Privacy and your data
NounDesk manages devices, not people. This page explains what information NounDesk receives from your company’s devices, what it doesn’t, and who in your team can see it. Share it with employees who ask what their work phone reports.
Who: everyone. Each section says which roles can see what.
What NounDesk receives from devices
Devices report to Google, and NounDesk reads those reports to show you each device’s status. NounDesk keeps:
| Kind | What’s included |
|---|---|
| Identity | Manufacturer, brand and model, serial number, IMEI or MEID where the device reports it, and the Wi-Fi hardware (MAC) address. |
| Software | Android version, security patch date and build number. |
| Hardware | Total memory, total storage and free storage. |
| Network | The name of the mobile network operator. |
| Security state | Whether a screen lock is set, whether storage is encrypted, whether USB debugging, developer options or installs from unknown sources are switched on, whether Google Play Protect is on, and Google’s own check for tampered or at-risk devices. |
| Policy status | Which policy version the device runs, when it last checked in and enrolled, and any setting the device couldn’t apply. |
| Apps | The apps installed on the device, with their names and versions, so NounDesk can check required and blocked apps. |
| Command results | Whether a lock, reboot, erase or other action you sent was completed. |
This is the information shown on the device page. See Device page.
What NounDesk doesn’t see
NounDesk has no feature to view, and doesn’t collect:
- phone calls or call history
- text messages (SMS) or chat messages
- photos, files or other personal content on the device
- what someone types (keystrokes)
- browsing history
There’s no separate NounDesk app on the phone. Google’s own Android Device Policy app manages the device.
Location: only in lost mode
NounDesk receives a device’s location only while it’s in lost mode. It never tracks devices in normal use.
- When you turn on lost mode, the device reports where it is and its battery level. The Location card on the device’s Security tab shows it.
- When you end lost mode, the reports stop.
- The policy setting Location services controls the device’s location switch. Always on (recommended for lost devices) makes sure a lost device can report; NounDesk still only sees a location during lost mode.
See Lost devices and location.
Company documents
When an employee opens a company document, NounDesk records it in the audit log with the employee’s name and the document title, and counts it in the documents library. The portal tells employees this on every page. Employees sign in with a one-time code sent to their work email; they don’t create a password. See Opening company documents.
The audit log
The Audit log records every meaningful action in your organization: who did it, when, what it affected and whether it worked. For actions by your team, it can also record the IP address and browser used. It includes:
- device actions such as lock, lost mode and erase
- policy changes, publishes and restores
- changes to employees, admins, apps and settings
- employee sign-ins to Company documents, and every document opened
Nobody in your team can edit or delete entries. See Reports and the audit log.
Who can see what
| Information | Owner | Admin | Operator | Viewer |
|---|---|---|---|---|
| Devices, including lost-mode location | Yes | Yes | Yes | Yes |
| Employees | Yes | Yes | Yes | Yes |
| Policies, apps and documents library | Yes | Yes | Yes | Yes |
| Alerts | Yes | Yes | Yes | Yes |
| Audit log | Yes | Yes | Yes | Yes |
| Remote support setup value | Yes | Yes | No | No |
| Billing | Yes | No | No | No |
What each role can change is described in Roles and permissions.
- Remote support: the value that links devices to your TeamViewer, AnyDesk or Splashtop account is masked on screen, and only Owners and Admins can see or change it. It’s kept out of the audit log and policy version history. See Remote support.
- Wi-Fi passwords you push in a policy are masked in the editor but are part of the policy. See Network settings.
- Each organization’s data is kept separate. People in one organization can’t see another organization’s devices or records.
Where data is kept
NounDesk is hosted on Vercel and Supabase in the US, which encrypt data in transit and at rest. Google credentials stay on NounDesk’s servers and never reach your browser. Enrollment codes are never stored or written to logs.
Deleting data
- Demo mode: when you leave demo mode (Exit demo mode, type
EXIT, Leave demo mode), NounDesk deletes the sample devices and their history, employees, apps, alerts, enrollment codes and every policy except the default one. This can’t be undone. The audit log is kept. See Demo mode. - Erase: erasing a device removes everything on the device itself. The device stays in your list, marked Erased, until you retire it. See Retire and offboard devices.
- Documents: Remove deletes a document from the library, and employees can no longer open it.
For anything else, such as closing your account, email support@noundesk.com.