Skip to content

Overview

Overdesk reads your support conversations so it can draft replies, which means it handles your customers' personal data. This section explains where that data goes, how it is protected, who on your team can reach it, how long Overdesk keeps it and how you remove it. It is written for the person who reviews Overdesk before your team relies on it.

The short version

  • Overdesk never messages a customer. Every draft waits unsent in your help desk until a person on your team reads it and sends it, and sending directly from Overdesk is disabled. The one exception is a FreeScout draft reply on an older module, which may be sent: see Where drafts go and the note below.
  • Drafting runs on your own Anthropic API key, so your conversations are processed under your own agreement with Anthropic.
  • Email addresses, phone numbers, card numbers and other recognisable details are replaced with stand-ins before any conversation text reaches the model, then put back in the draft your agent reads. Pictures and PDFs your customers attach are sent to the model as they are, unless you switch that off; see How customer data is handled.
  • Every query Overdesk runs on your workspace's behalf is limited to your workspace, and the few platform-wide jobs cannot show one workspace's content to another.
  • Help desk credentials, your Anthropic API key, the keys and tokens for the other services you connect, and webhook signing secrets are encrypted with AES-256-GCM using a key unique to your workspace.
  • An admin can erase one customer's conversations and the records built from them on request, and the owner can delete the whole workspace at any time.

Overdesk does not train models on your data. The Privacy Policy sets out that commitment in full.

What Overdesk writes to your help desk

Everything Overdesk writes into your help desk is for your team rather than your customer, such as internal notes, unsent drafts and tags. Three writes deserve a plain mention.

  • Escalation rules assign a conversation to a person or team in your help desk. The customer is not messaged. See Escalation.
  • Close stale conversations, which is off until your team schedules it, closes pending conversations nobody has touched for 90 days. Overdesk does not message the customer, but your help desk may send its own survey or notice when a conversation closes. See Closing stale conversations.
  • FreeScout draft replies need the API and Webhooks module 1.0.103 or newer. Older versions may not recognise the reply as a draft, and FreeScout sends a reply it does not recognise, so it could reach your customer unread. The internal note, which is the default, works on every version. See Where drafts go.

In this section

Security questions the docs don't answer go to hello@overdesk.io.