How Laya protects your data
Where your work lives, how credentials are encrypted, what Laya keeps, and what it never does with your content.
Last updated
On this page
Teams keep real work in Laya — native boards, docs, and connected boards mirrored from other tools. This article explains in plain terms where that data lives, how it is protected, and what Laya will never do with it.
Where your data lives
Laya stores two kinds of product data:
- Native data — boards, work items, docs, comments and attachments you create directly in Laya. Laya hosts this on Amazon Web Services in the United States (us-east-1), with email delivered via Amazon SES.
- Connected (mirrored) data — when you connect Jira, Azure DevOps, monday.com, GitHub or GitLab, Laya imports and stores a mirror of the boards you choose: a durable, synced copy of each item's core fields — title, status, assignees, dates and links — kept until you disconnect the board. Comments are read live from the source tool rather than stored in the mirror, and attachments are not part of ongoing sync — on Jira they are viewed live from Jira, and only a one-off Jira import copies them into Laya.
Laya is operated from the United Kingdom and data is processed in the United States under Standard Contractual Clauses and the UK IDTA. The full list of sub-processors is published in the Privacy Policy.
Mirrors and disconnecting
You choose which boards Laya mirrors, and when you disconnect a board Laya deletes its mirror of it. Items you imported into native Laya boards remain as ordinary Laya items — they simply stop syncing. See Disconnecting safely for exactly what stays and what goes.
Credentials and passwords
- Credentials for connected tools — OAuth tokens, API tokens and keys — are encrypted at rest with AES-256-GCM, and are never returned by the API or shown again in the app once saved.
- Webhook secrets are encrypted at rest in the same way.
- Your Laya password is hashed, never stored in plain text.
Data retention
Laya keeps your data for as long as your account exists. There is no automatic expiry and no background job that deletes your content, your workspaces or your history after a set period.
- Deactivating your account hides it but keeps your data — a workspace admin can restore it. See Sessions and account security.
- Erasure is by request: email privacy@laya.net and Laya answers within one month. Deleted accounts have a 30-day recovery window, after which the account is anonymised in place so boards keep a stable, anonymous author on your old items.
What Laya never does
- Laya does not sell your data.
- Laya does not use your content to train AI models. Where AI features are available, the AI provider receives only the content you choose to run them on.
- Analytics run only on the marketing site, only after you accept them — and a Global Privacy Control or Do Not Track signal from your browser stops them loading at all.
Public share links
Public links for boards, docs and roadmaps are secret token URLs: the token in the link is the only credential, so anyone who has the link can view what you shared. Treat the link itself as the key. Public views are read-only and rate-limited.
- Board shares let the owner control which columns and card fields are visible, and whether viewers can open a read-only detail view.
- Links can be revoked — a revoked link shows an error instead of the content.
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.