PRIVACY / PLAIN TEXT

What is onthe disk.

This describes the implementation. It is short because it is a description rather than a defence, and it changes when the code changes rather than when the quarter does.

Last updated

21 AUGUST 2026 · LIVARA 0.9.52 (156)


The cryptographic detail sits on the security page, and the parts that are checkable are in the Proof Lab.

Direct conversations

One-to-one message bodies and media are encrypted on your device. Current secure chats use the hybrid-PQ LVR1 ratchet; the server stores ciphertext, routing metadata, timestamps, receipts and the public material clients need. It cannot open the content.

Groups and channels

Private group conversations are fully end-to-end encrypted using LGS1 sender keys. Every message, edit, photo, video, file attachment, voice note, and caption is encrypted directly on user devices before upload. Only active group participants have the cryptographic keys to decrypt group content.

Public broadcast channels are designed for open distribution and are readable by design. Group metadata (such as timestamps and delivery routing) is stored to enable real-time device synchronization across web and Android.

Livara AI and Livara AI Pro

Livara AI runs on the Android device. Livara AI Pro is available only to accounts selected by an administrator and only when the user chooses it. Text needed for an AI Pro request is sent through Livara to Google; encrypted chats require per-chat permission for Smart Action and related context features. Livara does not store those AI prompts or results as AI history.

Credentials and recovery

Login uses SRP, so your password is never transmitted during authentication; the server holds a verifier instead. Recovery format v7 uploads only an encrypted identity bundle and authenticates its identity epoch and backup generation. It needs your recovery phrase and does not restore chat history or ratchet sessions.

What the service stores

  • Username, profile fields, privacy preferences, contacts and chat folders
  • Dialog membership, messages, reactions, receipts, edits, deletes and sync cursors
  • LVR1 direct ciphertext and LGS1 private-group ciphertext
  • Opaque encrypted private attachment objects; channel content remains readable
  • Push tokens when you enable notifications; encrypted-message mobile pushes contain only a generic wake event
  • Operational security records such as revoked-token signatures

Media access

Message, profile, story and wallpaper media requires authentication and an object-level permission check on every request. Media is not placed in a cross-account service-worker cache, and unattached or expired uploads are cleaned up automatically.

What you can do

Export your account data, clear your copy of a conversation, delete messages where your role allows it, sign out of a device, or delete the account entirely after proving your password.

Contact

Privacy questions go through the existing Livara support channel. The canonical copy of this page is at https://chat.livara.org/privacy, and it is updated when the implementation changes rather than on a schedule.

Open LivaraGet the app