Last updated 1 October 2026

Security and privacy

Loki Eye records your cameras to your own disk. This page lists every connection the app makes to us, exactly what it sends, and how to keep your recorder locked down.

Your footage stays on your recorder

Live video, recordings, snapshots, camera addresses, and camera passwords never leave the recorder unless you send them somewhere yourself. There is no Loki Eye cloud and no crash reporting. The only usage data the app sends is a small heartbeat, listed below, which you can switch off.

What the app sends to us

The app makes at most three kinds of request to us. Like any web request, each one also reveals your IP address to the server that answers it.

RequestWhenWhat it sends
Update checkAt start and every 6 hours. You can switch it off in Settings.Downloads the public list of the latest release. The only thing it tells us is your app version.
Licence checkOnly with a paid licence: at start, every 6 hours, and when you add or remove the licence.Your licence key, the app version, a random one-time value, and a machine ID. The machine ID is a one-way hash of your computer’s ID, so the ID itself never leaves your machine.
Usage statisticsAt start (retried every 5 minutes until it gets through), then every 6 hours. On by default. Switch it off in About › Usage statistics, or set DO_NOT_TRACK=1.An install ID (a one-way hash of the machine ID), the app version, operating system, processor type, whether it is free or licensed, and how many cameras are set up. No camera names, addresses, or recordings, and no email or licence key. We keep the country Cloudflare works out from your IP address, but not the address itself.

The About tab in the app shows exactly what the usage heartbeat contains and when it was last sent. Development builds never send it.

The free edition needs no account and never makes a licence check. Your email address is not sent when you activate a licence: the app checks it against the key on your own computer.

Connections you set up

Webhooks, MQTT, and Home Assistant only receive data when you configure them, and only at the addresses you enter. None of them go through us.

Signed licences and updates

Licence keys and every reply from the licence server are signed. The app checks each signature, and each reply must answer that request’s one-time value, so a replayed or tampered reply is rejected. A valid reply keeps working offline for up to 48 hours.

The desktop app checks the signature of every update before installing it, and refuses any update that was not signed by us.

Protecting the recorder

The free edition can only be viewed on the recorder computer itself. With a licence, other devices must sign in with an access password that you set on the recorder:

  • The password is stored only as a bcrypt hash.
  • Repeated wrong attempts from one address are slowed down.
  • A signed-in browser gets an HTTP-only, same-site cookie.

The recorder serves its interface over plain HTTP on your local network. Keep it on a network you trust. To watch from outside your home, connect to your network over a VPN such as WireGuard or Tailscale. Do not forward the recorder’s port on your router.

Your account and payments

You sign in to your lokieye.com account with a one-time link sent to your email, so there is no password for us to store or leak. Sign-in forms are protected by Cloudflare Turnstile, and your session is kept in an HTTP-only secure cookie.

Lemon Squeezy is our merchant of record and handles payments, with cards processed by Stripe. Your card details go straight to them and never reach us. The privacy policy lists every service provider and what each one receives.

What we have not done yet

  • Our macOS builds are not yet notarised by Apple, so macOS asks you to confirm the first launch.
  • Loki Eye has not had an independent security audit, and we hold no security certification.

We will update this page when either of these changes.

Reporting a vulnerability

If you find a security problem in Loki Eye or on this site, email support@lokieye.com with “Security” in the subject. Please include the steps to reproduce it, and give us a reasonable time to fix it before you publish. We will reply, keep you posted on the fix, and credit you if you want. Our security.txt has the same contact details.