Privacy
LumeDrop’s privacy properties are structural rather than contractual. Wherever possible the app is built so that a claim here is a consequence of how it works, not a promise about how we behave.
Last updated: 5 August 2026
What we collect
Nothing. There is no account, no sign-in, no email address, no profile, and no contact list. We operate no server that your content or your usage passes through, because the app has no backend at all.
| Personal data collected | None |
|---|---|
| Account required | No |
| Analytics or telemetry | None |
| Advertising identifier | Not used |
| Crash reports sent off-device | None |
| Remote configuration | None |
| Data sold or shared | None — there is none to sell |
How your files move
From the sending device’s screen, as light, into the receiving device’s camera. Local processors do the encoding and decoding; local storage holds the file. Nothing else is involved.
| File transfer | Screen → camera |
|---|---|
| Internet transfer | Never |
| Wi-Fi transfer | Never |
| Bluetooth transfer | Never |
| Local network transfer | Never |
| Cloud storage | Never |
The distinction we are careful about
LumeDrop never uses a network to transfer your content. That is the precise claim.
It is not a claim that your device is offline, or that the operating system makes no network connections. The App Store or Google Play may need a connection to install or update the app, or to complete and restore the optional Pro purchase. Those are platform services, they never receive transfer data, and the optical transfer itself never needs internet access.
The system share sheet is a related case. After a transfer completes, sharing the received file is something you choose to do, and the destinations it offers may well be network services. That is outside the optical-transfer promise and happens only because you chose it.
QR codes and this website
A LumeDrop code can be encoded as a link so that someone without the app can scan it with their system camera and be pointed at the right app store.
When the app is installed, those links open it directly with no network request at all. When it is not installed, a page on this site loads. In that case the transfer details are not sent to us: they travel in the part of the link after #, which browsers never transmit to servers. Our server sees only that some device requested a page.
You can also turn link-style codes off in the app’s settings, which makes the codes inert — they then cannot cause any network request under any circumstances.
Permissions
Camera. Requested when you choose Receive, or when a code actually needs scanning — not during onboarding and never without context. It is used only to read optical data.
No local-network permission is requested. On Apple platforms that means the local-network prompt will never appear, because there is no code that would trigger it.
What is stored on your device
Sending. No unnecessary permanent copies. Temporary encrypted data is deleted promptly.
Receiving. Only the file you asked for is saved. Temporary artefacts are deleted on success, on failure, and on cancellation alike.
Settings and your Pro purchase status are stored locally. Purchase verification is handled by Apple or Google; we never see it.
Transfer history is not kept.
Diagnostics
Developer diagnostics exist behind a debug build flag and stay on the device. Nothing is transmitted. If you explicitly export diagnostics, payload information is removed first.
What LumeDrop does not protect against
A privacy product that overstates its guarantees is worse than one that states modest guarantees accurately, so:
- A compromised device. If either device is compromised, an attacker reads the file before it is encrypted or after it is decrypted. No transfer method can fix that.
- Someone who can see the receiving screen. Encryption protects content while it crosses the optical channel, not content displayed on a device other people can see.
- How long a transfer takes. An observer can tell roughly how large a file is from how long the screen is busy. This is unavoidable when the channel is visible.
- Malicious file content. LumeDrop verifies that a file arrived intact; it does not scan for malware and does not judge whether a file is safe to open.
LumeDrop is not a certified air-gap solution and is not equivalent to a hardware data diode. We hold no such certification and do not describe it as one.
Children
LumeDrop collects no personal data from anyone, including children. There is no account and no content uploaded anywhere.
Changes
The default vision is zero analytics, and that will not change quietly. Any change here would be an explicit, announced decision and would never include your content.
Contact
Questions about privacy: privacy@lumedrop.app