Trust & data handling — Project Desk by Atlier
Last updated: July 19, 2026
Project Desk is operated by Wilds, Inc. (Lexington, Massachusetts, USA) — a founder-run company; Justin Wilds is the sole operator. It is an early product. This page says exactly what Project Desk can access, what it stores, and who can see it.
What Project Desk can access and store
| Project Desk cannot access directly | Sent to and stored on our servers |
|---|---|
| Your repositories, source files, local environment, credential store, terminal, and git history | Your board: project names, "Shape" summaries, issue/ticket titles and bodies, queues, handoff notes, and sources |
| Files and local data that your connected AI does not send through a Project Desk tool | Ordinary project text the connected AI includes in a desk field, such as summaries, ticket descriptions, selected log excerpts, architecture details, or client-approved project details |
| Your sign-in-provider password | Your account basics, connector records, and desk membership, including an invited email before the recipient signs in |
The boundary: Project Desk stores ordinary project text its writing interfaces receive. It does not grant an agent local access or choose what repository access the agent's host provides. Project Desk rejects common recognizable forms of payment-card data, protected health information, government identifiers, and access credentials/authentication secrets; keep those values in the system designed to hold them and refer to that system by name instead.
Verified product guarantees
These are not aspirations — each is enforced by an automated check in our build, so a release that broke one could not ship. They are product guarantees, not a compliance certification.
- Your desk is isolated from every other customer's. Another customer's data — including who worked on what — cannot appear on your desk, even when two desks happen to use the same project or issue name.
_Checked by the tenant-isolation and cross-desk provenance suites._
- An agent you connect reads exactly what you can read, and no more. It is authenticated as you and scoped to your membership; it cannot reach desk state you could not see yourself, and it is refused the supervisory Team view unless you personally hold that permission.
_Checked by the membership-isolation suite and the connector's supervisory-surface refusal check._
- Team Desk is not a productivity scoreboard. It shows where work sits and who is accountable — never per-person rankings, throughput, utilization, activity scores, or time-spent. Our build fails if anyone adds one.
_Checked by the anti-scoreboard build gate (a person-shaped view may carry no numeric metric)._
- Working alone, your desk gets no team behavior at all. A solo desk is byte-for-byte what it was before team features existed.
_Checked by the solo-invariance golden._
- Removing someone's team access removes what they can supervise — never the record of the work they did. Their own participation history survives.
_Checked by the navigation and revocation suite (a member's Archive survives losing access)._
Using Project Desk with client or NDA'd work
If you build under an NDA or handle a client's, employer's, or another party's confidential work, you decide whether descriptions of that work may be stored here. Any text your agent sends becomes hosted desk content. Review the obligations that apply to you and configure or direct your agent accordingly.
Data handling
- No training on your content. We do not use your desk content to train AI models, and we do not sell it or use it for advertising. (Note: any AI client you connect — Claude, Codex, etc. — handles your prompts and the desk content it reads or writes under that provider's own terms.)
- Where it lives. Hosted on Microsoft Azure in the United States (East US), in a multi-tenant PostgreSQL database. Every read and write is authorized against a desk: its owner and active invited members can access the shared desk; unrelated desks cannot.
- Who can access it. You, and any teammate you explicitly invite to a shared desk. Plus our own infrastructure to the extent needed to operate the service (as any hosted service requires). We're a small operation and we don't browse customer desks.
- Your control. Export your entire desk (
.mdor.json) any time from Settings, and delete your account — permanently, immediately — from Settings → Danger zone. An emailed deletion request is honored within 30 days.
Sign-in & security posture (honest MVP)
- We hold no passwords. You sign in with GitHub, Google, or Microsoft via OAuth; your two-factor and account security are whatever you've set on that provider. We store only your provider id, email, verification status, and name.
- Connector tokens are HMAC-signed, expire (access ~1 hour, refresh ~30 days), and are bound to durable grant families. Settings can revoke one client or all agents immediately; refresh tokens rotate and replay outside the retry window revokes the family.
- Logs are retained ~90 days.
- Per-desk change history supports synchronization and technical diagnosis and is deleted with the desk. A customer-facing mutation-audit interface, SSO/SAML, and individual token revocation are not yet available.
Questions, or want something here in writing for your own compliance review? Email wildsdesign@gmail.com. See also the Privacy Policy, Terms of Service, and About.