Privacy Policy
Lifeline is built so that there is almost nothing to have a privacy policy about. It has no accounts, no central servers, and no company sitting between you and the people you message. This page explains, plainly, what that means for your data.
1. Scope
This policy covers the Lifeline mobile and desktop applications ("the app"), the underlying open-source protocol, and this marketing website. Because Lifeline is open source, the ultimate authority on how it behaves is the source code itself, which you can inspect at any time.
2. No accounts, no identifiers we hold
Using Lifeline does not require you to create an account or provide a name, email address, or phone number. Your identity in the network is a cryptographic key pair generated on your device and stored only on your device. We never receive it.
3. Your messages
- Messages are encrypted end-to-end on your device before they are sent. Only the intended recipient's device holds the key needed to decrypt them.
- Messages travel directly between devices over Bluetooth and Wi-Fi, hopping from phone to phone. They do not pass through, and are not copied to, any server we operate.
- Devices that relay a message on its way to the recipient carry it as an opaque, encrypted envelope. A relay cannot read the contents and cannot determine the sender or recipient from the message itself.
- We have no ability to access, read, log, or produce the contents of your messages, because they never reach us.
4. Data stored on your device
To function, the app stores certain information locally on your own device, such as your cryptographic keys, your message history, your contacts, and queued messages waiting to be delivered. This data stays on your device under your control. You can erase it at any time, including instantly with the app's panic-wipe feature.
5. Location data
Some features — such as SOS beacons, "find each other," and geocast — use your device's location. When you use them:
- Location is read from your device only when you invoke a feature that needs it, and only to the extent that feature requires.
- Location shared in an SOS or with your group is end-to-end encrypted the same way messages are, and is sent only to the recipients you intend.
- We do not collect, aggregate, or retain any location data on a server. There is no server.
6. Relaying for others
As part of the mesh, your device may carry and forward other people's encrypted messages toward their destinations. You cannot read this traffic, and it is not retained beyond what is needed to attempt delivery. This is how the network stays alive without infrastructure — and it is designed so that relaying never exposes you to the contents of what you relay.
7. This website
This site is a static informational website. It does not use advertising cookies or third-party trackers. If you submit the contact form, the information you provide is used solely to respond to your inquiry. Our hosting provider may process standard server logs (such as IP addresses and request times) for security and reliability, as is typical for any website; we do not use these to build profiles of visitors.
8. Optional internet gateways
Lifeline can opportunistically bridge messages to the internet through a device that has connectivity. Where a message you send is routed over the public internet via such a gateway, it remains end-to-end encrypted in transit. Any optional hosted services offered separately (for example, a team or organization product) are governed by their own terms and notices presented at sign-up; the core mesh described here does not depend on them.
9. Children
Lifeline is not directed to children and does not knowingly collect personal information from children. Because the app does not collect personal information centrally at all, there is no such data for us to hold.
10. Changes to this policy
We may update this policy as the project evolves. Material changes will be reflected here with a new "last updated" date and, where appropriate, noted in the project's release notes.
11. Contact
Questions about privacy? Reach us through the contact page or open a discussion on GitHub.