How we protect your workspace, signatures, and client data
Sign in with AppleEncrypted syncNo data sellingGoogle Gemini (optional)Audit trails
AstraDesk® is for freelancers and small teams who need invoices, contracts, and e-signatures in one place — without asking clients to install an app.
Who makes AstraDesk
AstraDesk is built in Ireland by Niall Darby at Star-Tek IT Services. Star-Tek is registered with Ireland’s CRO; registration details on request via support@astradesk.org. LinkedIn: niall-darby. Full company facts: Who makes AstraDesk.
Pricing & access
AstraDesk is a one-time App Store purchase (iPhone, iPad, or Mac). There is no subscription. After purchase, sign in at www.astradesk.org with the same Apple ID. Your workspace syncs across Mac, mobile, and web. Windows users can also download the desktop app.
Before you put real clients on it
Questions a careful buyer should verify. Short answers:
Question
Answer
Who legally operates AstraDesk?
Niall Darby at Star-Tek IT Services, Ireland (CRO-registered; details on request). App Store seller: Niall Darby. Company page.
Where is customer data stored?
Workspace data is stored on Supabase in AWS region eu-north-1 (Stockholm, Sweden), in the EU. HTTPS in transit. Private-per-user workspace, not a zero-knowledge vault.
Profile → Export everything downloads a single ZIP of your full workspace (JSON, CSV, rendered PDFs, signed files, audit trails) — no support ticket needed. We commit to 90 days’ notice before any shutdown, with export available throughout. Continuity commitment.
Are e-signatures supported with an audit trail?
Clients sign in the browser from a private link — no account for them. Links expire after 30 days, you can void one at any time, and you can require an emailed 6-digit code before the signer sees the document. Completed documents include a timestamped audit trail that also records link creation, voiding, and email verification. Some documents still need wet ink or a notary. Get professional advice when the document matters. How signing links are protected.
Your data
We do not sell your invoices, contacts, or signature data to advertisers or data brokers. Full details: Privacy Policy and DPA.
Account and workspace data sync through encrypted cloud infrastructure (Supabase) in eu-north-1 (Stockholm, Sweden).
Signed PDFs and audit trails stay in your workspace and in exports you control.
Export invoices as PDF, CSV, or Excel anytime, or download your entire workspace as one ZIP from Profile → Export everything. Account deletion is also self-serve in Profile; for help with either, email support@astradesk.org or use Support.
Where your data sits
We build the app; big cloud companies run the servers. Those companies already pass serious security audits. Your invoices and contracts live there — not on a home computer.
For buyers who ask about audit paperwork: those providers publish their own security reports. AstraDesk has not completed a separate company-wide audit certificate yet — we will not claim we have.
When you send a signing link, recipients review and sign in their browser. Completed documents include a timestamped audit trail suitable for business records. Clients never need to create an AstraDesk account.
The link is the key, so we limit what a key can do:
Every signing link expires 30 days after it is issued.
You can void a link at any moment from the document — a voided or expired link never shows the document.
Optional signer email verification: require a 6-digit code emailed to the recipient before the document opens. That turns “anyone with the URL” into “anyone with the URL and the recipient’s inbox”. Recommended for NDAs and payment-linked agreements. The verified address is recorded in the audit trail.
Link creation, voiding, email verification, and each signature are recorded with UTC timestamps.
Some documents still need wet ink or a notary. See company and e-signatures.
Security questions we get asked
These are the questions a careful buyer should ask. Short answers:
Where is data hosted? Authentication, database, and file storage run on Supabase (Postgres + Auth + Storage) in AWS region eu-north-1 (Stockholm, Sweden — EU). Traffic uses HTTPS. This is a private-per-user workspace, not a zero-knowledge vault: we can operate the service; other AstraDesk customers cannot read your rows (database row-level security).
Is MFA / 2FA available? Yes. In Profile → Security → Two-factor authentication you can enrol any TOTP authenticator app (1Password, Google Authenticator, Authy, Apple Passwords). Once on, every new sign-in — email, Apple, or Google — asks for the 6-digit code before the workspace opens. Sign in with Apple additionally carries whatever two-factor you have on that Apple ID. Face ID / Touch ID can lock the app on device; that is separate from account 2FA. If you lose the authenticator, reset your password from the sign-in page and remove the old factor.
Are backups encrypted, and how long are they kept? Supabase encrypts data at rest and in transit on their infrastructure. Platform backups follow Supabase’s backup policy for the plan we use. When you delete your account or content we remove it from active systems; provider backups expire on their schedule. Export PDF, CSV, or Excel for your own copy — do not treat AstraDesk as the only backup.
How is my data kept safe? We build the app; big cloud companies run the servers. Those companies already pass serious security audits. Full table: Where your data sits.
Why does Apple’s privacy label matter? The App Store privacy nutrition label should match this policy: if you sign in, invoices, contracts, contacts, and related workspace data sync to our backend. Apple does not independently verify those labels. The Privacy Policy is the accurate description.
AI Draft Studio (optional)
Draft Studio can use Google Gemini to turn a plain-language prompt into a starting contract draft. Optional dictation sends a short microphone clip to Gemini to fill that prompt. This is optional — built-in templates and offline drafts never leave your workspace.
When AI is on, your prompt and related business context (such as company name and client) are sent through our servers to Google Gemini.
AstraDesk does not use your drafts to train our own models. Google’s handling of API content is described in the Gemini API terms.
You review and edit every draft before saving or sending it for signature. AI output is not legal advice.
Turn AI off in Profile, or simply don’t use Draft Studio. How-to: Support. Legal detail: Privacy Policy.