Privacy Policy
Akari is an AT Protocol client. This policy explains what data the app handles, where it goes, and what stays on your device.
What stays on your device
- Your authentication credentials — JWTs and refresh tokens for app-password sessions, or DPoP-bound access/refresh tokens plus the per-account DPoP keypair for OAuth sessions. All stored encrypted in the device's secure storage.
- Cached feed, profile, and conversation data, so the app can render immediately on launch instead of round-tripping every screen.
- Local preferences — theme, language, accessibility toggles, muted words, your trusted-verifier list, and similar settings.
What goes to the AT Protocol services you sign into
Akari is a client. Posts, likes, follows, mutes, blocks, messages, and every other record you create are written to the AT Protocol services you have authenticated against (your Personal Data Server, AppView, labelers, etc.). Lucid Softworks does not operate those services and does not see those records.
What goes to Lucid Softworks
Akari sends crash reports and limited diagnostic logs to a Lucid Softworks-operated telemetry endpoint when crash reporting is enabled in your build, in order to debug stability issues. Reports include the crash stack, app version, OS version, and device model. They do not include your post content, message content, or authentication credentials. You can opt out by uninstalling the app.
Third-party services
Akari may render content from third parties (image hosts, video services, link previews, GIF providers, etc.). Loading that content involves a network request to the third party, which may log standard HTTP metadata. Akari does not share your account identifier with third parties beyond what's already public in the AT Protocol record being rendered.
Children
Akari is not directed at children under 13. We do not knowingly collect data from children. Account-eligibility rules are enforced by the AT Protocol service you sign into, not by Akari.
Account deletion
Akari does not host your account — your AT Protocol identity is owned by your Personal Data Server (PDS). Account deletion has two parts:
- Delete your AT Protocol account at the PDS that hosts it. For Bluesky-hosted accounts that's bsky.app/settings/account; for self-hosted or third-party PDSes, follow that PDS's own deletion flow. Deleting at the PDS is what removes your records (posts, likes, follows, etc.) from the network.
- Remove Akari's local data from the device. Open Akari → Settings → Account → Wipe all data. This clears your stored credentials (JWTs / OAuth tokens / DPoP keys), cached feed and profile data, and local preferences. You can also achieve the same outcome by uninstalling the app.
Crash reports and diagnostic logs already sent to Lucid Softworks telemetry (see "What goes to Lucid Softworks") do not contain account identifiers tied to you personally and are aged out automatically. If you want them removed sooner, email [email protected] with the approximate dates you used the app.
Changes
This policy may change. The "last updated" date at the top reflects the most recent revision.
Contact
For privacy questions, contact us at github.com/lucid-softworks/akari/issues.