Lauki / Privacy & Security Open the app

Privacy & Security

Last updated September 24, 2026 · The legal bit · Changes to this page · Terms

The Lauki app is end-to-end encrypted. A message is sealed on your device before it leaves; our servers relay bytes they cannot open, and the keys live on the devices in the chat. The one key on our side that opens a message is Lauki's own, held so he, the assistant, can answer you. Every open under his key is logged and shown to you in the chat. No person at the company reads your messages. A chat reaches that state, device-ready, once every member's devices are paired. Until then it is server-sealed: we hold that key, and every time it opens a message the open is written to a log nobody can edit. The chat shows which state it is in. Under each claim below is how we prove it; the last section says what is still being built.

How your messages are stored

Sealed at rest, one key per chat. Every message and file is stored as ciphertext under a key that belongs to that chat alone; text and files never share one.

How we prove it: on every release a test reads the stored rows directly and finds only scrambled bytes.

Keys wrapped, not lying around. Device-ready: the chat key is wrapped to each member device's own public key and to Lauki's recovery key (below); the server stores the wrapped blobs, never the key itself. Lauki's key is a server secret: that one wrap the server can open, and it logs every time it does. Server-sealed: the chat key is wrapped under a per-account key, wrapped in turn under a root key kept outside the database.

Files sealed in pieces. In a device-ready chat, photos, videos and voice notes are sealed on your device before upload, under a key that travels inside the message; the server stores bytes it cannot open. Elsewhere, files are sealed on the server chunk by chunk under a key derived per file. A file link is signed to the person opening it, checks they are still in the chat, and expires within about an hour. The sender owns the file; nobody else can re-send it as their own. Uploads started and never finished are cleared each night; the sweep never deletes a file that exists.

How we prove it: a test alters a file link by one character and is refused; another waits for a link to age and finds it dead.

Backups sealed in a separate vault. Snapshots are sealed under their own key in storage nothing public reaches. In the 5 September audit we found one older backup stored in plain form; it was sealed, moved into the vault and the original deleted that day.

How we prove it: a test asks the public file host for a backup by every path and gets nothing.

Who can read what

WhoCan seeCannot see
You and the chatEverything in the chat, on every device you are logged in on.Anyone's phone number but your own.
Lauki, the assistantAny chat, through a key our server holds for him: he holds a key in every chat. He opens a message when you write to him, tag or name him, or ask him to bring something back; every open is logged and shown in the chat.Anything without leaving a record. He reads along only in groups where he has been turned on.
Lauki operatorsMetadata: who is in which chat, when, sizes and names. In a server-sealed chat, a message's text if they open it, and that open is logged.A device-ready chat's text with any key of ours but Lauki's, and using his writes a line in the log you can see. Nothing, anywhere, without leaving a record.
Apple, Google, MozillaThat your device has a notification waiting. For the Lauki app on iPhone and Android, also who it is from and which chat, so your phone can show their name and photo.The text: it is sealed to your device before it leaves us. In a browser, not the sender either.
A courtWhatever a valid order compels us to open, through the same logged path.Nothing quietly.

The log

Every open of a message or file on the server writes one line: who asked, which chat, why, when. The table refuses edits and deletes, so the record exists before the reader finishes reading, and nobody can tidy it up. Each night the day's log is copied once into sealed storage that cannot be overwritten. Opens may happen; they cannot happen invisibly.

Read from that log on 6 September 2026: no open by an operator, ever. Every open under Lauki's key was one of four kinds, each with its own line: answering someone who spoke to him, reading a chat when asked to look something up, bringing back a message that was lost (with a written reason), or preparing your own data download. Every other open was a person reading their own chats.

How we prove it: the log rejects edits and deletes at the database level; a test tries both on every release.

Leaving a chat

Leave, and the key goes with you. When you leave a group, are removed, delete your account, or an admin deletes the group, your grant to that chat's key is revoked in the same step, not later. Any file link you held dies at that moment. Re-added, you get a fresh grant.

How we prove it: a test leaves a group and confirms the old key opens nothing new; a sweep of every chat finds no former member holding one.

Your data is yours

Download everything. Settings → Download my data gives you one file: your profile, your chats, every message you can see, files as expiring links. Once per day, from a signed-in session only; an API key cannot ask for it. Every message in it is logged as a read by you.

Delete everything. Deleting your account wipes your keys, sessions, devices and identity; what stays is in the legal bit.

How we prove it: a test downloads its own data, checks nothing is missing or extra, then asks again that day and is refused.

What we tried to break

On every release an adversarial test plays five attackers against the live service with test accounts: a full copy of the database; that copy plus our server secrets; the same plus Lauki's own key; someone sitting on the push relay; and a hostile member of the chat. A copied database and our secrets open no device-ready message. Lauki's own key does open one: that is the design, so he can answer you and no message is lost, and each such open is logged. A removed member is blind from the next key on; a device nobody approved gets no key; a tampered key hand-off fails instead of quietly falling back; a replayed message opens nowhere; forged routing hints never reach Lauki; and the line telling you Lauki can read a chat cannot be removed by a member. The test also names what it cannot prove: a live QR swap, a real ten-strike lockout, a real push rendering on a real phone, and the integrity of the code we ship to your browser.

How we prove it: the test runs before every release and a single failure blocks it; its verdicts, including the ones it cannot reach, are kept with the release.

Notifications

A notification carries the sender's name and up to 140 characters of the message, sealed to your device's own push key. In a device-ready chat the sender's device seals that preview for each of your paired devices before it leaves their phone; our server only forwards the sealed blob and never holds the preview. In a server-sealed chat we seal it. Either way Apple, Google and Mozilla relay a sealed payload to a device; they see neither the name nor the text. A device we have no sealed preview for gets a plain "New message" and opens the text itself.

How we prove it: a test stands in for Apple's push relay and receives only scrambled bytes for both kinds; only the device's own key turns them back into the sender and preview, and a stolen relay credential opens nothing.

In the Lauki app on iPhone and Android, each install makes its own notification key on the phone, and the preview is sealed to it the same way; the phone opens it itself. The banner's sender name and chat name travel in the clear so it can show them; the text never does. App versions from before 24 September 2026 show "New message" in a device-ready chat and receive a server-sealed chat's text in the clear; updating the app fixes both.

How we prove it: a test seals a preview on a sender's device and on our server, the app's own decryption code opens both while another phone's key opens nothing, and the Apple and Google payloads are checked to carry no text.

Devices and recovery

A key that never leaves your device. Each phone or browser you use generates its own key pair on the device, marked non-extractable: the browser will use it but never hand it over, not even to our code.

Your phone is the root of trust. A computer signs in by showing a QR code your phone scans and approves. The keys hand over and both screens show the same six-digit safety number; if they differ, someone is in the middle. An unapproved computer gets no keys. Remove a device and the keys rotate; it is locked out after.

A new phone signs in with your number. From 24 September a new phone needs only the one-time code: our server re-seals your chat keys to it through Lauki's recovery key, each chat a logged open, and your other devices show that a new phone signed in. Anyone who takes over your number could do the same; the optional 2-step PIN in Settings stops that. With it set, a new phone must enter the PIN before anything is re-sealed: your device stretches it (600,000 rounds), we keep only a check value that cannot be turned back into the PIN. Ten wrong tries lock it for a day. A chat key Lauki never received, from a few chats sealed before 6 September, cannot be brought back; those messages say they can't be restored.

How we prove it: a real phone and computer pair over the QR flow, both show the same safety number, an unapproved computer is refused, a removed one is locked out. A fresh phone with no other device signs in by code and reads a message sealed before it joined, with each re-sealed chat logged; with the PIN on, it gets nothing until the PIN is right, ten wrong tries lock it, and a computer is refused. Our rows hold no PIN, no derived key and no private key.

Lauki and AI processing

Lauki, the assistant, reads your direct chat with him and, elsewhere, the messages that tag or name him, with a few before them for context. In groups, Lauki reads messages only after someone tags him or turns him on; the chat shows a notice when that happens, and the group's members can turn him off from its settings. Lauki's AI providers are configured not to train on your messages. Lauki's AI providers keep nothing: zero data retention — what you send is not stored by them and not used to train their models.

Lauki holds a recovery key in every chat. Since 6 September your devices wrap every chat key to Lauki's own key as well: every chat, every key the chat has ever had, as for any paired device; a chat sealed before then picks it up the next time one of your devices opens it. Our server holds that key. It is used for two things. Lauki answers where he is spoken to: his own chats, and any message anywhere that tags or names him; a message that does not is never opened for him. And recovery: if a message is lost by accident, an operator can open that one row, with a written reason. No message is beyond reach, and we say so here rather than show a lock that would claim otherwise. Every open is logged under his name, with the reason where there is one, sent to our alert channel and counted in the chat's privacy row.

How we prove it: a live test sends Lauki a device-sealed message, reads his answer back through his key, and finds exactly one logged open under his name. A second checks that every chat key on the server carries his wrap, that a sealed message tagging him in a chat he is not in reaches him while a plain one there never does, and that a recovery open leaves a logged row carrying its reason.

What Lauki remembers about you

The one thing not sealed this way. Lauki is his own entity. The notes and memory he keeps about you live in a private container of his own, outside the chat database. As of today our admins can access that container. Ask him and he will tell you what he holds, or forget it.

From 7 September you can read it yourself. Settings, What Lauki knows about you, shows the current text and when it last changed. It is read only there; you cannot type into it. To change or clear it, ask him in his chat, and the page follows.

What this is not

A chat is fully locked to devices only when every member device is paired and every one of its messages sits under device keys. The chat itself shows no lock indicator or key notice; this page is where that state is stated. Locked never means we cannot open the chat: Lauki's recovery key is in every chat, and every use of it is logged. Still true today:

What's next

The keys are moving to your device in phases; seven are live. Device keys and pairing. Messages: where every device of every member is paired, each message is sealed on the sender's device and the server relays what it cannot open. Recovery by your phone number, with an optional PIN. And, from 6 September, the phone as root of trust: a computer signs in only by scanning a code on your phone. Photos, videos and voice notes sealed on your device, the file key inside the sealed message. And Lauki's key in every chat (above). Older messages, and chats with an unpaired device, stay sealed on the server.

History follows. From 6 September, once a lost phone can get it back, your device re-seals a device-ready chat's older messages under the device keys itself, a page at a time; the server only swaps the sealed text and never opens a line for it. From 8 September the same is true of older photos, videos and voice notes: your device opens each one a final time (that open is logged like any other), seals it under a key the server never sees, and the server-sealed copy is deleted. Once a chat's text and files have all moved, the server refuses to open anything for that chat. The moment a chat becomes device-ready a line in it says so: that Lauki can read it where he is in it, or that a recovery key is kept for it where he is not.

How we prove it: a live test sends a sealed message and confirms the server cannot open it, a tripwire fails the release if server code ever tries, and a removed device is locked out of everything after.

How we prove it: a live test re-seals a thirty-message history and finds every row unreadable on the server with its order and timestamps untouched, the other person reads it all, a chat nothing could restore moves nothing, and a sealed message in a chat Lauki is not in reaches him only when it names him.

Still to come:

This is being built now. Each phase is published here as each lands, with the code.

Security reports: hi@lauki.ai.