---
title: "Privatta FAQ"
description: "Does it use a server, what encryption it uses, offline and air-gapped operation, machine authentication, audit trails, platforms and editions."
url: "https://royalsoftworks.com/products/privatta/faq/"
source: "https://royalsoftworks.com"
format: "markdown"
note: "Markdown rendering of the HTML page at `url`. Same content, same canonical URL."
---

FAQ

# Questions we hear most.

Is anything stored on a server? Does it work without internet? What does the free version do? Straight answers.

01 Can someone push a file onto my machine without my permission?

No. Privatta is pull-only: the recipient always requests a specific file before any bytes move. A sender can offer a file and describe it, but there is no command in the protocol that lets them deliver it unsolicited. This is structural — the same rule on the LAN and over the internet, not a setting that could be turned off.

02 Does Privatta store files on a server?

No. Files transfer directly from the sender's machine to the recipient's. There is no central server, no cloud storage and no relay holding your data — the only copy in transit is the encrypted stream between the two devices.

03 What encryption does Privatta use?

Every P2P transfer runs over WebRTC's built-in DTLS encryption, negotiated directly between the two machines — the same transport security browsers use for video calls. A lightweight, open-source relay only relays the initial connection handshake; it never sees the file or your credentials, holds one in-memory table of pending pairings and forgets each one the instant its two peers connect, and it's self-hostable, so you can run your own instead of ours. Account passwords are stored only as scrypt hashes.

04 Can it work on a LAN or fully air-gapped network?

Yes. On a local network Privatta discovers other machines automatically and transfers directly between them, with no internet required. It runs on a completely air-gapped LAN with no outbound calls, and you can pre-authorise VPN address ranges as trusted. Pro and Enterprise licenses can also be activated entirely offline — see the next question.

05 Can I activate Privatta with no internet connection at all?

Yes, on Pro and Enterprise. Generate this machine's fingerprint locally, carry it to any device that does have internet, and download a license file for it. That file is signed and encrypted specifically for your machine and your license key, and verifying it needs no network call at all — the running installation never has to phone home. The file carries its own expiry, so you'll periodically need to repeat the process from an online device to refresh it.

06 How does Privatta pair with the mobile app?

Scan a QR code. The desktop app shows a code encoding its address and connection details; open the mobile app, scan it, and you're paired — no account, no typing an address or a key by hand. It's available on every tier.

07 How does Privatta authenticate the machines that connect?

It depends on the mode. On the LAN, the connecting machine's MAC address must already be whitelisted, on top of a valid username and password. Over the internet (P2P) there are two independent factors before anything else is checked: a single-use, 32-character connection key minted by the relay, and a 6-character security code generated on the host that never leaves it — they are meant to travel by different routes, so a leaked key on its own reaches a host that will not answer. Both work once and the key expires after 5 minutes. A peer that clears the code then either signs in with a username and password, or connects as a guest and sees only the files marked for everyone.

08 Can someone connect over the internet without an account on my machine?

Only if you publish something for them. Since 1.1 the P2P Connect dialog has a “Connect as a guest” option: a guest still needs both the connection key and the security code, and once in, sees exactly the files whose access you set to Everyone — nothing else is listed and nothing else can be requested. The Internet P2P panel tells you how many public files exist before you hand out a key, so you know what a guest will see. If you publish nothing, a guest connects to an empty list.

09 Who can access a given file?

You choose per file: everyone, specific users, or whole user groups. Files can also be bundled into virtual folders that share one policy. Over the internet the internet-sharing toggle is the outer gate — a file inside it set to Everyone is downloadable by any guest who clears the key and the security code, while anything narrower requires signing in as a user you created. A signed-in peer sees both: the public files plus whatever is shared with them or their group.

10 Is there an audit trail?

On the Enterprise tier, yes — and it's immutable. Privatta keeps a local access log of every attempt: the user, the machine's name, MAC address and device ID, the IP, the file, whether it was allowed or denied, and the reason. Since 1.1 internet (P2P) sessions are logged as thoroughly as LAN ones — the connection, every sign-in and refusal including a wrong security code, denied files, completed and interrupted transfers, and the disconnect — with a Channel column marking each entry LAN or P2P. There is no delete or edit operation for the log anywhere in the code, so once an entry is written, nobody — including an administrator — can remove it, and the entries are hash-chained so an edit made outside the app is detectable. Passwords are never written to it.

11 Does Privatta update itself?

It checks automatically and installs on your say-so. Privatta looks for a newer version once, about twenty seconds after launch, and never again while it is running — a transfer or a long-running host session should not be interrupted because a release happened that afternoon. If it finds something it tells you, and nothing downloads until you press the button. Settings → Updates → Check now forces a check whenever you like. The check is an ordinary HTTPS request for a small text file; no account, no identifier, no telemetry.

12 What happens if a release is marked required?

Some releases change something older versions genuinely cannot work with — the LAN protocol or the P2P handshake, say, where an old client talking to a new host fails confusingly rather than cleanly. Those can be marked required, and the update dialog then drops its Later and Skip buttons. You can still decline, behind a confirmation that states the trade plainly: the release may carry important fixes to how Privatta works or to its security, and continuing without it is at your own risk. Decline once and that version stops blocking you; the next required release will still stop you.

13 Are Privatta's installers code-signed?

The Windows builds are, as of 1.1 — both the installer and the portable executable carry an Authenticode signature issued to Royal SoftWorks. Windows names the publisher instead of reporting an unknown one, and you can verify who built the file yourself from the Digital Signatures tab in its properties before you run it. macOS builds are not signed yet, which is why macOS gets the update notification and a download link rather than an in-place install.

14 What platforms does Privatta run on?

The desktop app ships for Windows (code-signed installer and portable build), macOS and Linux. An Android companion app lets you discover machines on your network, pair by QR code, and browse and download shared files with the same access rules; an iOS app is in development. The current 1.1 release is published for Windows first, with the macOS and Linux builds of that release to follow.

15 Is Privatta suitable for HIPAA- or GDPR-sensitive files?

By architecture, yes. Because transfers are end-to-end encrypted and go directly between your machines with no cloud intermediary, there is no third-party data processor and no copy of your files leaving your control. The Enterprise tier adds an immutable local audit trail for compliance review.

16 What's the difference between Free, Pro and Enterprise?

Pull-only transfer and QR pairing are on every tier, including Free. Free shares public files on your local network with a daily transfer cap. Pro adds private per-user sharing, machine whitelisting, internet (P2P) transfers, unlimited volume, and offline license activation. Enterprise adds an immutable audit log and user groups pre-modeled on real org structures — legal, finance/compliance, and the like — plus per-group virtual folders for organisation-scale control.

17 What version is Privatta on, and where do I see what changed?

The current release is 1.1.0, published on 19 August 2026. Every release and what it changed — including what it breaks — is listed on the Privatta changelog page at royalsoftworks.com/products/privatta/changelog/. From 1.1 onward the app also tells you itself: it checks once shortly after launch and shows the release notes before anything is downloaded.

18 Do I have to trust Royal Softworks' relay server?

No. The relay only introduces two peers and relays their WebRTC handshake — it never sees a file or a password, and it forgets the connection the instant the peers pair up or either one disconnects. It's open source, so you can audit it or run your own instance and point Privatta at it from Settings instead of the default.

## Still have a question?

Security reviews, volume licensing and pilot deployments go straight to the team that builds the product.

[Get in touch](https://royalsoftworks.com/contact/) [View WebRTC Relay Server (open source)](https://royalsoftworks.com/products/webrtc-relay-server/)
