LegalNaytto
Privacy Policy
Naytto lets you use your own computers from a web browser. This policy explains what Naytto keeps about you, why, for how long, who helps us run the service, and how to get a copy of your data or delete it.
The controller is Relyt Works LLC, 1925 Lovett Avenue, STE 7 278, Bismarck, North Dakota 58504, United States. Contact: privacy@naytto.com.
What Naytto never stores
The picture of your screen, what you type, pointer movements, clipboard contents and the files you transfer are encrypted between your browser and your computer (WebRTC DTLS-SRTP and DTLS). They don't pass through Naytto's servers, and the relay forwards encrypted packets it cannot read. Naytto's service identifies your computer for you, so it is trusted to connect you to the right one. Naytto does not record sessions. The support report on the Computers page is created in your browser and is sent only if you choose to send it yourself.
What Naytto stores
| Data | Why | How long |
|---|---|---|
| Account: email address, account ID, when the account was created, when you were invited, whether an authenticator app is on | To identify you, sign you in and email you security notices | Until you delete the account |
| Sign-in methods: passkey names, dates and public keys; the authenticator app secret and backup codes, encrypted; email sign-in codes, hashed | To sign you in and recover your account | Until you remove them or delete the account. Email codes expire after 10 minutes and are removed within an hour. |
| Signed-in browsers: IP address, browser user agent, when you signed in and were last active, and how you signed in | To keep you signed in, show you where you're signed in and detect abuse | Until you sign out or the sign-in ends (after 3 idle days, 14 days at most, or 1 day on a shared computer), then removed within an hour |
| Computers: each computer's name, ID, date added, a hash of its credential, when it was last seen, whether its permissions are granted, its Keep reachable state, and the ID and outcome of its latest remote session. While it is connected, its public IP address (or IPv6 /64). | To show your computers and connect you to them | Until you remove the computer or delete the account. The IP address is kept only while the computer is connected. |
| Activity: sign-ins; computers added, renamed or removed; remote sessions started and ended, with how they ended. For sign-ins, computers added and sessions started, also the IP address, country and browser user agent. | To show you recent activity, and to investigate security problems and abuse | 365 days. After you delete the account, 90 days, so deleting an account can't erase recent evidence of abuse. |
| Suspension: if we suspend the account, the reason and date | To prevent abuse and let you appeal | Until the account is reinstated or deleted |
| Abuse reports: reports about an account or computer: the reason, the reported account and email, the computer, the reporter's contact address and message, and for reports from the public page, the reporter's IP address and country | To investigate and stop unauthorized access and scams | 365 days, including after the reported account is deleted |
| New-signup checks: the network (IP address or IPv6 /64) of each new signup, not linked to an account | To limit mass signups | 1 day |
| Relay usage: traffic per day, and your usage warning setting | To enforce plan limits and warn you | 365 days, or until you delete the account |
| Email counts: how many emails we sent your account each month | To manage the service's costs | Until you delete the account |
| Support and abuse email: messages you send to support@, privacy@, security@ or abuse@naytto.com or through Contact support, and our replies | To answer you | As long as needed to handle the request and any follow-up |
| Service logs: request details such as the time, path, result and the network's location, and error messages | To operate and debug the service | 7 days (Cloudflare Workers Logs) |
| Email delivery records: recipient, subject and delivery status of the emails we send you | To confirm that sign-in codes and notices were delivered | 31 days (Cloudflare Email Service) |
Database backups (point-in-time recovery) keep changes, including deletions, for 30 days. Deleted data leaves the backups within 30 days of its deletion.
Naytto does not sell personal data or show advertising. The Naytto app (app.naytto.com) uses no analytics or tracking. The website naytto.com uses Google Analytics only if you agree to it (cookies). We disclose data to law enforcement only in response to valid legal process.
Legal bases (GDPR and UK GDPR)
- Performing our contract with you: your account, sign-in, computers, sessions and relay usage.
- Consent: Google Analytics on the website. You can withdraw it at any time.
- Legitimate interests in keeping the service secure and working, and in preventing unauthorized access and scams: activity, suspensions, abuse reports, new-signup checks, service logs, the human check, and security notices.
- Legal obligations: records we must keep, such as billing and tax records once paid plans exist.
Cookies and browser storage
The Naytto app uses only strictly necessary cookies, so it asks for no cookie consent:
Cookie (__Secure-better-auth. prefix in production) | Purpose | Lifetime |
|---|---|---|
session_token | Keeps you signed in | 3 days after last use, or until the browser closes on a shared computer |
dont_remember | Marks a sign-in on a shared computer | Until the browser closes |
two_factor | Carries an unfinished sign-in to the authenticator step | A few minutes |
passkey challenge | Carries a passkey ceremony | A few minutes |
The app also keeps settings in your browser's local storage: display mode, keyboard layout, list or map view, whether this is a shared computer, whether you dismissed the passkey prompt, and the connection route last used to each computer. They never leave your browser.
Before sending an email sign-in code, Naytto runs Cloudflare Turnstile, a human check that reads your IP address, browser details and page to block automated abuse. Cloudflare describes this processing as strictly necessary to detect and block bots, and it sets no cookie.
Website analytics
The website naytto.com uses Google Analytics. It first asks whether you accept analytics, and Google Analytics loads only after you choose Accept. If you choose Reject, or don't choose, the website sets no analytics cookies and sends nothing to Google. Your choice is stored in your browser, and you can change it at any time from Cookie settings at the bottom of every page.
If you accept, Google Analytics sets the _ga and _ga_<ID> cookies (up to 2 years) and receives the pages you visit, how you arrived, your browser and device type, and your approximate location from your IP address. Google Analytics does not store IP addresses. We use it only to understand how people find and use the website. Google signals and advertising data sharing are off, and Google keeps the data for 14 months.
Google Search Console tells us how naytto.com appears in Google Search. It receives no data from visitors to the website.
Who processes data for us
Naytto uses the subprocessors listed here. Cloudflare hosts the service, relays connections, sends email and provides the human check. Google Workspace receives the email you send to our support, privacy, security and abuse addresses, including Contact support messages and abuse reports. Google Analytics measures the website for visitors who accept it.
International transfers
Naytto runs on Cloudflare's global network, and our database is hosted by Cloudflare in the United States. Email to our addresses is handled by Google Workspace in the United States. Data from the EU, EEA, UK and Switzerland is transferred to both companies under their data processing terms, which incorporate the EU Standard Contractual Clauses with the UK and Swiss adaptations, and under their certifications to the EU-US Data Privacy Framework and its UK and Swiss extensions. Naytto does not offer EU data residency.
Your rights
Wherever you live, you can:
- Get a copy of your data. In the app, go to Account → Your data → Download my data. The file includes your account, the names and dates of your sign-in methods, signed-in browsers, computers, activity, and relay usage. It leaves out secrets such as keys, codes and credential hashes, the live connection state that is used only during a session, and the records that only Cloudflare holds (service logs and email delivery records). Contact us for those. If it's been more than 10 minutes since you signed in, or if you signed in with only an email code while you have a passkey, Naytto first asks you to sign in again.
- Delete your account. Go to Account → Delete account. Naytto removes your computers first, which ends their sessions, and then removes the rest of your data immediately. The exceptions expire on the schedule above: activity (90 days after deletion), abuse reports, support email, service logs, email delivery records and backups. A record of the deleted account's ID is kept for 35 days, so restoring a backup can't bring the account back.
- Correct your data. You can rename computers and passkeys in the app. To change your email address, contact us.
- Object, restrict processing, or complain. Contact us. In the EU, EEA or UK, you can also complain to your data protection authority.
California (CCPA/CPRA): Naytto does not sell or share personal information for cross-context behavioral advertising and does not use sensitive personal information to infer characteristics. Google Analytics on the website runs only with your consent, as our service provider, with advertising features off. The categories we collect are identifiers (email, IP address, account and computer IDs), internet activity (sign-in and session activity, service logs) and approximate location derived from IP address. We collect them for the purposes and retention periods above. You have the right to know, delete and correct, and Naytto will not discriminate against you for using these rights.
We answer requests within 30 days.
Children
Naytto is not intended for children under 16, and we don't knowingly collect their data.
Changes
We'll email account holders before a material change takes effect. Last updated: 2026-09-25.