Legal
Privacy Policy
Last updated August 21, 2026
Novius Now is a business platform for managing fleets of computers. Running it necessarily involves handling account, support, and managed-device information. This policy explains exactly what we collect, why, how long we keep it, and the choices you have — in plain language, grounded in what the product actually does.
Who we are & scope
Novius Now (“we”, “us”) provides an endpoint-management and IT support platform: a web console at noviusnow.com, native apps for iPhone, iPad, Apple Watch, and Mac, and a management agent that organizations install on the Windows computers they manage. You can reach us any time at [email protected].
Novius Now is sold to organizations. Most information in the platform — computer inventory, support conversations, approval activity — is there because a customer organization put its computers under management. We process that information on the organization’s behalf and under its direction. If your computer is managed by your employer or IT provider, questions about how your information is handled should go first to that organization; this policy explains what the platform itself does.
Account & sign-in information
- Account details. Your email address, a securely hashed password (Argon2 — we never store the password itself), your role, and your organization membership.
- Multi-factor credentials. Authenticator-app (TOTP) secrets stored encrypted; passkey public keys (the private key never leaves your device); one-time recovery codes stored only as hashes.
- Sessions and sign-in records. Each sign-in creates a session record with the IP address and browser/app identifier (user agent) it came from. If you choose “remember this browser”, we keep a trusted-device record (with IP and user agent) for 30 days. Sign-ins, failed sign-ins, and security-relevant actions are written to an audit log that also records the source IP address.
Managed-computer information
The agent on each managed computer reports operational inventory so technicians can support it:
- Identity and hardware: hostname, manufacturer, model, serial number, CPU, memory, disks, OS version, last boot time, uptime, and online/offline status.
- Network: public IP address, private IP addresses, and MAC addresses.
- People and accounts: the Windows usernames currently signed in, and the computer’s local accounts and administrator-group members (account names, identifiers, enabled state, last logon).
- Software and patching: installed applications and versions, and Windows Update status.
- Security posture: disk-encryption status, application-control state, and related security signals.
- Escrowed recovery secrets (optional, per organization): a BitLocker recovery key and Windows product key can be escrowed encrypted; viewing one requires an administrator and is recorded in the audit log. The platform also mints and stores (encrypted) break-glass recovery credentials so a locked-out computer can be recovered.
Approvals & security events
When someone on a managed computer asks to run something with administrator rights, the request carries the evidence a technician needs to decide: the requesting Windows username, the program’s path and publisher details, its SHA-256 fingerprint, the file-reputation verdict, and any reason the requester typed. We keep the request, the decision, who made it, and when. Related security telemetry — blocked or observed execution attempts, protected-folder events, and detections — is retained on shorter clocks (see retention). For file-reputation checks we send only the file’s SHA-256 fingerprint to VirusTotal — never the file itself, and never who ran it or where.
Support chats & content you create
- Support chat between a technician and the person at a managed computer, and technician chat between team members, are stored on our servers as written, along with sender, timestamps, and delivery/read receipts. Chat is not end-to-end encrypted; it has to reach the other side through our servers.
- Searches in the console’s universal search are processed to return results and are not saved in the product database. Like every request, a search may appear briefly in routine server request logs, which are small and rotate automatically.
- If you email us, we keep the correspondence. If you request access to the product, we store the name and email you provide (and a referral code if you used one) to manage the waitlist; your IP address is used transiently for rate limiting and is not stored with your entry.
Remote sessions & background tools
- Administrative commands. Commands technicians run on managed computers (for example PowerShell) are recorded with their full text and output, alongside who ran them — this is the product’s accountability trail.
- Background tools (Backstage). Live sessions for PowerShell, services, processes, registry, Device Manager, and file transfer are logged per operation (the request, the result, and streamed output). Files you transfer pass through our servers as part of the session record. Session records, including transferred file content, are deleted after about 48 hours; opening a session always requires a fresh multi-factor check and is audited.
- Screen preview. A technician can request a deliberately low-resolution snapshot of a managed computer’s screen. Only the most recent snapshot is kept — each new one overwrites the last — and it is removed with the computer.
- Remote desktop (RustDesk). We store each computer’s RustDesk ID and its access passwords in encrypted form. Per-session passwords are short-lived and cleared when the session ends; standing passwords rotate automatically and after every reveal. We keep session metadata (who connected, when); the screen-sharing stream itself travels over the RustDesk connection and is not stored by Novius Now.
- Device Web. Technicians can save locations (label, address, port) for admin pages of devices on a managed network and browse them through a tunnel. We store the saved locations and session metadata with byte counters only — the page content itself is relayed and never stored.
- Lock-screen sign-in (JIT). Approving a lock-screen sign-in records who approved it, when, and from what IP address. The one-time password involved exists only in the QR code and on the approving device — it is never stored on our servers.
The mobile & desktop apps
- The apps talk only to Novius Now servers and contain no third-party SDKs, no analytics, and no advertising or tracking code.
- If you enable notifications, we store a device push token tied to your account and deliver alerts through Apple Push Notification service (and, for any non-Apple device, Expo’s notification service). Notification content can include a computer name, a requesting username, a program name, or the beginning of a chat message.
- Your session token is kept in the device keychain, and a cached copy of your own profile is stored on the device for fast start-up. Face ID / Touch ID checks happen entirely on the device — biometric data never reaches us. The camera is used only to scan sign-in QR codes, on device.
Website visitors, cookies & logs
- No analytics, no trackers. This website uses no analytics scripts, tag managers, advertising pixels, session replay, or third-party fonts or CDNs. Anonymous visitors are served static pages and receive no cookies.
- Browser storage. Your light/dark theme preference is kept in your browser’s local storage. It never leaves your browser.
- Cookies on sign-in. Signing in to the console sets first-party, essential cookies only: a session cookie, short-lived multi-factor sign-in cookies, an optional 30-day “remember this browser” cookie, and an organization-selection cookie. There are no advertising or third-party cookies.
- Connection logs. Traffic reaches us through Cloudflare, which processes standard connection data (IP address, request metadata) at its edge to route and protect traffic. Our own servers keep routine request logs that are capped at a small fixed size and rotate automatically.
How we use information
- To provide the service: fleet monitoring, elevation approvals, support chat, remediation, and recovery.
- To secure it: authentication, multi-factor checks, rate limiting, abuse prevention, and the audit trail.
- To send messages you asked for: approval alerts, chat notifications, security notices, and password resets.
- To operate reliably: encrypted backups, troubleshooting, and capacity planning.
- To comply with law and enforce our agreements.
We do not sell personal information. We do not use it for behavioral advertising, and we do not track people across other companies’ apps or websites.
Who can see what
Information from a managed computer is visible to the customer organization’s authorized technicians and administrators — that is the product. Access is tiered: ordinary operational data is visible to the organization’s technicians; sensitive reveals (recovery keys, access passwords) require administrator rights plus a fresh multi-factor step-up, and every reveal is written to the audit log the organization’s administrators can review. Platform operators access customer data only to run and support the service.
Service providers
We share information only with providers that process it to run the service, and only what each needs:
- Cloudflare — network routing, TLS, and DDoS protection in front of the service.
- Apple (Push Notification service) and Expo — delivery of the push notifications you enable.
- VirusTotal — file-reputation lookups by SHA-256 fingerprint only.
- Backblaze B2 — off-site storage of backups that are encrypted before upload.
- Email delivery — transactional email (password resets, notifications) is sent through the configured SMTP provider.
No analytics, advertising, or data-broker relationships exist.
Legal disclosures
We may disclose information if required by law or legal process, to protect the rights, safety, or property of our users, the public, or Novius Now, or as part of a merger, acquisition, or sale of assets — in which case this policy continues to apply to the transferred information until it is updated.
How long we keep information
- Account data — for the life of the account. Sign-in sessions expire after 14 days of inactivity; “remember this browser” records after 30 days.
- Audit log, command history, and decided elevation requests — 365 days by default, then deleted automatically.
- Observed security telemetry (blocked/observed execution attempts, protected-folder events) — 30 days by default.
- Background-tool and Device Web session records (including transferred file content) — about 48 hours.
- Chats, inventory, detections, and saved Device Web locations — for the life of the managed computer or until the organization removes them.
- Removed computers — held in a 30-day trash (so recovery keys remain retrievable), then permanently purged along with their inventory, chats, commands, sessions, and snapshots.
- File-reputation cache — 7 days per fingerprint.
- Encrypted backups — kept off-site on a grandfather-father-son schedule (hourly for a day, daily for a week, weekly for a month, monthly for a year, yearly up to 7 years). Backups are encrypted before they leave our infrastructure.
Your choices & rights
You can request access to, correction of, an export of, or deletion of personal information we hold about you by emailing [email protected]. We verify requests and respond as applicable law requires; depending on where you live (for example under the GDPR or CCPA/CPRA) you may have additional rights, and we honor them on request.
- In the product, organization administrators can delete users, remove computers (30-day trash, then permanent purge), delete companies, and delete their organization — the last of these permanently erases everything tenant-scoped, including audit history.
- If your computer is managed by an organization (your employer or IT provider), direct requests to that organization first — it controls that data; we will support its instructions.
- Notifications can be disabled per device in system settings; the push token is removed when you sign out or unregister.
- Email from us is transactional; reply to any message or write to us to stop non-essential mail.
Security
Traffic is encrypted in transit with TLS. Passwords are hashed with Argon2; multi-factor authentication is required by default, with passkey support; sensitive stored secrets — recovery keys, access passwords, authenticator seeds — are encrypted at rest; revealing one requires a fresh step-up and is audited. Backups are encrypted before leaving our infrastructure. Support content (chat, command output, transferred files) is processed on our servers so the service can function and is not end-to-end encrypted. No system is perfectly secure, and we don’t promise otherwise — but the platform is built so that the sensitive path is the audited, encrypted, step-up-gated path.
Where information is processed
Novius Now is operated from the United States, and information is processed and stored there. Cloudflare routes traffic through its global network. If you use the service from elsewhere, you understand your information is transferred to and processed in the United States.
Children
Novius Now is a workplace product for organizations and their IT teams. It is not directed to children, and we do not knowingly collect information from anyone under 16.
Changes to this policy
We may update this policy as the product evolves. We’ll revise the “last updated” date above and, for material changes, give notice where appropriate. This page reflects the product’s actual behavior at the date shown; the final legal language has not yet been reviewed by counsel, and we’ll refine it as that review completes.
Contact
Novius Now — [email protected]
United States