Trust
Security & Trust Center
Last updated: March 6, 2026
Account Security
- Password hashing: Passwords are stored as secure hashes, never plaintext.
- Email verification: Password login requires verified email ownership.
- Magic links: Sign-in links reduce password reuse risk and support account recovery.
- Bot protection: CAPTCHA checks are applied on registration and login-link requests.
Data Controls
- Export your data: Download a JSON export anytime from account settings.
- Delete your account: Permanently delete your account and related data from account settings.
- No ad tracking cookies: We do not use third-party advertising trackers.
- Private desktop screenshots: Optional captures use opaque private object keys and stream only after owner authorization; no public or browser-signed object URLs are issued.
- Encrypted offline queue: Failed desktop batches use AES-256-GCM, with the queue key protected by operating-system secure storage. The queue expires after 24 hours and is capped at 250 MB.
Transparency
Report a Security Issue
Report vulnerabilities or security concerns to
security@nomadti.me.