Trust Center

Your data, your choices, and the controls behind NESKTOP

This page explains what NESKTOP stores, how each product mode works, and safeguards supported by reviewed implementation evidence. No online system can promise absolute security.

Published safeguard evidence last reviewed 21 July 2026. Infrastructure or independent-review claims are omitted until verified.

Current safeguards

What protects NESKTOP users today

Each statement below is limited to a control found in the current source. Infrastructure facts are published only after production verification.

Current safeguard

Your account password is not stored as readable text

Password accounts use a one-way password hash. NESKTOP cannot recover the original password from that hash.

Evidence reviewed: Argon2id password hashing with transparent legacy bcrypt migration

Current safeguard

Privileged administration has additional controls

Administrator access uses mandatory authenticator verification, hashed recovery codes, throttling, lockout and session invalidation controls.

Evidence reviewed: Admin MFA and audit modules

Source evidence last reviewed 21 July 2026.

Plain-language data map

What NESKTOP stores

Storage changes with the product mode you choose. Provider passwords are not a widget setting.

Product modeWhat is storedProtection and controlDefault retention
Guest canvasCanvas, links, folders, appearance and preferences on this device. Necessary request logs and consented analytics may still apply.No account sync. Clear it with browser controls or import it into an account when you choose.Until browser data is cleared.
Signed-in accountIdentity/profile, one-way password hash, preferences, layouts, bookmarks, folders, notes and tasks.Private by default, access-controlled, exportable and deletable. Ordinary content is not described as end-to-end encrypted.For the account lifetime, followed by deletion under the published account-deletion process.
TeamsMemberships, roles, invitations, shared canvases, assignments, messages, presence and security/audit events.Invitation and role-based access. Exports must not reveal another member's private data.For the membership or organization lifetime, subject to the applicable legal notice.
IntegrationsProvider/account reference, granted scopes, status and timestamps; encrypted OAuth credentials in a separate vault record.Widgets receive a connection ID, not a provider password or raw token. Disconnect deletes the active credential and attempts provider revocation.Until disconnect or account deletion.
Extension and desktopSettings, cache and a paired device credential.Optional browser permissions; desktop persistence is allowed only with OS secure storage.Until sign-out, revoke, removal/uninstall or device-data clearing.
Public sharingOnly explicitly published profile fields and a sanitized read-only canvas snapshot.Clear publish and unpublish controls. Private integration data is excluded.Until unpublish, revocation or account deletion; external search/cache copies may persist.
OperationsRedacted operational errors, pseudonymized consented analytics, security events, support records and billing-provider references when activated.No raw payment-card storage. Secrets and sensitive URL/query values are prohibited from logs.According to the retention periods in the Privacy Policy and applicable legal obligations.

Report a security or privacy concern

Please avoid including passwords, access tokens, private keys or unnecessary personal data. We will acknowledge a responsible report through the published contact route.

Email the security contact

Legal and product notices