Last updated 1 October 2026
Security and privacy
Loki Eye records your cameras to your own disk. This page lists every connection the app makes to us, exactly what it sends, and how to keep your recorder locked down.
Your footage stays on your recorder
Live video, recordings, snapshots, camera addresses, and camera passwords never leave the recorder unless you send them somewhere yourself. There is no Loki Eye cloud and no crash reporting. The only usage data the app sends is a small heartbeat, listed below, which you can switch off.
What the app sends to us
The app makes at most three kinds of request to us. Like any web request, each one also reveals your IP address to the server that answers it.
| Request | When | What it sends |
|---|---|---|
| Update check | At start and every 6 hours. You can switch it off in Settings. | Downloads the public list of the latest release. The only thing it tells us is your app version. |
| Licence check | Only with a paid licence: at start, every 6 hours, and when you add or remove the licence. | Your licence key, the app version, a random one-time value, and a machine ID. The machine ID is a one-way hash of your computer’s ID, so the ID itself never leaves your machine. |
| Usage statistics | At start (retried every 5 minutes until it gets through), then every 6 hours. On by default. Switch it off in About › Usage statistics, or set DO_NOT_TRACK=1. | An install ID (a one-way hash of the machine ID), the app version, operating system, processor type, whether it is free or licensed, and how many cameras are set up. No camera names, addresses, or recordings, and no email or licence key. We keep the country Cloudflare works out from your IP address, but not the address itself. |
The About tab in the app shows exactly what the usage heartbeat contains and when it was last sent. Development builds never send it.
The free edition needs no account and never makes a licence check. Your email address is not sent when you activate a licence: the app checks it against the key on your own computer.
Connections you set up
Webhooks, MQTT, and Home Assistant only receive data when you configure them, and only at the addresses you enter. None of them go through us.
Signed licences and updates
Licence keys and every reply from the licence server are signed. The app checks each signature, and each reply must answer that request’s one-time value, so a replayed or tampered reply is rejected. A valid reply keeps working offline for up to 48 hours.
The desktop app checks the signature of every update before installing it, and refuses any update that was not signed by us.
Protecting the recorder
The free edition can only be viewed on the recorder computer itself. With a licence, other devices must sign in with an access password that you set on the recorder:
- The password is stored only as a bcrypt hash.
- Repeated wrong attempts from one address are slowed down.
- A signed-in browser gets an HTTP-only, same-site cookie.
The recorder serves its interface over plain HTTP on your local network. Keep it on a network you trust. To watch from outside your home, connect to your network over a VPN such as WireGuard or Tailscale. Do not forward the recorder’s port on your router.
Your account and payments
You sign in to your lokieye.com account with a one-time link sent to your email, so there is no password for us to store or leak. Sign-in forms are protected by Cloudflare Turnstile, and your session is kept in an HTTP-only secure cookie.
Lemon Squeezy is our merchant of record and handles payments, with cards processed by Stripe. Your card details go straight to them and never reach us. The privacy policy lists every service provider and what each one receives.
What we have not done yet
- Our macOS builds are not yet notarised by Apple, so macOS asks you to confirm the first launch.
- Loki Eye has not had an independent security audit, and we hold no security certification.
We will update this page when either of these changes.
Reporting a vulnerability
If you find a security problem in Loki Eye or on this site, email support@lokieye.com with “Security” in the subject. Please include the steps to reproduce it, and give us a reasonable time to fix it before you publish. We will reply, keep you posted on the fix, and credit you if you want. Our security.txt has the same contact details.