Privacy Policy
Fund Desk collects nothing. No telemetry, no analytics, no crash reports, no usage statistics, no account. The software does not send us anything, ever — not on first run, not on update, not in the background. This policy exists mostly to say that precisely, and to cover the two places where we do unavoidably handle information: buying the software, and emailing us for help.
1. What stays on your computer
All of it. Specifically:
- Your Bybit API keys, encrypted at rest using facilities provided by Windows and tied to your user account. They are sent only to Bybit, by your own computer, to make the requests you asked for.
- Your trades, plans, journal entries, notes and tags.
- Your equity history, risk settings and guardrail events.
- Your desk token and any preferences.
These live in %LOCALAPPDATA%\FundDesk on your machine. We have no
copy, no access, and no ability to recover any of it for you. That cuts both
ways: nobody can subpoena it from us, and nobody can restore it for you if you
lose it. Keep your own backups.
2. What the software talks to
Only Bybit, and only at your instruction — to read your balance and positions,
to fetch market data, and to place or cancel orders you have approved. It binds
to 127.0.0.1, which means it is reachable only from your own
computer and not from your network or the internet.
There is no licence server. The software does not check in to verify that you paid, and it will keep working offline and indefinitely.
3. Buying it
Purchases are handled by a third-party payment provider acting as merchant of record. They collect what is needed to take a payment and meet tax obligations — typically your name, email address, country and payment details — and they hold that data under their own privacy policy, not ours.
We never see or store your card details. What reaches us is your email address and order reference, which we use to deliver your licence key, to send you update notices if you ask for them, and to handle refunds and support. We do not sell it, rent it, or pass it to anyone for marketing.
4. Emailing us
If you contact support, we receive whatever you choose to send: your message, your email address, and anything you attach. Please do not send us API keys, secrets, or your database — we will never ask for any of them, and there is no support problem that requires them.
We keep support correspondence only as long as it is useful for handling your issue and any follow-up, and then delete it.
5. Cookies
The software sets exactly one cookie, in your browser, on
127.0.0.1: your desk token, so you do not have to re-enter it on
every page. It never leaves your machine and is not an analytics or tracking
cookie. The desktop app uses the same mechanism inside its own window.
6. Your rights
Because we hold almost nothing, there is little to exercise rights over — but you may ask us what we hold about you, ask us to correct it, or ask us to delete it, by emailing the support address. We will respond within a reasonable time. For anything held by the payment provider, contact them directly; we will point you to the right place if you ask.
This policy is written to meet the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are in the EU or UK, the same practical answer applies: the software processes your data locally, on your own device, under your own control, and transmits none of it to us.
7. Changes
If this policy changes, the new version ships with a new release of the software and is dated. Because we collect nothing, a change here is far more likely to be a clarification than a new use of your data.
8. Contact
Privacy questions go to the support address published on the Fund Desk website.