← Back to KaylaDesk
Privacy Policy
Last updated: July 20, 2026 · Kaylasoft Solutions LLC
1. Overview
KaylaDesk is a remote desktop application developed by Kaylasoft Solutions LLC. We take privacy seriously. Our core principle: your sessions are private. KaylaDesk does not capture screenshots, record sessions, or analyze visual content from your remote sessions.
For the Hosted Service, we collect only the minimum data necessary to operate the service, prevent abuse, and comply with legal obligations. This Privacy Policy explains what we collect, why, and how we protect it.
2. Data We Collect
2.1 Account Data
- Email address — for account registration, notifications, and support
- Name — for account identification and support
- Password — hashed with bcrypt; never stored in plain text
2.2 Device Data
- Hostname — device name for identification in the portal
- Operating system — for compatibility and support
- Software version — for update management
- Device ID — cryptographic identifier for connection routing
2.3 Connection Data
- Source IP addresses — for connection routing and abuse prevention
- Device IDs of connected devices — for session logging
- Session start/end timestamps — for billing and audit
- Session duration — for analytics and billing
- Connection type — direct (P2P) or relayed
Connection logs are retained for 90 days, then automatically deleted.
2.4 Pattern Detection Data (Hosted Service Only)
To detect and prevent abuse, the Hosted Service performs automated pattern detection on connection metadata:
- Connection metadata — device IDs, IP addresses, timestamps, session duration, geographic region
- Behavioral patterns — connection frequency, sequential connections, geographic anomalies, device registration patterns
- Pattern analysis results — confidence scores for suspicious activity (no visual content analyzed)
KaylaDesk does NOT capture screenshots, record sessions, or process any visual content. The system operates solely on metadata, equivalent to standard server logging performed by every website and online service. No visual content from your remote sessions is captured, stored, or analyzed.
Pattern metadata is retained for 90 days for security and fraud prevention purposes, then automatically deleted. Metadata associated with confirmed abuse cases may be retained for up to 2 years for legal compliance and law enforcement cooperation.
2.5 Relay Network Data
By default, your device participates in the KaylaDesk peer relay network. When functioning as a relay, the following data is collected:
- Connection metadata — source IP, destination IP, bytes relayed, duration (standard network logging)
- Relay status reports — your device reports its availability, bandwidth capacity, and uptime to the KaylaDesk relay coordinator
Your device does NOT have access to the content of relayed traffic. All relayed data is encrypted end-to-end between the communicating peers. Your device receives encrypted bytes and forwards them. It has no decryption keys and cannot read, log, or store the content of relayed sessions.
Relay metadata is retained for 90 days for operational and security purposes, then automatically deleted. You can disable relay mode in Settings at any time.
2.6 Payment Data
Payments are processed by Stripe. We never see, store, or handle your credit card information. Stripe provides us with your subscription status and billing history. See Stripe's privacy policy at stripe.com/privacy.
3. What We Do Not Collect
KaylaDesk does NOT capture screenshots, record sessions, or store any visual content from your remote sessions. We do not have access to the content displayed during your remote desktop sessions. Our pattern detection system operates solely on connection metadata (IPs, timestamps, device IDs, session duration).
4. How We Use Your Data
- Operating the Service — routing connections, managing devices, billing
- Abuse prevention — detecting and preventing illegal use, banning violators
- Legal compliance — responding to valid law enforcement requests
- Support — responding to your support tickets and inquiries
- Security — detecting unauthorized access and protecting the Service
5. What We Do NOT Do
- Sell your data to anyone, ever
- Share your data with third parties for marketing or advertising
- Access your remote sessions or view your screen (except automated abuse detection)
- Record or store session content (except as described in Section 2.4)
- Use your data to train AI models (the abuse detection model does not learn from your sessions)
- Track your browsing, location, or behavior outside of KaylaDesk
- Share connection data with governments unless compelled by valid legal process
6. Data Retention
| Account data | Until account deletion |
| Connection logs | 90 days |
| Session pattern metadata (non-violating) | 24 hours |
| Abuse evidence | 2 years |
| Payment history | 7 years (tax compliance) |
| Banned device records | 2 years |
7. Data Security
- All connections are encrypted with TLS 1.2/1.3 and end-to-end DTLS+SRTP encryption
- Passwords are hashed with bcrypt (industry standard)
- API tokens are signed with JWT and expire automatically
- Rate limiting and fail2ban protect against brute force attacks
- Session monitoring data is stored encrypted at rest
- Database access is restricted to localhost only
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of your personal data
- Delete — request deletion of your account and associated data
- Export — export your data in a portable format
- Correct — request correction of inaccurate data
- Object — object to certain processing of your data
- Withdraw consent — request deletion of your metadata
To exercise these rights, contact privacy@kayladesk.com. We respond within 30 days. Account deletion can be performed directly in the customer portal at kayladesk.com/portal.
9. GDPR Compliance (EU/EEA Users)
Kaylasoft Solutions LLC is the data controller for the Hosted Service. Our legal basis for processing is:
- Contract — processing necessary to provide the Service you requested
- Legitimate interest — abuse prevention and security
- Legal obligation — compliance with law enforcement requests
- Consent — pattern detection metadata (can be deleted on request)
For GDPR complaints, you may contact your local data protection authority or the Information Commissioner's Office (ICO) at ico.org.uk.
10. CCPA Compliance (California Users)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact privacy@kayladesk.com.
11. Children's Privacy
KaylaDesk is not intended for use by children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@kayladesk.com and we will delete it.
12. Law Enforcement Requests
12.1 Legal Process Required
Kaylasoft Solutions LLC discloses user data to law enforcement only when compelled by valid legal process. We do not voluntarily disclose user data except as described below. All law enforcement requests must be:
- Sent in writing on official agency letterhead
- Directed to legal@kayladesk.com or by registered mail to Kaylasoft Solutions LLC, P.O. Box reference upon request
- Accompanied by valid legal authority (subpoena, court order, search warrant, or emergency certification)
- Signed by an authorized official (judge, prosecutor, or law enforcement officer)
We verify the authenticity of every request by contacting the issuing agency through independently verified contact information. We do not accept requests via informal channels (social media, phone, or email from non-official addresses).
12.2 Types of Legal Authority and Response
- Subpoena — We may disclose basic subscriber information (name, email, account creation date, device IDs)
- Court order (18 USC §2703(d)) — We may disclose connection logs, session metadata, and device information
- Search warrant — We may disclose session content, pattern metadata, analysis results, and all stored data for the identified user/device
- Emergency disclosure (18 USC §2702) — If we believe in good faith that an emergency involving immediate danger of death or serious physical injury requires disclosure, we may voluntarily provide information to law enforcement without legal process. This is reserved for imminent threats only and is documented in our transparency log.
12.3 Proactive Reporting
When our automated monitoring system detects evidence of illegal activity (fraud, scams, child exploitation, terrorism, or other crimes) with high confidence (above 80% AI certainty), the system flags the content for human review. No report is sent to any law enforcement agency automatically. All reports to law enforcement require manual review and explicit approval by Kaylasoft Solutions LLC management before any disclosure is made.
Important: The automated system builds evidence packages for internal review only. No report is sent to any law enforcement agency automatically. All reports require manual review and explicit approval by ownership. Failure to report flagged content is not negligent. See Terms of Service Section 26 (Non-Reporting Liability Protection) for full legal protections.
This process includes:
- Preserving pattern metadata and session data as evidence
- Notifying the FBI Internet Crime Complaint Center (ic3.gov) for fraud-related activity
- Notifying the National Center for Missing and Exploited Children (NCMEC) for child exploitation
- Notifying the Department of Homeland Security for terrorism-related activity
- Cooperating with law enforcement investigations of the reported user
All reports to law enforcement are manual and require explicit approval by ownership. The automated system only flags content for review — it does not send reports, notifications, or data to any external agency. We do not report legal but potentially abusive conduct.
12.4 User Notification
When legally permitted, we notify users of law enforcement requests for their data. Notification includes:
- The date of the request
- The requesting agency
- The type of legal authority used
- The general scope of data requested
We do NOT notify users when:
- A court order, statute, or legal process prohibits notification
- Notification would create imminent risk of death or serious physical injury
- The request is an emergency disclosure under 18 USC §2702
- Notification would jeopardize an active criminal investigation (per court order)
If a gag order is lifted, we will provide retroactive notification to affected users.
12.5 Request Tracking and Transparency
All law enforcement requests are logged in our internal tracking system, including:
- Date received and requesting agency
- Legal authority type and scope
- Whether we complied, partially complied, or objected
- Whether the user was notified
- Number of accounts affected
We publish an annual transparency report summarizing the number and type of law enforcement requests received, our response rate, and the number of users affected. Transparency reports are published at kayladesk.com/transparency.
12.6 Data Retention for Law Enforcement
Evidence preserved for law enforcement purposes is retained for up to 2 years, regardless of the standard retention schedule. If a legal hold is in place, data is preserved until the hold is lifted. Banned device records are retained for 2 years to prevent re-registration. See Section 6 (Data Retention) for the full schedule.
12.7 International Requests
Requests from foreign law enforcement agencies must be processed through the Mutual Legal Assistance Treaty (MLAT) framework or a valid United States court order. We do not directly comply with foreign government requests that bypass U.S. legal process, except in emergencies involving imminent danger to life.
12.8 Objection and Legal Challenge
Kaylasoft Solutions LLC may object to or narrow law enforcement requests when:
- The request is overly broad or lacks particularity
- The legal authority is insufficient for the data requested
- Compliance would violate these Terms, applicable law, or user rights
- The request seeks data that has been deleted under our retention policy
We will inform the requesting agency of any objection and seek to narrow the scope. If compelled by final court order, we will comply but document the objection.
13. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be posted with an updated "Last updated" date. Your continued use of the Service after any change constitutes acceptance of the updated policy.
14. Contact
- Privacy questions: privacy@kayladesk.com
- Data requests: privacy@kayladesk.com
- General: support@kayladesk.com
- Law enforcement: legal@kayladesk.com
Mail: Kaylasoft Solutions LLC, P.O. Box 841, Belleville, MI 48112-9998, USA
ATTN: KaylaDesk Product
© 2026 Kaylasoft Solutions LLC. All rights reserved.
California Consumer Privacy Rights (CCPA/CPRA)
California residents have the following rights:
- Right to Know: Request categories and specific pieces of personal information collected.
- Right to Delete: Request deletion of personal information, subject to legal exceptions (evidence retention).
- Right to Opt-Out: KaylaDesk does not sell personal information. To exercise opt-out rights, contact privacy@kayladesk.com.
- Right to Non-Discrimination: We will not discriminate for exercising privacy rights.
- Right to Correct: Request correction of inaccurate personal information.
Categories collected: identifiers (name, email, IP), commercial info (subscription, payment), internet activity (session logs, device IDs), visual info (pattern metadata for abuse detection only). Contact privacy@kayladesk.com. Response within 45 days.
GDPR — Legal Basis and EU Rights
For users in the EEA, UK, and Switzerland:
- Legal basis: Article 6(1)(b) GDPR (contract performance) for providing the Service; Article 6(1)(f) (legitimate interests) for abuse detection and security.
- Data subject rights: Access, rectify, erase, restrict, port, and object to processing.
- Breach notification: We notify the supervisory authority within 72 hours and affected individuals without undue delay per Articles 33-34.
- Data Processing Agreement: Business customers may request a DPA under Article 28 — contact legal@kayladesk.com.
- EU Representative: Contact eu-rep@kayladesk.com.
- Retention: Flagged pattern metadata: 2 years. Non-flagged: deleted within 24 hours. Account data: subscription duration plus 90 days.
- Complaints: Right to lodge complaint with your local data protection authority.