PRIVACY / PLAIN TEXT

What is onthe disk.

This describes the implementation. It is short because it is a description rather than a defence, and it changes when the code changes rather than when the quarter does.

Last updated

21 AUGUST 2026 · LIVARA 0.9.16 (116)


The cryptographic detail sits on the security page, and the parts that are checkable are in the Proof Lab.

Direct conversations

One-to-one message bodies and media are encrypted on your device. Current secure chats use the hybrid-PQ LVR1 ratchet; the server stores ciphertext, routing metadata, timestamps, receipts and the public material clients need. It cannot open the content.

Groups and channels

In a compatible private group, LGS1 encrypts text, edit content and the messages carrying unique attachment keys with a different signed sender chain for each member. Attachment bytes, captions, file names and render metadata are encrypted before upload.

Livara still sees and controls group membership, routing, timing and ciphertext size. A compromised service can insert a member before LGS1 key redistribution. Reactions and some control relationships remain visible. Channel content is server-readable.

Livara AI and Livara AI Pro

Livara AI runs on the Android device. Livara AI Pro is available only to accounts selected by an administrator and only when the user chooses it. Text needed for an AI Pro request is sent through Livara to Google; encrypted chats require per-chat permission for Smart Action and related context features. Livara does not store those AI prompts or results as AI history.

Credentials and recovery

Login uses SRP, so your password is never transmitted during authentication; the server holds a verifier instead. Recovery format v7 uploads only an encrypted identity bundle and authenticates its identity epoch and backup generation. It needs your recovery phrase and does not restore chat history or ratchet sessions.

What the service stores

  • Username, profile fields, privacy preferences, contacts and chat folders
  • Dialog membership, messages, reactions, receipts, edits, deletes and sync cursors
  • LVR1 direct ciphertext and LGS1 private-group ciphertext
  • Opaque encrypted private attachment objects; channel content remains readable
  • Push tokens when you enable notifications; encrypted-message mobile pushes contain only a generic wake event
  • Operational security records such as revoked-token signatures

Media access

Message, profile, story and wallpaper media requires authentication and an object-level permission check on every request. Media is not placed in a cross-account service-worker cache, and unattached or expired uploads are cleaned up automatically.

What you can do

Export your account data, clear your copy of a conversation, delete messages where your role allows it, sign out of a device, or delete the account entirely after proving your password.

Contact

Privacy questions go through the existing Livara support channel. The canonical copy of this page is at https://chat.livara.org/privacy, and it is updated when the implementation changes rather than on a schedule.

Open LivaraGet the app