Privacy policy
Last updated 14 September 2026
ApplyDesk is an application portal for Discord communities, operated at applydesk.net. This page explains what personal data we process, why, and how you can exercise your rights under UK GDPR and the EU GDPR.
Who we are
ApplyDesk is the controller for staff accounts, billing, and the platform itself. When you apply to a community, that workspace is typically a separate controller of your answers; we process them on their behalf to run the portal.
Contact: data request form or the email you used when you applied / signed in.
What we collect
- Staff (Discord OAuth): Discord user ID, username, avatar, email, servers you can manage (to connect a workspace).
- Applicants: answers you submit, optional Discord profile and email, submitter IP (abuse prevention), and decision emails if the workspace enables them. If you sign in on the community portal, you can see your own submissions and status. Staff notes appear there only when that workspace turns the setting on.
- Billing: Stripe customer and subscription IDs for workspace owners. Card details never hit our servers.
- Usage: application metadata (status, timestamps) and optional analytics aggregates on paid plans.
Why we process it
To provide the service (contract), keep the platform secure (legitimate interests), send transactional email you or a workspace requested, and meet legal obligations including data-protection requests. We do not sell personal data.
Processors
Hosting and file storage (Vercel), database (Postgres), email (Resend), payments (Stripe), identity and messaging (Discord). Community workspaces may also receive your application in Discord review channels.
Retention
Staff accounts last until you delete them. Applications stay with the workspace until the workspace is deleted or we complete an erasure request (we strip identity and answers; anonymous application rows may remain for the community's records). Backups rotate on our host's schedule.
Your rights
You can access, correct, erase, restrict, or object to processing, and (where it applies) take your data elsewhere. You can complain to the ICO (UK) or your local EU supervisory authority.
- Signed-in staff: Account settings — export JSON, erase application submissions, delete the account.
- Anyone: data request form. We aim to respond within 30 days.
- Enterprise workspaces: a data processing addendum that an owner can accept in the dashboard.
We may need to confirm it's you (usually via Discord ID and the email on file). We can refuse requests that are unfounded, excessive, or that would break another person's rights.
Cookies
We use a session cookie so staff stay signed in, and a short-lived cookie for applicant Discord login on a portal. No advertising cookies.
This page is a practical description of how ApplyDesk works, not legal advice. We may update it when the product changes.