Data processing in DeskCapsule
Last updated: August 28, 2026
This section explains what data DeskCapsule processes, where exactly it is processed, and what is passed to third parties. By installing or using the application, you agree to these terms.
1. Who we are
Data Controller: Individual Entrepreneur A. Kalendzhyan (SOVREST). Contact: info@sovrest.com, Telegram: @sovrestbot.
2. What the application does and what is free in it
DeskCapsule is a Windows utility. Keyboard layout switching, clipboard history, screenshots, notes, on-device translation and on-device speech recognition (a local Whisper model) work free of charge and in any licence state.
Your content — texts, images, notes, speech — does not leave your computer when these features are used. The application itself reaches the network in exactly two cases, both described below: once a day it checks the current version number and, if you ask it to, it downloads model files. Neither of these transmits your data.
A subscription unlocks three cloud features: translation, AI chat and voice input, all through our server. Each of them runs only on your explicit action and is described below.
3. What is processed on your computer and does NOT leave it
Clipboard history, screenshots, notes are stored locally and are never transmitted. They are not automatically added to the cloud features.
On-device translation and on-device speech recognition (ONNX Runtime, Whisper.net) run on your device. The text and audio being processed stay on your computer and are not sent to our servers.
Model files are not part of the distribution package and are downloaded on your explicit action, when you enable on-device translation or on-device speech recognition. On-device translation packages are downloaded from SOVREST object storage (storage.yandexcloud.net, Russia); on-device speech recognition models are downloaded from huggingface.co (Hugging Face, Inc., USA), so that download leaves the territory of the Russian Federation. Neither download transmits your text, audio, licence key or installation identifier: the host sees only the connection itself — the IP address, the time, and which public file was requested. The size and the SHA-256 checksum of every file are embedded in the application and are verified before a model is installed and again before it is used.
Licence key and tokens are stored on your computer in the protected Windows store (DPAPI, current user), so that the licence can be verified offline.
Installation identifier (device_id) is a random UUID created once at installation. It is not derived from your hardware characteristics: it is not a serial number, not a MAC address and not a hardware fingerprint.
4. What is sent to our server
Update check. No more than once a day the application asks our server for the current version number. The request contains only the product code and the version of the installed application. The installation identifier, the licence key and the tokens are not transmitted, and the request is made regardless of whether you hold a licence. You can disable update checks by blocking the application's network access with your operating system.
Everything else is sent only when you invoke a cloud feature:
Translation. The text you typed into the translator field and the language codes are sent after you press the button. Neither the clipboard history nor your notes are added.
AI chat. Your current question and a limited conversation context held in the application's memory. The chat history lives in memory only and is erased when you start a new chat and when you exit the application. Attachments from other sections are not transmitted.
Voice input. A single completed audio recording from the microphone, which you started and stopped manually. This is not a stream and not a background recording — the application does not listen to the microphone continuously. The audio and the transcript live in memory; in normal operation no file is saved to disk.
Licence verification. The licence key, the installation identifier and the token — on activation, renewal and deactivation.
5. Third-party providers (sub-processors)
The cloud features are performed with the help of third-party artificial intelligence services. The application reaches them only through our server and never directly:
- Translation and AI chat — OpenRouter, Inc. (USA), a model routing service; the request is forwarded to a language model chosen by us.
- Speech recognition — Groq, Inc. (USA), in Zero Data Retention mode.
Your voice is not used to identify you as a person: the recording is processed solely to convert speech into text; biometric characteristics (a voiceprint and the like) are neither extracted nor stored.
Separately from the cloud features, the application downloads model files from the hosting providers named in section 3. They do not process your content and receive only information about the connection itself.
6. Cross-border transfer
The providers of the cloud features are located outside the Russian Federation (USA), so the data passed to them leaves the territory of the Russian Federation. By starting to use a cloud feature, you consent to such a transfer.
The download of on-device speech recognition models from huggingface.co (USA), described in section 3, also leaves the territory of the Russian Federation. Your content is not transmitted during that download — only information about the connection. The download is performed on your explicit action; you may choose not to use on-device speech recognition, and this does not affect the other features of the application.
Do not type or dictate personal data — your own or that of third parties (full names, phone numbers, addresses, passport and payment details).
7. Retention
The text and audio that are transmitted are processed on the fly and are not stored on our servers after the operation completes; we do not log their content.
Our service logs record only technical information, without text or audio: licence and application identifiers, request size, processing cost, status, duration, IP and origin — they are kept for 90 days for billing and abuse protection.
Licence activation records (key, device identifier, timestamps) are kept for as long as the licence exists: they are what limits the number of devices.
The update check request is handled as an ordinary web server request and is not linked to your licence or your installation.
8. Telemetry and advertising
There is no telemetry. The application contains no advertising or analytics SDKs. Local diagnostics are limited to technical information (time, event category, error type) — your text, audio, tokens and the content of responses do not go into it.
9. How to opt out of the cloud features
Voice input is off by default and has to be enabled separately; instead of it you can use the keyboard or on-device recognition, which does not reach the network while it works. You can simply not use cloud translation and AI chat — this does not affect the free capabilities of the application.
10. Deletion and your rights
You have the right to request information about the processing of your personal data, its correction or its deletion, by contacting us at the addresses above.
You can deactivate the licence, freeing the device slot, and uninstall the application. On uninstallation:
- the Windows startup entry is always removed;
- the application asks whether to delete your local data — notes, clipboard history, screenshots and downloaded models;
- the licence key and the device binding are deliberately kept, even if you agreed to delete everything else. This is done so that reinstalling does not require activating again and does not take up a second device slot. You can delete them by an explicit action in the application settings, before uninstalling it.
The portable version ships without an uninstaller, so deletion there is performed by the same action in the settings.
Deleting local files does not delete records on our servers; to do that, contact us at the addresses above.
This document covers the DeskCapsule product only. The general terms of use of the SOVREST website are set out in the public offer and the privacy policy at sovrest.com.
Operator, lawful basis and rights — edition 3.0
Published: October 2, 2026. Operator: Individual Entrepreneur Kalendzhyan Artur Eduardovich (SOVREST), INN 235503700740, OGRNIP 326237500273341. Privacy contact: info@sovrest.com. Site-wide Privacy Policy and Terms.
This section supersedes earlier general wording on consent, response deadlines and operator identity in this policy. Installation, browsing or continued use alone is not personal-data consent. Processing necessary for the requested function/licence has a contractual basis; required consent is a separate affirmative action. Advertising and optional analytics require separate consent.
Processing-information requests: 10 working days, extendable by 5 working days with a reasoned notice. Confirmed inaccuracies are corrected, and confirmed unlawfully obtained/unnecessary data destroyed, within 7 working days. Unlawful processing stops within 3 working days; where it cannot be made lawful, destruction follows within 10 working days. Consent withdrawal or purpose completion: stop processing/destroy within 30 days unless another lawful basis applies. Stop-processing requests: 10 working days, extendable by 5 working days with a reasoned notice and statutory exceptions (Art. 20–21 of 152-FZ).
Mandatory settlement records are kept for applicable tax deadlines to the necessary extent; key delivery does not justify indefinite retention of all user data. Core-infrastructure backups have restricted access and rotation up to 190 days; recorded erasure requests are reapplied after restoration. See Privacy Policy, §5 and §9.
Where a function described above sends text/audio to OpenRouter, Groq, Alibaba Cloud/Qwen or the selected model provider, personal data in the content may be transferred across borders. Before enabling a route, identify its recipient, countries, lawful basis and safeguards and comply with Art. 12. User consent and policy publication do not replace a separate Roskomnadzor notification. External zero-retention promises apply only with a confirmed contract and route settings. Do not send special-category, biometric or third-party data without a lawful basis.