LumeDrop

Privacy

LumeDrop’s privacy properties are structural rather than contractual. Wherever possible the app is built so that a claim here is a consequence of how it works, not a promise about how we behave.

Last updated: 5 August 2026

What we collect

Nothing. There is no account, no sign-in, no email address, no profile, and no contact list. We operate no server that your content or your usage passes through, because the app has no backend at all.

Personal data collectedNone
Account requiredNo
Analytics or telemetryNone
Advertising identifierNot used
Crash reports sent off-deviceNone
Remote configurationNone
Data sold or sharedNone — there is none to sell

How your files move

From the sending device’s screen, as light, into the receiving device’s camera. Local processors do the encoding and decoding; local storage holds the file. Nothing else is involved.

File transferScreen → camera
Internet transferNever
Wi-Fi transferNever
Bluetooth transferNever
Local network transferNever
Cloud storageNever

The distinction we are careful about

LumeDrop never uses a network to transfer your content. That is the precise claim.

It is not a claim that your device is offline, or that the operating system makes no network connections. The App Store or Google Play may need a connection to install or update the app, or to complete and restore the optional Pro purchase. Those are platform services, they never receive transfer data, and the optical transfer itself never needs internet access.

The system share sheet is a related case. After a transfer completes, sharing the received file is something you choose to do, and the destinations it offers may well be network services. That is outside the optical-transfer promise and happens only because you chose it.

QR codes and this website

A LumeDrop code can be encoded as a link so that someone without the app can scan it with their system camera and be pointed at the right app store.

When the app is installed, those links open it directly with no network request at all. When it is not installed, a page on this site loads. In that case the transfer details are not sent to us: they travel in the part of the link after #, which browsers never transmit to servers. Our server sees only that some device requested a page.

You can also turn link-style codes off in the app’s settings, which makes the codes inert — they then cannot cause any network request under any circumstances.

Permissions

Camera. Requested when you choose Receive, or when a code actually needs scanning — not during onboarding and never without context. It is used only to read optical data.

No local-network permission is requested. On Apple platforms that means the local-network prompt will never appear, because there is no code that would trigger it.

What is stored on your device

Sending. No unnecessary permanent copies. Temporary encrypted data is deleted promptly.

Receiving. Only the file you asked for is saved. Temporary artefacts are deleted on success, on failure, and on cancellation alike.

Settings and your Pro purchase status are stored locally. Purchase verification is handled by Apple or Google; we never see it.

Transfer history is not kept.

Diagnostics

Developer diagnostics exist behind a debug build flag and stay on the device. Nothing is transmitted. If you explicitly export diagnostics, payload information is removed first.

What LumeDrop does not protect against

A privacy product that overstates its guarantees is worse than one that states modest guarantees accurately, so:

LumeDrop is not a certified air-gap solution and is not equivalent to a hardware data diode. We hold no such certification and do not describe it as one.

Children

LumeDrop collects no personal data from anyone, including children. There is no account and no content uploaded anywhere.

Changes

The default vision is zero analytics, and that will not change quietly. Any change here would be an explicit, announced decision and would never include your content.

Contact

Questions about privacy: privacy@lumedrop.app