Ingest the upstream master runtime pinned in the previous commit and carry every channel across the upstream changes without adding product behaviour of our own. - Vendor the new first-party packages (dsh-otel, experimental-schedule-bundle, client-product-analytics), resolve them to the local tarballs and declare dsh-otel for Stable and Beta so the runtime closure stays complete. - Keep upstream Desktop product analytics off in all three channels: Stable and Beta disable the `desktop-product-telemetry` and `product-analytics` rows at launch, Next disables them in its cordis patch. The exporter also needs the upstream Electron shell's DSH_CLIENT_VERSION, which no DSH Desktop launcher provides. - Next follows the Scheduled Tasks move to the official experimental-schedule-bundle: the plugin card opens and toggles the bundle, the retired item slots are removed, and existing Profiles are migrated by profile-schedule.ts. verify-host now exercises bundle enable/disable and restart persistence. - Rebase the ui-plugin-manager and ui-settings-account patches onto the new upstream sources, and give the Next plugin-detail test fixture the `configForms` service the upstream controller now injects. - Privacy notice 1.1: record that product analytics stays disabled and that session telemetry defaults to feedback-only.
25 KiB
DSH Desktop Privacy Policy
- Version: 1.1
- Effective and last updated: September 28, 2026
DSH Desktop is a local-first, open-source desktop application. This policy explains what information the official DSH Desktop distribution and official online services process, why they process it, who receives it, and what choices you have.
In this policy, “we” means the Anywhere Labs project maintainer team that maintains and publishes the official DSH Desktop distribution under the anywhere-labs GitHub organization and operates the official dshdesktop.cn services. DSH Desktop is an independent community project and has no affiliation, partnership, authorization, or endorsement relationship with DeepSeek.
For privacy questions or rights requests, email t4wefan@qq.com. Do not put installation identifiers, logs, credentials, or other private information in a public GitHub Issue.
1. Scope
This policy applies to:
- DSH Desktop provided through the official GitHub repository and official release channels;
- the official website, version-check service, and download redirects under
https://www.dshdesktop.cn/; and - privacy requests, support email, or issue reports that you voluntarily send to the project maintainers.
This policy does not control processing performed by third-party forks, modified builds, third-party distributors, model providers, plugins, marketplace sources, or package services. If a third-party build still calls the hard-coded official dshdesktop.cn endpoints, this policy applies to the information those official endpoints actually receive, but not to other processing by that build or its distributor.
2. Summary
- DSH Desktop profiles, settings, workspaces, sessions, logs, and crash files remain on your device by default.
- The official update service does not require a DSH Desktop account. Its version-check code does not intentionally send prompts, responses, file contents, workspace paths, profile names, session contents, API keys, MAC addresses, or hardware serial numbers.
- Packaged macOS and Windows builds check for updates by default and send a locally generated, persistently stored random installation UUID. This is a pseudonymous identifier that may qualify as personal data under applicable law. It is not a hardware ID and does not guarantee one value per physical machine.
- Installer downloads do not receive that installation UUID from Desktop, although the website, download host, and network infrastructure still receive ordinary network metadata.
- Diagnostic archives are created locally only when you export them and are never uploaded automatically by DSH Desktop.
- Model services, plugins, marketplace sources, and package services that you choose process data under their own terms. They do not become subject to this policy merely because DSH Desktop can connect to them.
3. Official version checks
3.1 When the request occurs
Packaged macOS and Windows applications request the following endpoint about 60 seconds after startup by default:
GET https://www.dshdesktop.cn/api/desktop/version
Another check occurs about six hours after each completed check. You can also select Check for Updates manually. Development runs, unpackaged launches, and Linux do not currently use this packaged automatic-update flow.
3.2 What the request contains
The client explicitly adds:
Accept: application/json; andX-DSH-Desktop-Installation-Id: <random UUID v4>.X-DSH-Desktop-Version: <canonical installed stable version>.
The application adds no query parameters or request body to this GET request. Like every internet request, the official service and its infrastructure also receive the IP address, request time, TLS and connection details, and standard request metadata generated by the networking stack. That metadata may include a User-Agent, cookies, accepted compression, and operating-system or runtime-version information. The current code does not explicitly require the Electron network session to omit existing credentials, so we do not promise that a version request can never include session data. We also do not describe “two headers explicitly set by the client” as “only two fields leave the device.”
The version-check code does not intentionally attach prompts, responses, file contents, workspace paths, profile names, session contents, model credentials, MAC addresses, or hardware serial numbers.
3.3 How the installation UUID is created and changed
The installation UUID:
- is generated as a cryptographically random UUID v4 when Desktop starts and no valid persistent value exists in its Electron user-data directory;
- is stored in
identity/installation-idbelow that user-data directory; - is regenerated when the file is missing or corrupt, or when the complete user-data directory has been removed, and is not rotated during an ordinary launch;
- is not derived from and does not encode a username, device name, MAC address, disk serial number, or other hardware information;
- identifies one Desktop user-data directory, not a physical machine. Different operating-system users, user-data directories, or app copies on the same computer can have different UUIDs, while copied user data may copy the UUID; and
- normally persists until the file or application user data is deleted, becomes corrupt, and is rebuilt.
Default locations are:
- macOS:
~/Library/Application Support/DSH Desktop/identity/installation-id; - Windows:
%APPDATA%\DSH Desktop\identity\installation-id.
Deleting this file only causes a new UUID to be generated at the next launch. It does not stop later version checks or prevent the new UUID from being sent.
3.4 Purposes
Version-check data may be used only to:
- return the latest stable version and support update notices;
- recognize repeated requests from the same Desktop user-data directory as one installation, enabling deduplicated, aggregate update-service usage trends;
- maintain service reliability, investigate abnormal requests, and prevent abuse; and
- meet applicable legal obligations.
We do not use the installation UUID for advertising profiles or cross-service tracking, and we do not sell it. A version check requires no login, and the client sends no name, email address, or DSH Desktop account ID in that request.
4. Installer downloads, the website, and project communications
| Scenario | Trigger | Information that may be processed | Purpose and recipients |
|---|---|---|---|
| Installer download | You click a download or confirm a download after an update is found | IP address, time, standard network metadata, and the platform shown by the /mac or /windows path |
dshdesktop.cn, its hosting service, and the final download host use this information to deliver the file, protect the service, and measure download service usage. Desktop does not add the installation UUID to the download request. |
| Website visit | You open the website in a browser | IP address, time, browser and device network metadata, and the requested page | Website hosting and network infrastructure use it to deliver the page, protect the service, and diagnose failures. |
| GitHub Issue, discussion, or contribution | You submit it | Account details, text, attachments, code, and metadata that you make public | GitHub and the project maintainers use it to process issues, contributions, and community communications. Public submissions are publicly visible. |
| Email and support material | You send it | Email address, message, attachments, and diagnostics or environment details that you choose to provide | QQ Mail, your sending provider, and the project maintainers use it to deliver and respond to the message, investigate problems, and retain necessary correspondence. |
As of this policy's effective date, the website and official APIs are hosted by Vercel, so Vercel directly processes the installation UUID, IP address, and request headers that reach the API. Stable release state uses Upstash; the repository proves only that the backend reads release state, and this policy does not claim that the Desktop installation UUID is forwarded to Upstash. Official installer downloads currently redirect to files hosted by ModelScope. A download redirect target may set its own cookies or other session identifiers and processes the request under its own policy. We will update this section when a provider or download host changes.
5. Information stored locally by default
The following information remains on your device by default rather than being uploaded automatically to Anywhere Labs:
| Local information | Purpose and retention |
|---|---|
| Profiles, Desktop preferences, window preferences, plugin configuration, and marketplace source selection | Provide your configured local experience; retained until you delete it in the application, manually delete the relevant data, or reset application data. |
| Sessions, prompts, responses, tool records, and workspace information | Support local DSH features. Session records are stored under $DSH_HOME/sessions by default. The current persistence backend has no deletion API, so they accumulate until you remove them externally. Content may be sent to your chosen services when you invoke a model or tool, as described in Section 6. |
| Attachments and image caches | Stored under $DSH_HOME/attachments/v1 by default. The current implementation has no reference-aware garbage collection, so they remain until you delete them manually. |
| Model and service credentials | May come from the inherited environment, a project .env, $DSH_HOME/.env, or $DSH_HOME/.credentials.yaml. The managed YAML uses a 0600 file below a 0700 directory on platforms with POSIX permissions, but it is not encrypted. Tools or models running as the same operating-system user can deliberately read it. |
| Desktop logs | Stored below the Electron user-data directory. A file rotates at 10 MiB; files older than seven days are removed at startup; and the log directory is held below 200 MiB. Logs can still contain paths, workspace IDs, session IDs, commands, or plugin messages. |
| Local crash files | Electron Crashpad collects them locally and is configured not to upload to a crash server. They may contain fragments of process memory. |
| Diagnostic ZIP archives | Created only when you export one. They may contain logs, system and version information, paths, workspace or session IDs, bounded lifecycle and plugin IDs, and crash files within a shared 50 MiB evidence budget. The application retains the three newest archives that it manages; copies you make elsewhere are outside that limit. |
| System notifications | Turn and job notices use generic completion or failure copy without session names, user text, job contents, or error details; update notices include the available version. The operating system handles them locally without a DSH Desktop remote-push service. Notification history or cross-device synchronization depends on your system account settings. |
| Installation UUID | Stored as described in Section 3 and sent to the official update endpoint during a version check. |
Credential masking reduces risk but cannot guarantee that a log or diagnostic archive contains no sensitive information. Review an archive and remove information you do not want a recipient to see before sharing it.
Uninstalling the application may leave Electron user data, the DSH home, profiles, downloaded installers, or diagnostic files that you copied elsewhere. Back up anything you need before deleting local data.
6. Third-party services you choose
DSH Desktop is a composable plugin platform. The following transfers are triggered by services, sources, plugins, or actions you choose. Each recipient processes information under its own privacy terms.
6.1 Model and tool services
When you configure and invoke a model provider, MCP service, external tool, or other API, the recipient may receive an API key, prompts, conversation context, attachments or file contents, tool inputs and outputs, session identifiers, network metadata, and other information required by that service's protocol. The exact scope depends on your configuration and request. Do not send sensitive data to a provider you do not trust.
Upstream DSH also maintains an .anonymous-user-id that is separate from the Desktop installation UUID. When you invoke the current default DeepSeek model adapter, it sends that identifier in the x-deepseek-harness-user-id header, together with an optional session ID, the API key, and the complete model request, to the DeepSeek or compatible baseURL you configure. Do not confuse it with X-DSH-Desktop-Installation-Id.
The default composition also provides DeepSeek web_search. When you invoke it, it sends the API key, original search term inside a fixed prompt, model and token/use limits, and standard request metadata to the configured DeepSeek Messages endpoint. The webpage fetch tool is disabled by default.
6.2 Community Market and package services
Community Market does not require a remote source to be selected by default. After you select and use a source, the Host sends requests to it. Current built-in optional sources include:
- DSH 1024Store:
deepseek1024.com; - dshfind:
api.dshfind.com; and - a standard catalog source that you configure and confirm.
These sources receive the IP address, time, a fixed Market User-Agent, and the requested catalog resource. Depending on the capabilities of the selected source, a request can also include search terms, categories, sort order, language, page numbers, or cursors. Desktop's Host may fetch plugin images from the catalog source, GitHub, or an allowed image host, allowing the recipient to infer which plugin or publisher you are viewing.
When you preview or confirm a plugin installation, Desktop may also contact registry.npmjs.org, raw.githubusercontent.com, GitHub, or a registry you configure to retrieve package names, versions, manifests, repository or commit evidence, and dependencies. When profile dependencies need to be materialized at startup, the bundled package manager may also contact npm, GitHub, dependency hosts, or Electron's download service. Installed plugins and their dependencies run locally with your permissions and may independently read local data or access the network. Catalog inclusion and an Installable result are not privacy or security reviews.
6.3 dsh-market
If you select dsh-market in Setup or settings, opening the market, checking for updates, or viewing plugin content can contact awesome-dsh-plugin.com, the npm Registry, the GitHub API, raw.githubusercontent.com, GitHub avatar services, and images.weserv.nl. These recipients receive the IP address, time, requested resource, and relevant plugin, package, or repository identifiers; an image proxy also receives the original image URL. Installation or update still requires your confirmation and can then contact addresses declared by plugin dependencies. These requests do not include Desktop's X-DSH-Desktop-Installation-Id.
dsh-market also provides profile backups that you trigger manually or after you explicitly enable optional automatic backup:
- a local export only creates a file on your device;
- a WebDAV upload always sends a complete backup. Automatic backup is off by default; after you enable it, an upload can occur automatically when its 24-hour interval condition is met. The URL, username, automatic-backup setting, and last-success time are stored in browser local storage. After entry, the password remains in current renderer memory until the component unmounts or the page refreshes and is sent temporarily to the local Host for each request;
dsh-marketdoes not write the password to local storage or disk; - a GitHub Gist backup uses a GitHub token with
api.github.comto verify access and create, update, or read a secret Gist. A secret Gist is not publicly listed, but anyone with its URL can read it. A manually entered token remains in session memory, whileDSH_GITHUB_TOKENor a locally authenticatedghcan also be used. The Gist ID and WebDAV URL or username may remain in browser local storage; and - a complete backup contains
package.jsonand profile configuration files. It excludesnode_modules, the lockfile, and Market cache, but may includeconfig.toml,.env, API keys, tokens, or other secrets without masking. Local and WebDAV exports always use a complete backup; only a Gist export can select plugins and let you decide whether to include configuration.
Upload a backup only to a WebDAV service or GitHub account you trust. The selected service processes the backup, credentials, and network metadata under its own policy.
6.4 Optional upstream telemetry
Upstream DSH session telemetry keeps the upstream default of FEEDBACK_ONLY in Desktop's default composition: ordinary use uploads no session content, and only after you explicitly submit feedback in a session is that session's raw log up to the feedback sent, with the upstream anonymous user ID (stored as .anonymous-user-id in the DSH data directory; delete it to reset), to https://dsh-otel-collector.deepseeksvc.com/v1/logs or the endpoint configured in DSH_TELEMETRY_OTLP_URL. If you or a deployment operator explicitly sets DSH_TELEMETRY_MODE to FULL, session telemetry is sent continuously during ordinary use; setting DSH_TELEMETRY_DISABLED to any non-empty value makes Desktop turn the component off. That processing is controlled by the upstream configuration and recipient policy and is not the Anywhere Labs official update service.
Upstream also provides Desktop product analytics (product-analytics and desktop-product-telemetry) for any Profile named desktop, which would send a device ID, a user ID when signed in to a DeepSeek account, OS and app versions, and interface interaction events to DeepSeek. DSH Desktop turns both off at startup, and the official distribution does not send these analytics.
6.5 External links
External HTTP, HTTPS, and email links in the application or documentation are handed to the system browser or email client. The destination's policy applies after you open it.
7. Browser and LAN access
Allowing DSH to open in a browser does not itself upload a session to Anywhere Labs. It lets an ordinary browser access the local Host and is available only in compatibility mode. Loopback access is limited to 127.0.0.1 by default.
If you explicitly enable LAN access, the Host listens on LAN interfaces. The Host trust marker is not user authentication. Configuration surfaces such as settings, credentials, and local native dialogs remain restricted to loopback access, but a LAN client can create sessions and may operate your computer through the default command and filesystem tools. Browser security restrictions on LAN HTTP can also make some security modules unavailable. Enable it only temporarily on a fully trusted network, and turn it off when no longer needed.
LAN traffic normally does not pass through Anywhere Labs, but a person who connects to your computer over the LAN becomes a recipient of the data exposed through that connection.
8. Sharing, processors, and international transfers
The legal basis depends on your jurisdiction and the specific processing. Downloads, support, and third-party connections that you initiate are used to fulfill your request. Where that basis is recognized, version checks and necessary network logs rely on our legitimate interests in delivering secure, reliable updates and protecting the official service. Legal obligations rely on the relevant law, and non-essential processing that requires consent can rely only on valid consent. A jurisdiction that does not recognize legitimate interests for the processing does not acquire such a basis merely from this policy. Section 11 explains the current consent limitation for the stable installation UUID and your right to object.
We disclose or permit processing only in the following circumstances:
- infrastructure providers needed for the website, updates, downloads, email, and source-code hosting;
- model, tool, plugin, catalog, registry, download, or external-link services that you choose;
- recipients reasonably necessary to comply with applicable law or a court order, or to protect users, the project, and public safety; and
- a successor operator that assumes the same purposes and policy obligations in a project reorganization or service migration, with additional notice where required.
We do not sell personal data or provide the installation UUID to third parties for their advertising profiles.
Vercel, Upstash, GitHub, npm, ModelScope, model providers, and community sources may process data in different countries or regions. The location depends on current routing, the recipient, and your choices. Where a cross-border notice, separate consent, standard contract, or another safeguard is required, we and the relevant recipient must complete the applicable requirements.
9. Retention
We determine retention as follows:
- local installation UUIDs, logs, and diagnostic archives follow the rules in Sections 3 and 5;
- raw official-service request logs, including any UUID, IP address, and network metadata they contain, are retained only for the shortest period reasonably needed to deliver updates, maintain security, prevent abuse, diagnose failures, and produce de-identified aggregate statistics. They are then deleted or irreversibly de-identified unless a longer period is legally required;
- support email and issue records are retained until responding, dispute handling, or security follow-up no longer reasonably requires them. Public GitHub content is also subject to your controls and GitHub's retention rules; and
- third-party recipients retain information under their own policies and your arrangements with them.
Official-service infrastructure and logging settings can change, so this policy states the purpose and deletion conditions used to determine the period instead of inventing a fixed number of days that has not been verified against server configuration. You can ask about current processing and retention through the privacy contact email.
10. Security
Official internet endpoints use HTTPS. Desktop creates private directory and file permissions for the local installation UUID and constrains navigation, remote images, and catalog requests. Crashpad does not upload automatically, and diagnostic export warns about its privacy boundary.
No measure provides absolute security. Third-party plugins, privileged local processes, copied user data, publicly shared diagnostics, and unauthenticated LAN access can cross Desktop's intended boundaries. LAN HTTP is not an end-to-end encrypted channel.
11. Your choices and rights
Depending on applicable law, you may have rights to access, copy, correct, delete, or restrict processing of personal data; withdraw consent; object to particular processing; receive a portable copy; and complain to a supervisory authority. Contact t4wefan@qq.com. To locate version-service records, we may ask you to provide your local installation UUID privately. Do not publish it.
We cannot remotely delete files on your device. You can remove relevant local data while the application is closed; deleting the installation UUID causes a new value to be generated at the next launch. Data that has already been irreversibly aggregated or can no longer be linked to you may not be recoverable or individually deletable.
This policy is a notice, not automatic consent where law requires separate or affirmative consent. The current release sends a stable installation UUID by default and does not yet expose a dedicated user interface that disables only that identifier. Where applicable law requires consent before transmission, the product also needs an appropriate prior-choice mechanism; installing or continuing to use the software does not replace legally required separate consent.
We do not make decisions with legal or similarly significant effects about you solely from the data described in this policy.
12. Children
DSH Desktop is a tool for developers and people able to manage a local computing environment and is not directed specifically to children. Minors should use it with a guardian's guidance. If you believe we processed a child's personal data without satisfying applicable requirements, contact us so that we can investigate and take appropriate action.
13. Changes to this policy
When data categories, purposes, official recipients, or user choices change materially, we will update this policy, its effective date, and the repository history. Where law requires renewed notice or consent for a material change, we will complete that step before the relevant processing begins.
The Chinese and English versions of this policy have equal authority. If they diverge, read them together and notify us through the privacy contact email so that we can correct them.