Your Privacy & Security at Lantern โ
Welcome! We know privacy matters to you. It matters to us too. This guide explains how we protect your information and what you can do to stay safe.
What Makes Lantern Different โ
Most social apps collect as much data as possible. Lantern does the opposite.
What We DON'T Collect โ
โ Photos of you - Ever. Not allowed in the app.
โ Your real name - Optional. If provided, it's encrypted.
โ Your age - We verify you're 18+, but don't display it.
โ Your location history - Deleted after 48 hours automatically.
โ Your chat logs - Stored only on your device, not our servers.
What We DO Collect โ
โ
Lantern Name - A generated username like "Sapphire Lantern"
โ
Interests - Tags you choose (Coffee, Jazz, Hiking, etc.)
โ
Mood - Your current vibe (Chatty, Quiet, Exploring)
โ
Check-ins - Where you light your lantern (deleted after 48hr)
โ
Birth date - Encrypted, only for age verification
The difference: Most of what we collect is PUBLIC and helps you meet people. The sensitive stuff (birth date) is ENCRYPTED so we can't see it.
Your Location Privacy โ
How We Use Your Location โ
Lantern needs your location to enable proximity features:
- Waves: Connecting with people physically nearby (within ~50 feet)
- Lantern Hub: Showing who's at the same venue as you
- Check-ins: Verifying you're actually at a venue for merchant offers
How We DON'T Use Your Location โ
โ No location history - We don't track where you've been
โ No movement tracking - We don't monitor your routes
โ No location profiles - We don't build a map of your habits
โ No GPS storage - Your coordinates are NEVER saved to our database
The Technical Details (Simple Version) โ
When you use a proximity feature:
- Browser asks permission - You see "Allow Lantern to access your location?"
- You grant access - Your device gets GPS coordinates (just for this moment)
- We check proximity - "Are you within 50 feet of User X?" or "Are you at Venue Y?"
- We answer yes/no - The feature works (or doesn't)
- We forget your location - GPS coordinates deleted immediately
What we keep (briefly):
- Check-in event: "User checked into Bar XYZ at 8pm" (deleted after 48 hours)
- Wave event: "User A waved to User B" (deleted after 7 days)
What we NEVER keep:
- Your GPS coordinates
- Your movement patterns
- Where you went yesterday, last week, or last year
Browser Protection โ
Your browser has extra safeguards:
- You must click "Allow" each time you open the app (or grant persistent permission)
- Only Lantern's website can request location (third-party scripts cannot)
- You can revoke permission anytime in browser settings
- You can use the app without granting location (some features won't work)
What About Stalking/Harassment? โ
Protection layers:
- Zero-knowledge design - Nobody knows who's nearby until you BOTH wave
- Block feature - Blocked users never see you or your location
- Pattern detection - Our system flags users who suspiciously check into the same venues as you repeatedly
- No real-time presence - We don't broadcast "User X is at Bar Y right now" to everyone
If you feel unsafe:
- Use the block feature immediately
- Report the user (we investigate patterns)
- Contact us at safety@ourlantern.app
How Encryption Protects You โ
Your Passphrase = Your Privacy โ
When you sign up, you create a passphrase (like a super-strong password). This passphrase encrypts your sensitive information on YOUR device before it ever reaches our servers.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Your Device โ
โ โ
โ Birth date: 1990-05-15 โ
โ โ โ
โ Your passphrase encrypts it โ
โ โ โ
โ Encrypted: "k2j3n4lk5j6h7..." โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Our Servers โ
โ โ
โ Received: "k2j3n4lk5j6h7..." โ
โ (Gibberish without your passphrase) โ
โ โ
โ โ ๏ธ We CANNOT decrypt this โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโWhat this means for you:
- โ Even if our servers are hacked, your data is safe
- โ Even if the government demands your info, we can't give plaintext
- โ ๏ธ If YOU forget your passphrase, your data is GONE forever
Creating a Strong Passphrase โ
Your passphrase protects everything. Make it strong:
Good examples:
Coffee&Jazz2025!Luna*Hikes@MidnightBookWorm#415Reader
Bad examples:
passwordโ12345678โlanternโ
Requirements:
- At least 12 characters
- Mix of uppercase and lowercase
- At least one number
- At least one special character (!@#$%^&*)
Pro tip: Write it down and keep it somewhere safe (NOT in a digital file).
What Happens to Your Data โ
Automatic Deletion โ
We don't hoard your data. Here's what gets auto-deleted:
| What | When |
|---|---|
| Venue check-ins | After 48 hours |
| Wave requests | After 7 days |
| Chat messages | When you delete them (stored on your device only) |
| Your entire account | 30 days after you request deletion |
Manual Deletion โ
You control your data:
- Delete account: Settings โ Privacy & Data โ Delete Account
- Clear check-in history: Automatically happens every 48 hours
- Remove interests: Settings โ Profile โ Edit interests
Chat Privacy โ
How Chat Works โ
Unlike most apps, Lantern doesn't store your chats on our servers. Here's the flow:
Your message
โ
Encrypted on YOUR device
โ
Relayed through our server (not stored)
โ
Delivered to recipient's device
โ
Stored on THEIR device (not ours)What this means:
- โ We can't read your chats
- โ We can't hand over chat logs (we don't have them)
- โ ๏ธ If you lose your device, your chats are gone (unless you backup)
What We CAN See โ
We can see metadata (not content):
- Who sent a message to whom
- When it was sent
- Approximate size of message
We CANNOT see:
- What the message says
- Any photos/content shared
This is similar to how your phone company knows you called someone but doesn't record the conversation.
Your Rights โ
Data Access โ
You have the right to see all data we have on you:
- Settings โ Privacy & Data โ Download My Data
- We'll send you a file with everything we store
- Most of it will be encrypted (you'll need your passphrase to read it)
Data Portability โ
You can export your data and take it elsewhere:
- Interests, mood, Lantern name โ JSON file
- Check-in history โ CSV file
- Chat messages โ Stored on your device already
Data Deletion โ
You can delete your account anytime:
- Settings โ Privacy & Data โ Delete Account
- Confirm you understand data is unrecoverable
- Account deleted within 24 hours
- All data purged within 30 days
Warning: Deletion is permanent. We CANNOT recover your account.
Safety Tips โ
Protect Your Passphrase โ
๐ Do:
- Write it down on paper
- Store it in a safe place
- Use a password manager (optional)
โ Don't:
- Share it with anyone
- Save it in a text file or email
- Use the same passphrase for other sites
Meeting People Safely โ
Lantern helps you meet people at public venues. Stay safe:
โ Do:
- Meet in public places only
- Tell a friend where you're going
- Trust your instincts
- Use the block/report feature if needed
โ Don't:
- Share personal info (address, full name) in chat
- Meet at private locations
- Feel pressured to meet if uncomfortable
Recognize Scams โ
If someone asks for:
- Money or gift cards
- Your passphrase
- Photos or videos
- Personal information (SSN, credit card)
๐จ That's a scam. Block and report immediately.
Security Features in Your Control โ
Location Tracking (Opt-In) โ
By default, we DON'T track your location history. You can opt-in if you want:
Settings โ Privacy & Data โ Location History
- OFF (default): Check-ins deleted after 48 hours, no history kept
- ON: We remember your recent spots to suggest venues
Even with tracking ON, data is deleted after 48 hours.
Profile Visibility โ
Control what others see:
- Lantern Name: Always visible (that's how you connect)
- Interests: Always visible (helps people find you)
- Mood: Always visible (shows your vibe)
- Age: NEVER visible to anyone
- Birth date: NEVER visible, encrypted
Questions & Concerns โ
What if I forget my passphrase? โ
Bad news: Your encrypted data is gone. We CANNOT reset it.
Why: If we could reset it, we could also decrypt your data, which defeats the purpose.
Prevention: Write it down NOW and keep it safe.
What if my device is lost or stolen? โ
Immediate steps:
- Use another device to log into Lantern
- Change your passphrase (Settings โ Security โ Change Passphrase)
- Report device stolen to your phone carrier
What happens to your data:
- Encrypted data on our servers: Still safe (needs passphrase)
- Chat messages on lost device: Potentially accessible if device was unlocked
- Solution: Enable device encryption on your phone (iOS/Android settings)
What if Lantern gets hacked? โ
What hackers would get:
- Encrypted birth dates (gibberish without passphrase)
- Public data (Lantern names, interests, moods)
- No chat logs (we don't store them)
What hackers would NOT get:
- Your passphrase (never stored)
- Your decrypted birth date (we can't decrypt it)
- Your chat messages (on your device, not our servers)
What we'd do:
- Notify all users within 72 hours
- Force password resets if auth system compromised
- Publish transparency report
- Work with security experts to patch vulnerability
Can the government read my data? โ
What we'd provide if ordered by court:
- Encrypted data (we'd say: "we cannot decrypt this")
- Public profile data (Lantern name, interests, moods)
- Account metadata (creation date, last login)
What we CANNOT provide:
- Decrypted private data (we don't have passphrase)
- Chat message content (not stored on our servers)
Our position: We comply with valid legal requests, but our architecture ensures we have minimal useful data to hand over.
How We're Getting Better โ
We're Always Improving โ
Security is a journey, not a destination. Here's what we're working on:
Now:
- โ Zero-knowledge encryption for sensitive data
- โ Device-local chat storage
- โ Automatic data deletion
Next 6 months:
- ๐ External security audit
- ๐ Bug bounty program
- ๐ Backup codes (in case you forget passphrase)
Future:
- ๐ฎ Signal Protocol (gold standard for chat encryption)
- ๐ฎ Hardware security key support
- ๐ฎ Even better metadata protection
We Want Your Feedback โ
Found a security issue? Have a suggestion?
Please tell us:
- Email:
security@ourlantern.app(coming soon) - GitHub: Report vulnerabilities responsibly
- In-app: Settings โ Help โ Security Concern
We take every report seriously and respond within 48 hours.
Trust, But Verify โ
How to Verify Our Claims โ
We say we can't decrypt your data. Here's how you can verify:
- Check the code: Our encryption code is open for review
- Ask an expert: Share our docs with a security professional
- Read audits: We'll publish external audit reports (when available)
We believe in transparency over trust. Don't just take our word for itโverify it yourself.
Summary: Your Data in 60 Seconds โ
โ
Your passphrase encrypts sensitive data on YOUR device
โ
Our servers only see encrypted gibberish
โ
Your chats are stored on YOUR device, not our servers
โ
Your check-ins are auto-deleted after 48 hours
โ
Your account can be deleted anytime, permanently
โ
We can't decrypt your data even if forced to
โ
We welcome security feedback and research
Bottom line: We built Lantern so we don't have your private data. Because if we don't have it, we can't lose it, leak it, or be forced to hand it over.
Questions? Settings โ Help โ Security & Privacy
Stay safe out there! ๐