Overview
NimbleDesk is a remote desktop application operated by Gudka Ventures LLC (“NimbleDesk,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect when you use our desktop app, mobile app, web client, and website (together, the “Service”), how we use it, and the choices you have.
NimbleDesk facilitates remote connections between devices. Where possible, remote desktop video, audio, and control data are transmitted directly between participating devices using encrypted peer-to-peer connections. When a direct connection cannot be established, encrypted traffic may be routed through relay infrastructure. NimbleDesk does not store recordings of remote desktop video, audio, keyboard input, mouse input, or controller input as part of normal operation.
Information We Collect
Account information
When you create a NimbleDesk account, we collect your email address and a display name you choose. Authentication is handled by our identity provider (AWS Cognito); we never see or store your password in plaintext.
Device information
When you register a device (for example, the computer you want to remote into), we store a device name, platform, operating system version, app version, and device model string, along with timestamps such as when the device was added and when it last connected. This lets you identify and manage your devices from the app.
Connection and usage information
We store the connections (“friends”) you’ve added, pending session invitations, active session state while a remote session is in progress, and any custom control layouts you create. We also record aggregate relay bandwidth usage (in bytes) on a monthly basis to enforce plan limits — we do not inspect or retain the content of that traffic.
Payment information
If you subscribe to NimbleDesk Premium, billing is handled by Stripe. We do not collect or store your card number or billing address — Stripe processes that information directly. We store a reference to your Stripe customer record and your subscription status so we can provide the features you’ve paid for.
Device-local data
Optional per-device connection passwords are hashed on your device and stored locally (in your browser’s local storage, the OS keychain, or equivalent secure storage), keyed to your account and device. These hashes are never sent to or stored on our servers.
Information we do not collect
We do not use analytics, advertising, or crash-reporting SDKs of any kind, and no third-party trackers are embedded in our apps or website. We do not log the IP addresses of your requests, and our desktop app does not transmit diagnostic or crash logs to us — any local log files created by the desktop app stay on your own machine.
How We Use Information
We use the information described above to:
- Create and secure your account, and authenticate you across the desktop, mobile, and web clients
- Establish and facilitate remote desktop connections between your devices, including signaling and, when necessary, relaying encrypted traffic
- Let you manage your registered devices, connections, and control layouts
- Provide, maintain, and improve the Service, and troubleshoot technical issues
- Process payments and manage subscriptions through Stripe
- Enforce plan limits, such as monthly relay bandwidth allowances
- Communicate with you about your account, such as verification and password-reset emails sent by our identity provider
How Remote Sessions Work
When you connect to one of your devices, NimbleDesk’s servers help the two devices find and authenticate each other (a process called signaling) and, when a direct peer-to-peer connection isn’t possible, provide relay infrastructure so encrypted traffic can still reach its destination. In both cases, the video, audio, and input data that make up your remote session are encrypted and are not readable, recorded, or stored by NimbleDesk. We only track the total volume of relayed traffic (in bytes) for the purpose of enforcing plan limits.
Sharing of Information
We do not sell your personal information. We share information only with:
- Service providers who help us operate NimbleDesk, such as Amazon Web Services (hosting, authentication, and relay infrastructure) and Stripe (payment processing)
- Other NimbleDesk users, but only to the extent you choose to share (for example, your display name and friend code when you add a connection)
- Law enforcement or other parties when required by law, or to protect the rights, property, or safety of NimbleDesk, our users, or others
Account and Data Deletion
You may delete your NimbleDesk account from the account settings within the NimbleDesk app. Step-by-step instructions, and a list of what data is deleted or kept, are on our account deletion page. When an account is deleted, we delete or anonymize personal information associated with the account, including account information, registered devices, connections, invitations, and other account-related data, except where retention is reasonably necessary for legal, security, fraud-prevention, accounting, or other legitimate purposes. Certain server and security logs may remain for a limited retention period before being automatically deleted.
Data Retention
We retain account and device information for as long as your account is active. Relay bandwidth usage records are retained for a limited period for auditing purposes and are then automatically deleted. Pending session invitations and temporary connection state expire automatically, typically within minutes to hours. If you delete your account, we delete the associated data as described above under “Account and Data Deletion.”
Data Security
We use industry-standard measures to protect your information, including encryption of data in transit for remote sessions and account authentication via AWS Cognito. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Children's Privacy
NimbleDesk is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.
International Users
NimbleDesk is operated from the United States, and information we collect is processed and stored in the United States. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.
Your Choices and Rights
You can review and update your account information, manage your registered devices and connections, and delete your account at any time from within the app. Depending on where you live, you may have additional rights over your personal information, such as the right to request access to, correction of, or deletion of your data. You can exercise these rights by deleting your account as described above or by contacting us using the details below.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at support@nimble-desk.com. For the terms that govern your use of NimbleDesk, see our Terms of Service.