Skip to content

Security and data FAQ

Quick answers about where your data lives, what Laya stores, credential handling, two-factor authentication and revoking access.

Last updated

Short answers on data handling and account security. For the full picture, start with How Laya protects your data.

Your data

Where is my data stored?

Laya is operated from the United Kingdom and hosted on Amazon Web Services in the United States (US East). International transfers are covered by Standard Contractual Clauses and the UK IDTA. See How Laya protects your data.

What does Laya store for a mirrored board?

A durable, synced copy of each item on the boards you choose to connect — fields such as title, status, assignees and dates — kept until you disconnect, when Laya deletes its mirror. Comments are not copied into Laya: they are read live from the source tool when you open an item. See Mirror vs import.

How long is my data kept?

For as long as your account exists — nothing is auto-purged on a schedule. You can request erasure by emailing privacy@laya.net; requests are answered within one month.

Is my content used to train AI models?

No. Laya does not sell your data and does not use your content to train AI models. AI features send only the content you choose to run them on to the AI provider.

Accounts and access

How are passwords and connection credentials handled?

Passwords are hashed and never stored in plaintext. Credentials for connected tools — OAuth tokens and API keys — are encrypted at rest with AES-256-GCM and are never returned by the API once saved. See Provider permissions and scopes.

Does Laya support two-factor authentication?

Yes — it is opt-in from the Security page in your account menu. Passkeys (Face ID, Touch ID, Windows Hello or a security key) are the primary factor, an authenticator app is the fallback, and single-use recovery codes cover you if you lose both. Once on, it applies to every sign-in route, including magic links and the "Continue with" buttons. See Two-factor authentication.

How do I revoke access?

The Security page lists your Active sessions with a Sign out button on every other device. Linked sign-in identities are managed at Connected apps, workspace API tokens are revoked from Settings → Access tokens (Owner only), and tool connections are disconnected from workspace Settings. See Sessions and account security.

How do I report a security issue?

Email support@laya.net with the details and we will take it from there. For privacy-specific requests, such as data erasure, contact privacy@laya.net.

Still stuck?

Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.

Contact support