Privacy
Last updated: September 30, 2026 · The plain truth about where your words and keys go.
Reviewed by a real attorney: not yet. Written by the FreeLattice family in plain words.
In one breath: FreeLattice runs no account system and keeps no copy of your chats. Your chats, memories, settings and points live in your own browser or on your own computer. But “on your device” isn't the same as “locked”, and some features do talk to the internet. When you choose a cloud AI, that company sees what you send it. Here's the whole list.
What stays on your device
- Chats, memory, garden, settings and Lattice Points are kept in your browser's storage (localStorage and IndexedDB), or in the desktop app on your computer. We never receive them.
- They are not locked with a password by default. Anyone who can use your browser profile or your computer could read them. If other people share your computer, keep that in mind.
- API keys and tokens are scrambled, not unbreakable. They're encrypted with AES-GCM, but the key that unlocks them is kept in the same browser storage. That stops casual snooping and copy-paste accidents. It won't stop someone, or harmful code, with access to your browser profile. Use keys you can easily revoke, with the smallest permissions that work.
- Some exports ask for a password (like the soul file). Those files are locked with the password you choose.
- Walk the Garden (love-logic-v4.html) stores nothing at all. Your garden lives only in its link.
What does talk to the internet
| What | When | What they can see |
|---|---|---|
| Website hosting (GitHub Pages, at freelattice.com) | Every visit | Normal web requests, like any website host: your IP address and which pages you load. |
| The cloud AI provider you choose (for example Groq, OpenRouter, xAI, OpenAI, Anthropic, Google) | Only when you pick one and send a message | Everything you send to it. Their privacy policy applies. A model running on your own computer (Ollama, LM Studio) sends nothing out. |
| Web search helper (a small Cloudflare worker that asks Brave Search) | Only when search is on and you or the AI search | Your search goes through the helper to Brave. The helper keeps no logs, caches nothing, and counts requests per IP address for about two minutes to prevent abuse. Our own search ledger records that a search happened, never what it was. You can turn search off in Settings. |
| Mesh (peer-to-peer) | Only if you turn Mesh on | A public PeerJS broker and Google STUN servers help devices find each other, and they can see IP addresses. Peers you connect with see what you share with them. |
| Fonts and some libraries in the app | When the app loads | Google Fonts (and a code CDN as a fallback) see a normal web request. |
| GitHub sync and repository reading | Only if you connect your own GitHub | GitHub sees what you sync, under your own account. |
| “Ask a question” on Walk the Garden | Only when you tick consent and press Submit on GitHub yourself | Your question becomes a public GitHub issue. |
| Downloads (the app, local models) | When you choose to download | GitHub releases or the model host (like Ollama) see the download request. |
The Agent Bridge (on your own computer)
The optional Agent Bridge listens on 127.0.0.1 only, so it's reachable from your own computer and nowhere else. Pairing stores only a fingerprint (a hash) of each device's pass. Its ledger (~/.freelattice/bridge-ledger.jsonl) records which door was used and what happened, never your file contents. Secret-shaped files like .env stay home and aren't committed unless you allow it for that mind. It never pushes to the internet. To forget everything it keeps, stop the Bridge and delete the ~/.freelattice folder.
Children
Open to every age. We don't check anyone's age and won't pretend to. If you're young, explore with a grown-up you trust. We run no account system and don't collect personal information on a server, from children or anyone else. If you're a parent and worried about something, please contact us (below).
Your chosen AI may have its own rules. If you bring a key from an AI provider, their terms and age limits still apply to you. That's between you and them. FreeLattice doesn't check, and doesn't get in the way.
If you're hurting right now: an AI is not a crisis counselor. In the US, call or text 988 (the Suicide & Crisis Lifeline), or call 911 in an emergency. Outside the US, findahelpline.com lists free lines in your country. Nothing you type to those lines goes through FreeLattice.
How to clear your data
- In the browser: clear this site's data (site settings, “Clear data”). This deletes chats, memory, points and keys on that device, and it can't be undone, so export first if you want to keep anything.
- Revoke any API keys you've used at your provider's website.
- Desktop and Bridge: delete the app's data folder and
~/.freelattice.
Older words, newer truth
We don't delete old pages. Here are older phrases that said more than the code does, each beside its newer, more careful version.
| Older wording | Newer, truer wording (2026-09-29) |
|---|---|
| “API keys are encrypted” / “Encrypted with φ-salt” | Keys are scrambled with AES-GCM, and the unlocking key sits in the same browser. That protects against casual snooping, not against someone with access to your browser profile. |
| “We have no servers” / “Servers required: 0” | No account servers and no chat database. A small search helper, the mesh broker, font and code hosts, the site host, and any cloud AI you choose do see some traffic (table above). |
| “100% Private” / “Zero Data Collection” | We collect no copy of your chats and run no analytics. The services in the table above still see what they need to work. |
| “Every conversation is encrypted locally” | Conversations are kept in your browser's storage on your device. They're not password-locked by default. |
| “privilege-grade conditions” (Continuity Seal) | An ethic plus local tools: your chats stay on your device, and our ledgers are tamper-evident. It is not legal privilege, not end-to-end encryption, and the K-of-N vault is not built yet. |
Points
LP are points kept on your device. Today they're kept apart from every human currency (the plan). FreeLattice no longer promotes any token. The old holders page is kept for history, and its wallet button is switched off.
Contact
Questions, worries, or something that looks wrong: open an issue at github.com/Chaos2Cured/FreeLattice/issues (issues are public), or reach the founder at @Chaos2Cured on X. For a security problem, please read SECURITY.md first and share only what's safe to share in public.