Security & Data Practices
Your acquisition work deserves clear data practices.
Acquisition Desk helps buyers organize listings, assumptions, diligence materials, risks, and documents. This page explains handling, providers, limitations.
No online service can guarantee absolute security. Acquisition Desk uses safeguards intended to reduce risk. Upload only information needed to evaluate an acquisition.
Direct answer
Acquisition Desk deal workspaces are account-protected and are not public webpages. The application uses specialized providers for authentication, infrastructure, AI processing, payments, and operations. Information may be shared with those providers only as needed to deliver functionality, subject to their terms and data practices.
Account access
Workspaces require an authenticated account, with server-side checks that scope deal access to the applicable user.
Uploaded documents
Upload only what is reasonably needed. File-type and size checks help limit unsupported uploads.
AI-assisted processing
Relevant deal context is sent to the configured AI service only when a user invokes an AI-assisted feature.
What information Acquisition Desk may process
Account information
- Name and email address
- Authentication identifier and account status
- Subscription plan and entitlement
Buyer preferences
- Buyer Profile and Buy Box preferences
- Acquisition goals and target industries
- Financial criteria
Deal information
- Listing details and purchase assumptions
- Financial and financing inputs
- Risk reviews, broker questions, diligence findings, and deal updates
AI, billing, and technical information
- Context submitted for requested AI-assisted workflows and saved Copilot messages
- Subscription and transaction metadata from billing
- Approved product events, attribution fields, timestamps, browser or device information, and error diagnostics
Public planners may remain in the browser. AI-assisted features require relevant context to be sent to the configured AI provider.
Deal data and uploaded documents
Acquisition Desk may receive listing documents, financial records, diligence files, screenshots, notes, and other materials when a feature asks for them. The audited implementation does not establish one public storage, scanning, or retention statement for every document type, so this page does not invent one.
Feedback screenshots have a separate path: up to five JPEG, PNG, or WebP files of up to 5 MB each are format- and signature-checked, processed in memory, and sent as email attachments rather than stored by the application.
Upload only what is reasonably necessary. Consider redacting Social Security numbers, bank-login credentials, full payment-card numbers, health information, and unrelated personal records. Downloads are outside Acquisition Desk’s control after you save or share them.
How AI-assisted features use deal information
AI-assisted features include listing extraction, AI Risk Review, Pursuit Pack and Acquisition Memo generation, and Deal Copilot. The requested workflow determines the context, which may include deal information, extracted listing data, risk or financing context, and prior Copilot content. Relevant prompts and results may be saved for the feature and conversation history.
Acquisition Desk uses an API-based AI service for specified AI-assisted features. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Standard provider retention and abuse-monitoring practices may still apply.
That is the provider’s current API policy. Acquisition Desk cannot independently confirm the managed integration’s organization-level setting and does not promise immediate deletion, a fixed retention period, or exclusive human access to provider systems.
OpenAI business data practicesOpenAI model-improvement policy
Acquisition Desk Clipper
When activated, the Clipper reads the active tab for a requested listing import. A clip may include the page URL, title, selected text, and visible listing content. It requests active-tab, scripting, and tab metadata permissions.
It is not a background browsing-history collector. Clipped information is sent to Acquisition Desk when you submit it for the requested workflow.
Read about the ClipperView the official Chrome Web Store listing
Billing is handled through Stripe
Stripe processes payment-card details and sends billing events used to update subscription status. Acquisition Desk generally does not store full payment-card numbers, but receives provider identifiers and subscription or transaction metadata needed for access, billing, and support. Billing records may be retained for accounting, fraud prevention, or legal obligations.
Product analytics and operational logs
Analytics and attribution records may include approved product events, attribution fields, paths, timestamps, session or anonymous identifiers, user-agent information, response details, and error diagnostics.
Acquisition Desk does not intentionally include uploaded-document contents, planner or worksheet values, checklist selections, broker-question selections, financial inputs, deal notes, seller or business identity, or AI prompt text in public attribution events.
Technical logs may still include request timestamps, endpoints, response status, technical identifiers, and error details. Authorization and cookie headers are redacted, and no fixed log-retention period is claimed.
Some public tools store information only in your browser
The SDE worksheet, due-diligence checklist, business-broker question planner, and cash-requirement planner store entered values in first-party browser storage without sending them to Acquisition Desk. No account is required, and values may persist after refresh.
Browser-local storage is not an account boundary. Someone using the same browser profile may see the values. Clear browser storage or use the reset action, especially on shared devices.
Retention and deletion
The application supports deal deletion and a separate archive state. These actions concern the application record; billing records, logs, provider records, and backups may follow different retention rules.
Users may request deletion of their Acquisition Desk account and associated application data by contacting support@acquisitiondesk.ai. After verifying the request, Acquisition Desk will remove application data reasonably associated with the account through its available administrative processes. Some billing, security, fraud-prevention, backup, or legally required records may be retained where reasonably necessary or required. Deleting an authentication account does not necessarily delete all application or third-party records automatically.
Service providers that support Acquisition Desk
| Category | Provider | Purpose |
|---|---|---|
| Authentication | Clerk | Account authentication and session management. |
| AI processing | OpenAI API | AI-assisted acquisition workflows and resulting outputs. |
| Payment processing | Stripe | Payment-card processing, billing events, and subscription metadata. |
| Email delivery | Resend | Certain product, feedback, and support emails. |
Providers may update their services and policies; their handling of information is governed by their applicable agreements and privacy documentation.
Current application safeguards
Security is implemented as a collection of controls rather than a single feature. The following customer-relevant practices are currently verified.
- Managed authentication
- Server-side authorization and user-scoped access
- Upload file-type and size validation
- Server-side subscription and entitlement enforcement
- Production traffic is intended to use HTTPS
- Automated regression and production-build validation
Security is shared with the user
- Protect account access with a unique password, available authentication protections, and careful sharing practices.
- Upload only information reasonably needed for the acquisition workflow.
- Redact unnecessary sensitive personal information, passwords, and authentication secrets before upload.
- Verify recipients and protect exported or downloaded reports, PDFs, and diligence files.
- Sign out and clear browser-local tools when using a shared device.
Acquisition Desk is an acquisition-analysis workspace, not a secure credential vault, payment-card repository, health-record system, or document room designed for unrestricted regulated data.
Report a security concern
If you believe you found a security issue involving Acquisition Desk, contact support@acquisitiondesk.ai with the affected page or feature, a clear description of the issue, and steps that help reproduce it. Do not include passwords, private keys, full payment-card numbers, or unrelated personal information. Please do not access, modify, download, or disclose another user’s information while investigating an issue.
Frequently asked questions
Last reviewed: August 2026
Evaluate deals in one organized workspace.
Keep listing information, financial assumptions, risks, questions, diligence materials, and acquisition documents connected to the same opportunity.
Acquisition Desk