ArchDesk

Privacy Policy

ArchDesk keeps your firm's work on your firm's own computer. This explains the small amount of information that does reach us, why, and how to have it deleted.

Last updated 8 September 2026. ArchDesk is a product of NexArch Design Lab, Lucknow, Uttar Pradesh, India.

The projects, drawings, timesheets, invoices and ledger entries you keep in ArchDesk never leave the office computer it is installed on. We hold no copy of them, we cannot read them, and there is nothing about them for us to lose, sell or hand over.

1.Who we are

ArchDesk is made and sold by NexArch Design Lab, based in Lucknow, Uttar Pradesh, India. When this policy says “we”, it means that business. Questions and requests about your information go to archdesk@nxdl.in, which is also the address for a grievance under India's Digital Personal Data Protection Act, 2023.

2.The two halves of ArchDesk, and why it matters here

There are two separate things, and almost every question about privacy has a different answer for each.

  • The software is installed on one computer in your office and used from browsers on your own network. It is where your firm's work lives.
  • This website is where you buy a subscription, hold an account, and get your activation code. It is the only part of ArchDesk we operate.

We hold information from the second. We hold none from the first, except the few lines described in section 4.

3.What this website collects

When you create an account here, we store:

  • your email address and a password, held for us by our authentication provider and never visible to us in plain text;
  • the details you type into your account page — your name, your firm's name, and optionally a phone number, city and your role at the firm;
  • your subscription: which plan, when it started, when it renews, and what you have paid, including a reference for each payment;
  • your licence, the activation codes issued against it, and a log of when it was activated, released or renewed;
  • the name of the computer that holds your licence — the PC's own Windows name, which you chose — so that your account page can tell you which machine it is on.

We use this to run your subscription and to answer you when you get in touch. It is not used for advertising, it is not profiled, and it is not sold or shared with anyone for their own purposes.

4.What the software sends, on the one day it does

ArchDeskworks offline. It makes no automatic network calls at all — no telemetry, no update checks, no analytics, no crash reporting. It reaches the internet only when a person at your office presses a button that plainly requires it, which is: activating a new installation, releasing it to move to another PC, and pressing “Sync” after a renewal.

When one of those happens, this is everything that is sent:

  • your activation code, or your account email and password if you sign in instead — the password is checked against this website's own sign-in service and is never stored, written down or logged by us;
  • a device fingerprint, which is a one-way SHA-256 hash of an identifier Windows already keeps for the machine. We receive the hash, never the identifier itself, and it cannot be turned back into anything about your computer. It exists for one purpose: so that a licence bought once cannot be run in two offices at the same time;
  • the computer's name, so your account page can say which PC holds the licence rather than showing you a row of hexadecimal.

No project, task, drawing, file name, employee record, timesheet, invoice or ledger figure is ever transmitted, on any of those calls or at any other time. The software has no code that would do it.

5.Cookies and what is kept in your browser

This website sets no advertising or analytics cookies and runs no third-party trackers. When you sign in, your session is kept in your browser's own local storage so that you stay signed in; signing out removes it.

The software itself, on your office computer, sets a session cookie so that people stay signed in between visits, and remembers small preferences — which view you last used, how a list was sorted — in the browser on each employee's own machine. None of that reaches us.

6.Who else is involved

We keep this list as short as we can, and every entry here is a supplier that helps us run the account area — none of them receives anything from the software on your office PC.

  • Supabase hosts the database and the sign-in service behind your account.
  • Our activation service, which we run ourselves, issues and verifies licences.
  • When card payments are introduced, the payment provider will handle your card details directly. We will not see or store a card number at any point, and this policy will be updated to name the provider before that goes live.

7.How long we keep it

Your account details are kept while your account exists. Records of payments are kept for as long as tax law requires us to keep them, which in India is currently eight years from the end of the relevant financial year — that obligation applies to the record of the sale, not to your name and contact details.

When an account is closed, everything in section 3 is erased and what remains is a dated line saying that an account existed and was closed.

8.Your rights, and the button that exercises them

You can see everything we hold about you on your account page — it is the same data, read from the same rows. You can correct any of it there at any time.

You can have it erased. Close your account schedules the deletion for 14 days later and can be cancelled at any point inside that window. Nothing is deleted before the date shown, and everything is deleted on it. You do not need to write to us or explain yourself.

If you would rather ask us to do it, or you want a copy of your data in a file, write to archdesk@nxdl.in and we will do it within thirty days. If you are unhappy with how we have handled a request, you may complain to the Data Protection Board of India.

9.Security

Passwords on this website are stored hashed by our authentication provider. Access to your account data is enforced by the database itself rather than by the website hiding things from you: the rules say that a signed-in account can read its own rows and nothing else, and they apply no matter how a request arrives.

On your own office computer, security is largely in your hands, and the honest advice is short: keep the machine on a network you control, make sure someone takes the backup, and generate a recovery key in Settings so a forgotten password never locks the firm out of its own records.

10.Changes

If this policy changes we will update the date at the top of the page. Where a change is significant we will say so on your account page rather than relying on you to re-read it.