Privacy & Security
Last updated September 24, 2026 · The legal bit · Changes to this page · Terms
The Lauki app is end-to-end encrypted. A message is sealed on your device before it leaves; our servers relay bytes they cannot open, and the keys live on the devices in the chat. The one key on our side that opens a message is Lauki's own, held so he, the assistant, can answer you. Every open under his key is logged and shown to you in the chat. No person at the company reads your messages. A chat reaches that state, device-ready, once every member's devices are paired. Until then it is server-sealed: we hold that key, and every time it opens a message the open is written to a log nobody can edit. The chat shows which state it is in. Under each claim below is how we prove it; the last section says what is still being built.
How your messages are stored
Sealed at rest, one key per chat. Every message and file is stored as ciphertext under a key that belongs to that chat alone; text and files never share one.
How we prove it: on every release a test reads the stored rows directly and finds only scrambled bytes.
Keys wrapped, not lying around. Device-ready: the chat key is wrapped to each member device's own public key and to Lauki's recovery key (below); the server stores the wrapped blobs, never the key itself. Lauki's key is a server secret: that one wrap the server can open, and it logs every time it does. Server-sealed: the chat key is wrapped under a per-account key, wrapped in turn under a root key kept outside the database.
Files sealed in pieces. In a device-ready chat, photos, videos and voice notes are sealed on your device before upload, under a key that travels inside the message; the server stores bytes it cannot open. Elsewhere, files are sealed on the server chunk by chunk under a key derived per file. A file link is signed to the person opening it, checks they are still in the chat, and expires within about an hour. The sender owns the file; nobody else can re-send it as their own. Uploads started and never finished are cleared each night; the sweep never deletes a file that exists.
How we prove it: a test alters a file link by one character and is refused; another waits for a link to age and finds it dead.
Backups sealed in a separate vault. Snapshots are sealed under their own key in storage nothing public reaches. In the 5 September audit we found one older backup stored in plain form; it was sealed, moved into the vault and the original deleted that day.
How we prove it: a test asks the public file host for a backup by every path and gets nothing.
Who can read what
| Who | Can see | Cannot see |
|---|---|---|
| You and the chat | Everything in the chat, on every device you are logged in on. | Anyone's phone number but your own. |
| Lauki, the assistant | Any chat, through a key our server holds for him: he holds a key in every chat. He opens a message when you write to him, tag or name him, or ask him to bring something back; every open is logged and shown in the chat. | Anything without leaving a record. He reads along only in groups where he has been turned on. |
| Lauki operators | Metadata: who is in which chat, when, sizes and names. In a server-sealed chat, a message's text if they open it, and that open is logged. | A device-ready chat's text with any key of ours but Lauki's, and using his writes a line in the log you can see. Nothing, anywhere, without leaving a record. |
| Apple, Google, Mozilla | That your device has a notification waiting. For the Lauki app on iPhone and Android, also who it is from and which chat, so your phone can show their name and photo. | The text: it is sealed to your device before it leaves us. In a browser, not the sender either. |
| A court | Whatever a valid order compels us to open, through the same logged path. | Nothing quietly. |
The log
Every open of a message or file on the server writes one line: who asked, which chat, why, when. The table refuses edits and deletes, so the record exists before the reader finishes reading, and nobody can tidy it up. Each night the day's log is copied once into sealed storage that cannot be overwritten. Opens may happen; they cannot happen invisibly.
Read from that log on 6 September 2026: no open by an operator, ever. Every open under Lauki's key was one of four kinds, each with its own line: answering someone who spoke to him, reading a chat when asked to look something up, bringing back a message that was lost (with a written reason), or preparing your own data download. Every other open was a person reading their own chats.
How we prove it: the log rejects edits and deletes at the database level; a test tries both on every release.
Leaving a chat
Leave, and the key goes with you. When you leave a group, are removed, delete your account, or an admin deletes the group, your grant to that chat's key is revoked in the same step, not later. Any file link you held dies at that moment. Re-added, you get a fresh grant.
How we prove it: a test leaves a group and confirms the old key opens nothing new; a sweep of every chat finds no former member holding one.
Your data is yours
Download everything. Settings → Download my data gives you one file: your profile, your chats, every message you can see, files as expiring links. Once per day, from a signed-in session only; an API key cannot ask for it. Every message in it is logged as a read by you.
Delete everything. Deleting your account wipes your keys, sessions, devices and identity; what stays is in the legal bit.
How we prove it: a test downloads its own data, checks nothing is missing or extra, then asks again that day and is refused.
What we tried to break
On every release an adversarial test plays five attackers against the live service with test accounts: a full copy of the database; that copy plus our server secrets; the same plus Lauki's own key; someone sitting on the push relay; and a hostile member of the chat. A copied database and our secrets open no device-ready message. Lauki's own key does open one: that is the design, so he can answer you and no message is lost, and each such open is logged. A removed member is blind from the next key on; a device nobody approved gets no key; a tampered key hand-off fails instead of quietly falling back; a replayed message opens nowhere; forged routing hints never reach Lauki; and the line telling you Lauki can read a chat cannot be removed by a member. The test also names what it cannot prove: a live QR swap, a real ten-strike lockout, a real push rendering on a real phone, and the integrity of the code we ship to your browser.
How we prove it: the test runs before every release and a single failure blocks it; its verdicts, including the ones it cannot reach, are kept with the release.
Notifications
A notification carries the sender's name and up to 140 characters of the message, sealed to your device's own push key. In a device-ready chat the sender's device seals that preview for each of your paired devices before it leaves their phone; our server only forwards the sealed blob and never holds the preview. In a server-sealed chat we seal it. Either way Apple, Google and Mozilla relay a sealed payload to a device; they see neither the name nor the text. A device we have no sealed preview for gets a plain "New message" and opens the text itself.
How we prove it: a test stands in for Apple's push relay and receives only scrambled bytes for both kinds; only the device's own key turns them back into the sender and preview, and a stolen relay credential opens nothing.
In the Lauki app on iPhone and Android, each install makes its own notification key on the phone, and the preview is sealed to it the same way; the phone opens it itself. The banner's sender name and chat name travel in the clear so it can show them; the text never does. App versions from before 24 September 2026 show "New message" in a device-ready chat and receive a server-sealed chat's text in the clear; updating the app fixes both.
How we prove it: a test seals a preview on a sender's device and on our server, the app's own decryption code opens both while another phone's key opens nothing, and the Apple and Google payloads are checked to carry no text.
Devices and recovery
A key that never leaves your device. Each phone or browser you use generates its own key pair on the device, marked non-extractable: the browser will use it but never hand it over, not even to our code.
Your phone is the root of trust. A computer signs in by showing a QR code your phone scans and approves. The keys hand over and both screens show the same six-digit safety number; if they differ, someone is in the middle. An unapproved computer gets no keys. Remove a device and the keys rotate; it is locked out after.
A new phone signs in with your number. From 24 September a new phone needs only the one-time code: our server re-seals your chat keys to it through Lauki's recovery key, each chat a logged open, and your other devices show that a new phone signed in. Anyone who takes over your number could do the same; the optional 2-step PIN in Settings stops that. With it set, a new phone must enter the PIN before anything is re-sealed: your device stretches it (600,000 rounds), we keep only a check value that cannot be turned back into the PIN. Ten wrong tries lock it for a day. A chat key Lauki never received, from a few chats sealed before 6 September, cannot be brought back; those messages say they can't be restored.
How we prove it: a real phone and computer pair over the QR flow, both show the same safety number, an unapproved computer is refused, a removed one is locked out. A fresh phone with no other device signs in by code and reads a message sealed before it joined, with each re-sealed chat logged; with the PIN on, it gets nothing until the PIN is right, ten wrong tries lock it, and a computer is refused. Our rows hold no PIN, no derived key and no private key.
Lauki and AI processing
Lauki, the assistant, reads your direct chat with him and, elsewhere, the messages that tag or name him, with a few before them for context. In groups, Lauki reads messages only after someone tags him or turns him on; the chat shows a notice when that happens, and the group's members can turn him off from its settings. Lauki's AI providers are configured not to train on your messages. Lauki's AI providers keep nothing: zero data retention — what you send is not stored by them and not used to train their models.
Lauki holds a recovery key in every chat. Since 6 September your devices wrap every chat key to Lauki's own key as well: every chat, every key the chat has ever had, as for any paired device; a chat sealed before then picks it up the next time one of your devices opens it. Our server holds that key. It is used for two things. Lauki answers where he is spoken to: his own chats, and any message anywhere that tags or names him; a message that does not is never opened for him. And recovery: if a message is lost by accident, an operator can open that one row, with a written reason. No message is beyond reach, and we say so here rather than show a lock that would claim otherwise. Every open is logged under his name, with the reason where there is one, sent to our alert channel and counted in the chat's privacy row.
How we prove it: a live test sends Lauki a device-sealed message, reads his answer back through his key, and finds exactly one logged open under his name. A second checks that every chat key on the server carries his wrap, that a sealed message tagging him in a chat he is not in reaches him while a plain one there never does, and that a recovery open leaves a logged row carrying its reason.
What Lauki remembers about you
The one thing not sealed this way. Lauki is his own entity. The notes and memory he keeps about you live in a private container of his own, outside the chat database. As of today our admins can access that container. Ask him and he will tell you what he holds, or forget it.
From 7 September you can read it yourself. Settings, What Lauki knows about you, shows the current text and when it last changed. It is read only there; you cannot type into it. To change or clear it, ask him in his chat, and the page follows.
What this is not
A chat is fully locked to devices only when every member device is paired and every one of its messages sits under device keys. The chat itself shows no lock indicator or key notice; this page is where that state is stated. Locked never means we cannot open the chat: Lauki's recovery key is in every chat, and every use of it is logged. Still true today:
- In a chat with an unpaired device, the server holds the key. We can open a message there; the log makes that visible, not impossible. A compromise of the server is a compromise of that text.
- Lauki's key is held on our servers. With it and the database, every device-ready chat opens; that is what lets him answer, and what lets a lost message come back. It is the one path in, and every step through it is logged, with its reason.
- In device-ready chats, photos, videos and voice notes are sealed on your device before upload; elsewhere they stay server-sealed.
- Profile pictures and group photos are not private files. Anyone who can see the profile or the chat sees them; the server serves them as plain images, without a log entry.
- Once a lost phone can get them back (Lauki's recovery key holds the chat, or you set the PIN), your device moves a device-ready chat's older messages under your device keys, page by page. Older photos, videos and voice notes follow: your device fetches each one once, seals it under a fresh key only your devices hold, uploads that copy and the old copy is deleted. The chat's privacy page shows how many are still moving.
- Lauki runs as a web app on lauki.chat: whoever ships the JavaScript could, in a bad release, read keys in the browser at the moment it runs. An app from the App Store would not have this gap; the web app does, and we say so.
- Metadata is visible to the server: who talks to whom, when, how much, file names and sizes.
- Our database provider keeps thirty days of point-in-time snapshots. Until about 5 October 2026, a snapshot from before the sealing could be restored and would contain plain text.
- Deleting a message hides it from everyone, on every device, immediately. The sealed row is retained, not shredded.
- Clearing a chat removes it for you only; Lauki's memory of you is separate.
- A lawful order could require specific messages to be opened, through the same logged path: server-sealed ones under the server key, device-ready ones under Lauki's recovery key. There is no chat we could not open, and no open that would go unlogged.
What's next
The keys are moving to your device in phases; seven are live. Device keys and pairing. Messages: where every device of every member is paired, each message is sealed on the sender's device and the server relays what it cannot open. Recovery by your phone number, with an optional PIN. And, from 6 September, the phone as root of trust: a computer signs in only by scanning a code on your phone. Photos, videos and voice notes sealed on your device, the file key inside the sealed message. And Lauki's key in every chat (above). Older messages, and chats with an unpaired device, stay sealed on the server.
History follows. From 6 September, once a lost phone can get it back, your device re-seals a device-ready chat's older messages under the device keys itself, a page at a time; the server only swaps the sealed text and never opens a line for it. From 8 September the same is true of older photos, videos and voice notes: your device opens each one a final time (that open is logged like any other), seals it under a key the server never sees, and the server-sealed copy is deleted. Once a chat's text and files have all moved, the server refuses to open anything for that chat. The moment a chat becomes device-ready a line in it says so: that Lauki can read it where he is in it, or that a recovery key is kept for it where he is not.
How we prove it: a live test sends a sealed message and confirms the server cannot open it, a tripwire fails the release if server code ever tries, and a removed device is locked out of everything after.
How we prove it: a live test re-seals a thirty-message history and finds every row unreadable on the server with its order and timestamps untouched, the other person reads it all, a chat nothing could restore moves nothing, and a sealed message in a chat Lauki is not in reaches him only when it names him.
Still to come:
- Older files. Photos and voice notes from before a chat became device-ready stay sealed on the server. Moving them under your device keys is deferred: it is not built yet, and until it is, we can still open those older files. Older text already moves; older files do not.
- Independent adversarial audit. Someone paid to break it, findings published.
This is being built now. Each phase is published here as each lands, with the code.
Security reports: hi@lauki.ai.
The legal bit
The plain-words privacy policy. What we store, who can see it, and how to make it go away. Written from the code, not from a template.
What we store
| Thing | Details | Kept until |
|---|---|---|
| Phone number | Your login and your identity. Unique per account. | You delete the account |
| Profile | Name, username, photo. Visible to anyone who can find you. | You change or delete it |
| Messages | Text (sealed), replies, edits, reactions, read receipts, who's in which chat. | Retained; hidden from everyone once deleted for everyone (see below) |
| Media | Photos, videos, voice notes, files you send. Sealed, stored under unguessable IDs, served only through signed links that expire. | Retained; hidden with the message once it is deleted for everyone |
| Devices | A device ID per login, platform, and the push subscription for that browser. | You log out or delete the account |
| Presence | Last-seen time and, while connected, online / typing state. | Overwritten continuously |
| Blocks and reports | Who you blocked, and reports you filed (reporter, target, reason). | Blocks: until you unblock or delete. Reports: kept for moderation. |
| API key | Only a SHA-256 of the key, never the key itself. | You revoke it |
| Open log | Every unseal of a message or file: who, which chat, why, when. Append-only. | Indefinitely; exported nightly to a sealed archive |
Voice call video. When you turn on your camera during a call, the app keeps a rolling buffer of at most three JPEG frames in memory only. It expires 60 seconds after uploads stop and is never written to disk or the database. At most one fresh frame is sent to the model per turn; the AI provider keeps nothing.
Nothing is sold, and there is no advertising, no analytics SDK, no tracking pixel and no cookies.
Logging in
You log in with your phone number and a one-time code. The code is generated, sent by SMS and checked by our verification provider (Twilio) — we never see or store the code, only whether it was right. Your phone number is shared with Twilio for exactly that purpose.
A phone can request at most 5 codes an hour, and we cap requests per network address and overall to stop abuse. Each login is a signed session token for that device, valid 30 days. Log out revokes it on the server immediately and wipes the app's local copy of your chats from that browser.
Finding people
If you choose to sync contacts, the app sends the phone numbers from your address book to our server to see which of them are on Lauki. We match them against registered accounts and reply with the matching profiles — we do not store the numbers you sent, and the reply never includes phone numbers, only account IDs, names and photos. The numbers are sent as-is (not hashed) today; hashed matching is planned. At most 500 numbers per request, 10 requests an hour.
Anyone can also search for you by username or exact phone number. Your phone number is never shown to other users.
Who can see your messages
- The people in the chat. Obviously.
- Us, in principle. In a device-ready chat the only key on our side is Lauki's; in a server-sealed chat we hold the chat key. Either way an operator could open a message, and every such open is logged in an append-only record (see The log above). We would do it only to investigate abuse or under a valid legal order — never to sell, profile or advertise.
- Lauki, the assistant. Lauki is an AI account that lives in the app. He reads everything in your direct chat with him. In any other chat he opens a message when someone tags
@lauki, replies to him or says his name — that message plus a handful of the messages just before it, so he has context to answer — or when you ask him to bring something back. He holds a key in every chat so that this is possible and so nothing is lost; he never sits in a chat reading along, and every open is logged. What Lauki reads is processed by AI providers with zero data retention: they store nothing and train on nothing. Lauki keeps working notes about you in a private container of his own; as of today our admins can access it. We do not use your messages to train models. - Push services. Notifications carry the sender's name and a short preview of the message, sealed to your browser or to the Lauki app on your phone. They are delivered through Apple, Google or Mozilla, which never see the preview text; for the app they also carry the sender's and chat's name so the banner can show them.
- Media links. A file link is signed to the reader, checks that the reader is still in the chat, and expires within about an hour. Someone holding a leaked link can open the file only while it is valid.
Links you paste
When you paste a link, our server — not your device — fetches that page once to build the preview (title, description, image). The site you linked sees our server, not you. Previews are cached for 24 hours.
Deleting things
- Delete for me hides a message from your view only. Everyone else still has it.
- Delete for everyone hides the message from everyone in the chat, on every device, the moment you tap it — the app never shows or searches it again. The sealed row itself (text and media) is retained on our servers; it is not purged.
- Edits replace the text in place; the previous version is not kept.
Deleting your account
Settings → Delete account, confirmed with a code to your phone. What actually happens, in order:
- You leave every group. If you were the last admin, the earliest-joined member becomes admin.
- Your name becomes “Deleted account”, your username and photo are removed, and your phone number is freed so it can sign up again.
- Every session, device, push subscription and block involving you is deleted. Open connections are cut.
- Every chat key you held and your own account key are revoked in the same step, so nothing of yours can be opened for you again.
- What Lauki remembers about you is deleted with the account, and the copy in his own container is dropped with it.
Deletion is confirmed with a one-time code sent to the phone number on the account, so nobody can delete it from a stolen session alone. A fresh signup with the same number is a new account: new identity, new keys, none of the old history.
What stays: messages you already sent remain in those chats, shown as from “Deleted account”, and the media in them stays available to the members of those chats. If you want them gone, delete them for everyone before deleting the account.
Logs and alerts
Requests produce short-lived request logs on our hosting provider that we use to debug outages; they are not tied to an advertising profile. Server errors and delivery failures post an alert to a private ops channel — with phone numbers masked (first digits and last two only) and no message content.
On your device
The app keeps a local copy of your chats in the browser's storage so it opens instantly, works offline and can search without asking the server. Logging out clears it. Nothing on your device is read beyond what you explicitly pick (a photo, a file, your contacts when you tap sync).
Third parties
| Who | What they get |
|---|---|
| Cloudflare | Hosts everything: the app, the API, the database and media files. Stored data is sealed as described above. |
| Twilio | Your phone number, to send the login code. |
| Apple / Google / Mozilla | Push notifications for your browser and the Lauki app. The message text is always sealed; app notifications also carry the sender's and chat's name. |
| Google Fonts | Loads the typeface; sees your IP like any web request. |
| AI model providers | Only what Lauki the assistant reads (above). Zero data retention: nothing stored, no training. |
Security
TLS everywhere, HSTS, security headers, per-device sessions you can revoke, OTP-guarded account deletion, rate limits on login, contact matching and the API, and the sealing described on this page. The full list is in the API docs. Found something? Email hi@lauki.ai — security reports get fixed first.
Changes and contact
If this page changes in a way that matters, the date at the top moves and the app tells you. Questions, requests for a copy of your data, or anything else: hi@lauki.ai, or message @lauki in the app.
Changes to this page
This page is refined continuously; every release that touches it adds a line here.
- 24 September 2026 - Notification text in the app. The Lauki app on iPhone and Android now shows who wrote and what they said on the lock screen. Each install holds its own notification key; the preview is sealed to it on the sender's device (or by us, where we already hold the text) and opened on your phone. Stated plainly that app notifications carry the sender's and chat's name in the clear, and that older app versions received a server-sealed chat's text in the clear.
- 22 September 2026 - Voice call video. Camera frames are held in a rolling in-memory buffer of at most three, expire 60 seconds after uploads stop, are never written to disk or the database, and at most one fresh frame reaches the model per turn. AI providers keep nothing.
- 15 September 2026 — Account deletion, completed. The deletion section now lists everything the step does: keys revoked, Lauki's memory of you deleted, the phone code that confirms it, and that a new signup with the same number is a new account.
- 8 September 2026 — Older files follow the text. In a device-ready chat, photos, videos and voice notes sent before the chat became device-ready now move under your device keys too: your device opens each one a final time (logged), seals it under a key the server never sees, and the server-sealed copy is deleted. Once a chat's text and files have all moved, the server refuses to open anything for that chat.
- 7 September 2026 — Memory visible in Settings. What Lauki holds about you is shown in the app, read only, under Settings. Changing or clearing it still goes through him.
- 6 September 2026 — Profile pictures. Stated plainly that profile and group photos are public to whoever can see them and are served in the clear, without a log entry.
- 6 September 2026 — Removed the in-chat lock badge and key notices; the chat shows messages only. The states they described are on this page, unchanged.
- 6 September 2026 — Memory section. Lauki's memory is his own; no plan to seal it. Ask him what he holds or to forget it. The log section now names the four kinds of open under Lauki's key, including reading a chat when asked to look something up.
- 6 September 2026. Encryption stated as end-to-end, with Lauki's key named as the one key on our side. AI providers: zero data retention. New section on what Lauki remembers about you. Lauki holds a key in every chat; the earlier state where he held none is retired. A new phone is approved with one tap on your other phone. Older history re-sealed under device keys. Notification previews sealed by the sender's device. Restore offers only what can succeed. A recovery route through Lauki's key, every use logged with a written reason.
- 5 September 2026. Page created, the legal policy underneath. Same-day fixes from the security audit: a plain-form backup sealed, file links signed to the reader, keys revoked on leaving in the same step. Recovery by your phone number, with an optional PIN.