PressDesk handles sensitive things on your behalf — your Gmail, your journalist relationships, your brand voice. This page is how we earn the trust to do that. No marketing copy. Just what we do, what we don't, and where we are in the process.
Audit begins when closed beta concludes. Type I expected Q3 2026. Type II Q1 2027.
Full data export, right to erasure, EU subprocessor disclosures in place.
California Consumer Privacy Act compliant. Do Not Sell flag honored.
Every outbound from Press includes a physical address, an unsubscribe link, and respects opt-outs immediately.
PressDesk is engineered to be a custodian of sensitive information from day one. Encryption, isolation, and least-privilege everywhere — not because a compliance auditor told us to, but because we'd want them ourselves.
All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Database backups are encrypted with separate keys held in AWS KMS. No unencrypted production data exists anywhere in our infrastructure.
Your Gmail OAuth tokens are stored encrypted with envelope encryption: a per-tenant data key wrapped by an AWS KMS master key, rotated every 90 days. Tokens are decrypted in-memory only at the moment of use, never logged, never persisted in plaintext anywhere.
We request only gmail.send, gmail.modify, and gmail.readonly on the threads Press has touched. We never read your entire inbox. We never access threads we did not initiate.
Every customer's Brand Brain, journalist relationships, and agent state are isolated at the database row level with enforced tenant IDs on every query. Cross-tenant access is impossible by construction, not just by policy.
Engineer access to production data is read-only, audited, and requires explicit just-in-time elevation tied to a specific support ticket. Founder access is the same. We log every query against a customer's data; you can request the access log for your own account at any time.
Annual third-party penetration test. First scheduled for Q3 2026 with NCC Group or equivalent. Report summary will be shared with paying customers under NDA.
PressDesk only works because Press learns deeply about your company. The Brand Brain is the most valuable asset in your account. Here's exactly what happens to it.
Your brand voice samples, your journalist relationships, your pitch outcomes — none of it is ever used to train foundation models. Not by PressDesk, not by Anthropic, not by any LLM provider. We use Anthropic's zero-data-retention API tier specifically to prevent this.
Customer A's Brand Brain is never visible to Customer B in any form, including aggregated. The shared parts of the system (the global journalist universe, news data, source feeds) are intentionally separated from anything tenant-specific.
Request a full export of your Brand Brain at any time from your dashboard. You'll receive a structured JSON file containing every entity, fact, voice sample, pitch outcome, and journalist relationship. Yours to keep, whether you stay with us or leave.
One click in the dashboard erases your Brand Brain from production. Within 30 days it is purged from backups. We retain only the legally required minimum (billing records under tax law, audit logs under SOC 2 retention). Everything else is gone.
Production data is hosted on AWS us-east-1 by default. EU data residency available on Senior and Director tiers (eu-west-1, with no data crossing the Atlantic). Custom regions on Enterprise.
These are the third-party services that touch PressDesk customer data. Disclosure is required for GDPR; we'd publish it anyway. If we add or remove a subprocessor, we update this page and notify paying customers 30 days in advance.
| Provider | Purpose | Data accessed | Region |
|---|---|---|---|
| AWS | Compute, database, object storage, KMS | All customer data (encrypted) | US, EU |
| Anthropic | LLM inference (Claude) | Prompt content (zero-retention API) | US |
| OpenAI | Backup LLM (classification only) | Anonymized text (zero-retention API) | US |
| Stripe | Billing, payments, invoices | Customer name, email, billing address, card token | US, EU |
| Google (Gmail API) | Send and read pitch threads | OAuth token, thread metadata, message content | US |
| Resend | Transactional email | Customer email, message content | US |
| Sentry | Error tracking | Stack traces, user IDs (no PII) | US |
| PostHog | Product analytics | Anonymized event data | US, EU |
| Vercel | Frontend hosting | Public assets only | Global edge |
If we don't deliver, you don't pay. We made the trial and the refund policy generous on purpose, because we want the buying decision to be obvious.
If Press doesn't land you a real placement in a real outlet within 60 days of starting your trial, your next month is free. No fine-print list of “qualifying” outlets, no hoops. Real coverage, real credit.
If you're charged after the trial and decide within 7 days that it wasn't right, email us at support@pressdesk.ai. Full refund, no questions, no exit survey required. Your access continues for the period you paid.
All tiers are monthly. Cancel any time from the dashboard. Annual billing is offered at a discount but never required.
Data Processing Agreement (DPA) available on request for any paying customer. Subprocessor list published above. Right to access, rectification, erasure, portability, and restriction all honored. EU representative listed in our DPA. Standard Contractual Clauses (SCCs) in place for transatlantic transfers.
Do Not Sell My Personal Information flag honored from any state. We do not sell customer data, ever, regardless of jurisdiction. The categories of personal information we collect are disclosed in our Privacy Policy.
Every email sent by Press on your behalf includes a physical address (yours, captured at onboarding) and a working unsubscribe link. Opt-outs honored immediately, not within 10 business days as the law allows.
Express or implied consent basis documented for every Canadian contact pitched. Consent records retained for the legally required period.
Not in scope. PressDesk is not designed for healthcare PHI. If your business handles PHI, your Brand Brain should not contain identifying patient data.
Audit kicks off after closed beta concludes. Type I controls already in place; full Type II report expected Q1 2027. We will publish the bridge letter once issued.
PressDesk is built by humans. Humans ship bugs. Here is what we promise about how we respond.
If we detect or are notified of a security incident affecting your data, we notify affected customers within 72 hours of confirmation. Full disclosure of what happened, what data was involved, and what we are doing. No PR-trained corporate-speak. The founder writes the email.
If Press sends an email on your behalf that it should not have, we will: pull the trace, send you the full reasoning chain, and credit your account if the mistake caused you reputational harm. We won't pretend it didn't happen.
Status page at status.pressdesk.ai (coming soon). Outages logged with timestamps, root cause, and remediation. Service credits applied automatically per our SLA on paid plans.
Security review for a procurement team. DPA request. Pen test report under NDA. Anything we missed. Email goes to a human who responds within one business day.