing & Spaces

CoolDesk includes an optional Spaces feature for sharing links, notes, saved items, and a shared "space context" (a goal, today's focus, and notices) with people you choose. It is off until you create or join a Space, and no account or sign-up is required.

A Space is opened with a shared secret phrase. That phrase is the key: on your device it is turned into a room ID and an encryption key — the phrase itself is never uploaded. Anyone who has the phrase can join the Space and read its contents, so treat it like a password and share it only with people you trust.

How the data moves:

  • Peer-to-peer & end-to-end encrypted. Space data syncs directly between members' devices over WebRTC and is encrypted with the key derived from your secret phrase.
  • Signaling server. A lightweight signaling server helps members discover and connect to each other. It sees only the Space's connection ID — never your decrypted content.
  • Relay servers. To connect across firewalls and networks, WebRTC may route traffic through third-party STUN/TURN relays (e.g. Google STUN and Open Relay). Because the data is end-to-end encrypted, these relays only ever carry ciphertext.
  • No central store. CoolDesk does not operate a server that stores your Space content — it lives only on members' devices.

What is shared inside a Space:

  • The items you add — links, notes, and saved data, including their titles, URLs, and tags
  • The shared space context — goal, today's focus, notices, and the alert flag
  • Your display name and colour, so members can see who's present. This is a name you set; no email or account is attached.

You stay in control: you can pause syncing for a Space at any time, and leaving a Space stops sharing your data with it. Only the data you put into a Space is shared — your personal tabs, history, and private workspaces are never shared unless you explicitly add them.

Anonymous Usage Analytics

To understand how many people use CoolDesk and which versions are active, the Windows app sends a once-daily anonymous heartbeat to our analytics endpoint. This same request doubles as the check for new app updates, so the app does not make a separate tracking call.

The heartbeat contains only these non-identifying fields:

  • Install ID — a random identifier generated on your device the first time the app runs (a UUID). It is not tied to your name, email, or any account, and is used only to avoid double-counting the same install.
  • Operating system — e.g. "windows"
  • App version — e.g. 1.4.0
  • Install source — how you installed the app (e.g. winget, GitHub)
  • Locale — your system language setting, e.g. "en-US"
  • Spotlight opens — a simple count of how many times you opened Spotlight that day

We explicitly do not collect or store:

  • Your IP address (it is never logged or stored)
  • Search queries, URLs, page contents, notes, or workspace data
  • The names of your apps, windows, files, or any free-text content
  • Any cross-site or advertising identifier

Opt out anytime: turn off usage analytics in the app's settings. With analytics disabled, the app skips the ping entirely and checks for updates directly from GitHub instead.

Website Analytics

The cool-desk.com website (not the extension) uses Google Analytics (GA4) to collect anonymous usage statistics such as page views and session duration. This helps us understand which content is useful.

  • Analytics apply only to the marketing website, not the extension or desktop app
  • No personally identifiable information is collected via analytics
  • You can opt out using the Google Analytics Opt-out Browser Add-on

Data Security

  • Extension data remains on your device — Chrome handles local storage encryption
  • No CoolDesk server receives your browsing, tab, or workspace data (the only off-device cases are the anonymous usage ping, optional cloud AI you enable with your own key, and Team Sharing — which is peer-to-peer and end-to-end encrypted, with no content stored on our servers)
  • Strict Content Security Policy prevents unauthorised network requests
  • The only script the extension runs on third-party pages is the engagement-measuring content script described under Chrome Permissions; it reads interaction counts, not page content, and sends nothing off your device

User Control & Rights

You have full control over your data:

  • View all stored data via Chrome DevTools → Application → Storage
  • Delete individual items or clear all data from within the extension settings
  • Uninstalling CoolDesk removes all locally stored data

Compliance

CoolDesk complies with the Chrome Web Store User Data Policy and the Limited Use Policy. We do not sell, share, or transfer user data to third parties.

If cloud sync or cross-device features are added in the future, this policy will be updated and users will be notified before any data leaves their device.

Contact & Questions

For privacy questions or data requests:

We aim to respond within 5 business days.

Summary

  • Everything runs locally — no account, sign-up, or login required
  • Your browsing, tabs, notes, workspaces, and apps stay on your device — never sent to our servers
  • No tracking, ads, or third-party data sharing
  • The desktop app sends only an anonymous daily usage ping (random ID, OS, version, locale, Spotlight count) — no IP, no content — and you can turn it off
  • AI is optional: it runs locally by default, or with your own OpenAI/Anthropic key — CoolDesk never stores your key or proxies your data
  • Team Sharing is optional and end-to-end encrypted: only data you put in a Space is shared, peer-to-peer with people who have your secret phrase — CoolDesk never stores your Space content
  • Chrome permissions used only for the features described above
  • Website uses Google Analytics (anonymous, opt-outable)
  • You can delete all data at any time by uninstalling

Your privacy is central to CoolDesk — productivity without compromise.