Lightning

Privacy

This page summarises docs/privacy.md in the source repository. That file is the full policy; every claim in it names the source file that implements it.

Lightning is a desktop Matrix client, not a service. There is no Lightning server, no Lightning account and no backend run by the project. What Lightning stores lives on your computer, and what it sends goes to your homeserver or to a service you asked for.

In short

Your homeserver

Lightning has no default homeserver. It talks to the one you sign in to, using the official matrix-rust-sdk: sign-in, sync, messages, media, key backup, verification and so on. In an unencrypted room your homeserver can read messages, as with any Matrix client; in an encrypted room it cannot. Its privacy policy is its operator's, not ours.

Lightning fetches a linked page itself, from your computer, and does not use your homeserver's preview proxy. A preview therefore reveals your IP address and the Lightning/<version> user agent to the linked site, which may have been chosen by whoever sent the message. That is why previews are off by default, both for unencrypted and encrypted rooms. You can turn them on in Settings → Privacy & security, or load a single one with a per-message action. No cookies, no Matrix identifiers and no referrer are sent. Only HTTPS to public addresses is allowed; SVG is never rendered and no JavaScript is run.

GIF providers (only when you open the picker)

The GIF picker contacts GIPHY or KLIPY, whichever you select. Nothing contacts them before you open the picker. The request carries the provider's API key, your search term (up to 50 characters), a result limit and the safe-search rating. No Matrix data of any kind is sent: no user, room, event, homeserver or message. The provider sees your IP address, as any website does. Saved GIFs from a chat are stored on your device and load without a network request.

Clicking a link hands the address to your default browser. Authenticated Matrix media addresses are never given to another program; media is fetched and decrypted inside Lightning.

Update checks and downloads

At most once every 24 hours, and never within the first 30 seconds after launch, Lightning fetches two small public files from the project's own package server: the update manifest and its signature. The only thing sent is the address and the user agent Lightning/<version>. No account, device, room or installation identifier exists to send.

If you choose to install an update, the file is downloaded from the project's read-only GitHub mirror, falling back to the project's own server. GitHub sees an anonymous download and your IP address. Every download is checked against an Ed25519 signature and a SHA-256 hash before anything is installed, wherever it came from. Flatpak and Snap installs are updated by their own package managers.

What is stored on your device

Signing out or removing an account deletes that account's store.

Logs and diagnostics

Local debug logs may include a short account identifier and account-scoped paths, and stay on your machine. Call diagnostics name the other participant's Matrix ID and device ID in the local log. Tokens, recovery keys, room and session keys, passwords and decrypted message bodies are never logged. The optional support-diagnostics export carries hashed account identifiers and no paths, is written locally, and is never uploaded by Lightning.

Installers

The Windows installers copy files and register an uninstall entry and shortcuts under your user profile. They contact no network service and need no administrator rights. Uninstalling does not delete your Matrix session or message store; sign out inside Lightning first, or delete the application data directory.

Children

Lightning is a general-purpose messaging client and is not directed at children.

Changes and contact

The policy is versioned in the repository beside the code it describes. Questions: Rokas Smetonis, antrasrokas@gmail.com, or the source repository.