← Back to KaylaDesk

Privacy Policy

Last updated: July 20, 2026 · Kaylasoft Solutions LLC

1. Overview

KaylaDesk is a remote desktop application developed by Kaylasoft Solutions LLC. We take privacy seriously. Our core principle: your sessions are private. KaylaDesk does not capture screenshots, record sessions, or analyze visual content from your remote sessions.

For the Hosted Service, we collect only the minimum data necessary to operate the service, prevent abuse, and comply with legal obligations. This Privacy Policy explains what we collect, why, and how we protect it.

2. Data We Collect

2.1 Account Data

2.2 Device Data

2.3 Connection Data

Connection logs are retained for 90 days, then automatically deleted.

2.4 Pattern Detection Data (Hosted Service Only)

To detect and prevent abuse, the Hosted Service performs automated pattern detection on connection metadata:

KaylaDesk does NOT capture screenshots, record sessions, or process any visual content. The system operates solely on metadata, equivalent to standard server logging performed by every website and online service. No visual content from your remote sessions is captured, stored, or analyzed.

Pattern metadata is retained for 90 days for security and fraud prevention purposes, then automatically deleted. Metadata associated with confirmed abuse cases may be retained for up to 2 years for legal compliance and law enforcement cooperation.

2.5 Relay Network Data

By default, your device participates in the KaylaDesk peer relay network. When functioning as a relay, the following data is collected:

Your device does NOT have access to the content of relayed traffic. All relayed data is encrypted end-to-end between the communicating peers. Your device receives encrypted bytes and forwards them. It has no decryption keys and cannot read, log, or store the content of relayed sessions.

Relay metadata is retained for 90 days for operational and security purposes, then automatically deleted. You can disable relay mode in Settings at any time.

2.6 Payment Data

Payments are processed by Stripe. We never see, store, or handle your credit card information. Stripe provides us with your subscription status and billing history. See Stripe's privacy policy at stripe.com/privacy.

3. What We Do Not Collect

KaylaDesk does NOT capture screenshots, record sessions, or store any visual content from your remote sessions. We do not have access to the content displayed during your remote desktop sessions. Our pattern detection system operates solely on connection metadata (IPs, timestamps, device IDs, session duration).

4. How We Use Your Data

5. What We Do NOT Do

6. Data Retention

Account dataUntil account deletion
Connection logs90 days
Session pattern metadata (non-violating)24 hours
Abuse evidence2 years
Payment history7 years (tax compliance)
Banned device records2 years

7. Data Security

8. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights, contact privacy@kayladesk.com. We respond within 30 days. Account deletion can be performed directly in the customer portal at kayladesk.com/portal.

9. GDPR Compliance (EU/EEA Users)

Kaylasoft Solutions LLC is the data controller for the Hosted Service. Our legal basis for processing is:

For GDPR complaints, you may contact your local data protection authority or the Information Commissioner's Office (ICO) at ico.org.uk.

10. CCPA Compliance (California Users)

California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact privacy@kayladesk.com.

11. Children's Privacy

KaylaDesk is not intended for use by children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@kayladesk.com and we will delete it.

12. Law Enforcement Requests

12.1 Legal Process Required

Kaylasoft Solutions LLC discloses user data to law enforcement only when compelled by valid legal process. We do not voluntarily disclose user data except as described below. All law enforcement requests must be:

We verify the authenticity of every request by contacting the issuing agency through independently verified contact information. We do not accept requests via informal channels (social media, phone, or email from non-official addresses).

12.2 Types of Legal Authority and Response

12.3 Proactive Reporting

When our automated monitoring system detects evidence of illegal activity (fraud, scams, child exploitation, terrorism, or other crimes) with high confidence (above 80% AI certainty), the system flags the content for human review. No report is sent to any law enforcement agency automatically. All reports to law enforcement require manual review and explicit approval by Kaylasoft Solutions LLC management before any disclosure is made.

Important: The automated system builds evidence packages for internal review only. No report is sent to any law enforcement agency automatically. All reports require manual review and explicit approval by ownership. Failure to report flagged content is not negligent. See Terms of Service Section 26 (Non-Reporting Liability Protection) for full legal protections.

This process includes:

All reports to law enforcement are manual and require explicit approval by ownership. The automated system only flags content for review — it does not send reports, notifications, or data to any external agency. We do not report legal but potentially abusive conduct.

12.4 User Notification

When legally permitted, we notify users of law enforcement requests for their data. Notification includes:

We do NOT notify users when:

If a gag order is lifted, we will provide retroactive notification to affected users.

12.5 Request Tracking and Transparency

All law enforcement requests are logged in our internal tracking system, including:

We publish an annual transparency report summarizing the number and type of law enforcement requests received, our response rate, and the number of users affected. Transparency reports are published at kayladesk.com/transparency.

12.6 Data Retention for Law Enforcement

Evidence preserved for law enforcement purposes is retained for up to 2 years, regardless of the standard retention schedule. If a legal hold is in place, data is preserved until the hold is lifted. Banned device records are retained for 2 years to prevent re-registration. See Section 6 (Data Retention) for the full schedule.

12.7 International Requests

Requests from foreign law enforcement agencies must be processed through the Mutual Legal Assistance Treaty (MLAT) framework or a valid United States court order. We do not directly comply with foreign government requests that bypass U.S. legal process, except in emergencies involving imminent danger to life.

12.8 Objection and Legal Challenge

Kaylasoft Solutions LLC may object to or narrow law enforcement requests when:

We will inform the requesting agency of any objection and seek to narrow the scope. If compelled by final court order, we will comply but document the objection.

13. Changes to This Policy

We may update this Privacy Policy at any time. Material changes will be posted with an updated "Last updated" date. Your continued use of the Service after any change constitutes acceptance of the updated policy.

14. Contact

Mail: Kaylasoft Solutions LLC, P.O. Box 841, Belleville, MI 48112-9998, USA
ATTN: KaylaDesk Product

© 2026 Kaylasoft Solutions LLC. All rights reserved.

California Consumer Privacy Rights (CCPA/CPRA)

California residents have the following rights:

Categories collected: identifiers (name, email, IP), commercial info (subscription, payment), internet activity (session logs, device IDs), visual info (pattern metadata for abuse detection only). Contact privacy@kayladesk.com. Response within 45 days.

GDPR — Legal Basis and EU Rights

For users in the EEA, UK, and Switzerland: