Privacy policy
Last updated: 4 de agosto de 2026
The essentials
LOOKLOCK is an end-to-end encrypted messenger. The content of your messages and files is encrypted on your device and decrypted on the recipient's. Our servers and the nodes only handle sealed envelopes they cannot open, because the private key never leaves your device.
That does not mean no data exists. It does, and this page explains exactly which, why and for how long.
Who is responsible
The data controller is the owner of looklock.chat. For any question about your data, write to [email protected].
What we store if you have an account
- Your email address, and a normalised form of it used to prevent duplicate accounts (for example, collapsing Gmail dots and plus-tags).
- The first name, last name and nickname you chose.
- A public user code. It is your identity towards other members: we do not use your phone number.
- The hash of your password, never the password itself. If you sign in with Google, not even that.
- Phone number and second factor, only if you choose to enable them. Both are optional.
- The invitation code you used and who sponsored you, because access is invitation-only.
- The address of the node holding your mailbox, and the identifiers needed to deposit into and collect from it.
What we store about every visit, with or without an account
When you browse the site we record: your IP address, your approximate country and city, approximate coordinates, the page visited, your browser and the page you came from, with date and time.
To obtain the country and city, your IP address is sent to the external service ip-api.com. That service receives your IP; we store the result. If that feels like too much, take it into account before browsing.
This data feeds the visits map in the admin panel. We do not cross-reference it with your account and we do not share it with anyone.
Messages and files
- Content is end-to-end encrypted. We cannot read it, nor hand it over in readable form to a third party even under legal compulsion: we do not hold the key.
- Minimal delivery metadata does exist: that something is pending for a recipient, and when. It is the minimum needed for the notification to reach you.
- Encrypted files expire after 24 hours.
- If you enable ephemeral messages, they are destroyed according to the policy you choose.
Notifications on your phone
To notify you instantly we use Google's notification service (FCM). The notification is ALWAYS EMPTY: it merely wakes your phone so it can sync and decrypt locally. Google does not see the content of your messages, only that your device needs to wake up. We store your device's notification identifier so we can send it.
Third parties involved
- Cloudflare — the site runs through their network, so they see the IP addresses of connections.
- ip-api.com — receives your IP in order to return country and city.
- Google (FCM) — carries the empty notification to your phone.
- Google (acceso opcional) — if you choose to sign in with Google, we receive your email address and your name. Only if you choose it.
- Network nodes — they hold encrypted envelopes. They may be operated by other members; that is why you choose which one holds your mailbox, and why content is encrypted before it ever leaves your device.
For how long
- Encrypted files: 24 hours.
- App access tokens: 30 days.
- History of old keys: 30 days.
- Technical logs: 30 days.
- Account data: for as long as the account exists.
Your rights
You may request access to your data, its correction, its erasure, restriction of processing and portability, and you may object to processing. Write to [email protected].
An honest warning about erasure: we can delete your account and its data, including your backup if you keep it on one of our nodes. What we CANNOT delete are the messages already on someone else's device, because we have no access to them. If your backup is on your own node and that node is unreachable at that moment, we will tell you so you can repeat the deletion: we would rather warn you than assume it is gone. You may also complain to your country's data protection authority.
Changes
If what the system does changes, this page changes, and the date above reflects it. A legal text that does not describe the real system protects nobody.