Privacy
This page summarises docs/privacy.md in the source repository. That file is the full policy; every claim in it names the source file that implements it.
Lightning is a desktop Matrix client, not a service. There is no Lightning server, no Lightning account and no backend run by the project. What Lightning stores lives on your computer, and what it sends goes to your homeserver or to a service you asked for.
In short
- Lightning collects nothing. No analytics, no telemetry, no crash reporting, no usage measurement, no advertising identifier. The project receives no personal data from installed clients.
- It checks for updates, and that is on by default. The check is an anonymous request for two small public files. It carries no account, device or usage information, and you can turn it off in Settings → Updates.
- Your homeserver receives normal Matrix traffic, because that is what a Matrix client does.
- Third parties are contacted only for link previews, the GIF picker, and downloading an update file. All three are under your control.
- Messages in encrypted rooms are end-to-end encrypted by the official Rust Matrix SDK. Lightning implements no cryptography of its own.
Your homeserver
Lightning has no default homeserver. It talks to the one you sign in to, using the official matrix-rust-sdk: sign-in, sync, messages, media, key backup, verification and so on. In an unencrypted room your homeserver can read messages, as with any Matrix client; in an encrypted room it cannot. Its privacy policy is its operator's, not ours.
Link previews (off by default)
Lightning fetches a linked page itself, from your computer, and does not use your homeserver's preview proxy. A preview therefore reveals your IP address and the Lightning/<version> user agent to the linked site, which may have been chosen by whoever sent the message. That is why previews are off by default, both for unencrypted and encrypted rooms. You can turn them on in Settings → Privacy & security, or load a single one with a per-message action. No cookies, no Matrix identifiers and no referrer are sent. Only HTTPS to public addresses is allowed; SVG is never rendered and no JavaScript is run.
GIF providers (only when you open the picker)
The GIF picker contacts GIPHY or KLIPY, whichever you select. Nothing contacts them before you open the picker. The request carries the provider's API key, your search term (up to 50 characters), a result limit and the safe-search rating. No Matrix data of any kind is sent: no user, room, event, homeserver or message. The provider sees your IP address, as any website does. Saved GIFs from a chat are stored on your device and load without a network request.
Links you click
Clicking a link hands the address to your default browser. Authenticated Matrix media addresses are never given to another program; media is fetched and decrypted inside Lightning.
Update checks and downloads
At most once every 24 hours, and never within the first 30 seconds after launch, Lightning fetches two small public files from the project's own package server: the update manifest and its signature. The only thing sent is the address and the user agent Lightning/<version>. No account, device, room or installation identifier exists to send.
If you choose to install an update, the file is downloaded from the project's read-only GitHub mirror, falling back to the project's own server. GitHub sees an anonymous download and your IP address. Every download is checked against an Ed25519 signature and a SHA-256 hash before anything is installed, wherever it came from. Flatpak and Snap installs are updated by their own package managers.
What is stored on your device
- Sign-in tokens go in your system keyring where there is one. Without a keyring Lightning says so and uses a plain fallback file.
- Message content is not encrypted at rest. The Matrix SDK's event cache and room state, and Lightning's local search index, hold messages in plain SQLite files once they have been decrypted, encrypted rooms included. The files are readable only by your user and are deleted with the account. Anything that can already read your home directory, such as another program of yours, a backup or a stolen unencrypted disk, can read them. Full-disk encryption is the answer today.
- Downloaded media is kept so it opens again without downloading. Media from encrypted rooms is kept encrypted, with a per-account key held in the keyring, and is not kept at all where no secure keyring exists. Settings → Privacy & security lets you stop keeping media and clear it.
- Attachments you send are held by the SDK's send queue until uploaded, then for up to 60 days, in the encrypted media store.
- Settings, saved GIFs and recent emoji stay local. Saved GIFs are deleted on sign-out and can be cleared from Settings.
Signing out or removing an account deletes that account's store.
Logs and diagnostics
Local debug logs may include a short account identifier and account-scoped paths, and stay on your machine. Call diagnostics name the other participant's Matrix ID and device ID in the local log. Tokens, recovery keys, room and session keys, passwords and decrypted message bodies are never logged. The optional support-diagnostics export carries hashed account identifiers and no paths, is written locally, and is never uploaded by Lightning.
Installers
The Windows installers copy files and register an uninstall entry and shortcuts under your user profile. They contact no network service and need no administrator rights. Uninstalling does not delete your Matrix session or message store; sign out inside Lightning first, or delete the application data directory.
Children
Lightning is a general-purpose messaging client and is not directed at children.
Changes and contact
The policy is versioned in the repository beside the code it describes. Questions: Rokas Smetonis, antrasrokas@gmail.com, or the source repository.