Skip to content
LOAM
  • How it works
  • Features
  • Open source
  • GitHub

Legal

Privacy policy

Last updated 25 September 2026

This policy covers two things: the LOAM app (the Android host app, the web client people join with, and the self-hosted server) and the loamnet.com website. They work very differently, so they have separate sections. LOAM is published by Magic Zebra Ltd.

The LOAM app

Who holds your data

LOAM has no central server and no cloud service. Whoever starts a LOAM network (the host) runs the server on their own phone, laptop or Raspberry Pi. Everything posted on that network is stored on the host's device. Magic Zebra Ltd never receives it, cannot see it, and has no copy of it. The host decides how their network is configured, so on a given network the host controls the data described below.

No accounts, analytics or tracking

The app has no sign-up, and it never asks for an email address, phone number or real name. It contains no analytics, advertising, crash reporting or third-party tracking code.

What the host device stores

  • Your identity on that network: a random user id (such as user.1a2b3c4d…), the display name generated from it or one you choose, and your avatar settings or an avatar image you upload. A session cookie links your browser to that id.
  • What you post: channel messages, replies, direct messages, reactions, and any images or files you attach. A location appears only if you add it to a message yourself.
  • Moderation records: reports you file, and actions the host or moderators take (bans, timeouts, removed messages, join approvals).
  • Your block list: the people you have blocked. The app shows it only to you; it isn't shared with the people you blocked, with moderators, or with other networks.
  • Network settings chosen by the host.

Your own device keeps a copy of the conversations you have open so the app keeps working offline. That copy is deleted when the network is reset.

How long it is kept, and how it is deleted

  • By default, data stays on the host device until someone deletes it. You can delete your own messages. The host can make messages expire automatically after a set time.
  • The host can run an Emergency Reset, which deletes every message, user, image and file on the network and clears the copies on devices connected at the time. A device that was offline clears its copy the next time it reconnects to that network.
  • The host can turn on encryption of the stored database. With encryption on, a reset also replaces the key on the Android host app, and on a computer using a temporary key, so the deleted data cannot be recovered from the device's storage. A computer that uses a fixed passphrase deletes the database files but keeps the same passphrase. Uploaded images and files are stored outside the encrypted database, and a reset deletes them.
  • Uninstalling the Android host app deletes everything it stored.

When data leaves the host device

In the default setup, nothing leaves the host device except the messages delivered to the people on that network, over the local Wi-Fi or hotspot. When you join by scanning the host's QR code, the app encrypts the traffic between your device and the host. Data leaves the host device only if the host turns on one of these features:

  • Sync with other LOAM networks: public channels (their names and descriptions), the messages, replies and reactions posted in them, their attachments, and their authors' user ids, display names and avatar settings are copied to the networks the host links to. Direct messages and private channels are never synced.
  • Remote assistant: if the host connects the assistant to a model running on another computer, messages you send to the assistant go to that computer. The on-device assistant runs entirely on the host phone.
  • Mesh delivery (experimental): messages to your mesh contacts may be carried by other LOAM networks, sealed so that only the recipient can read them.

When the host downloads an on-device assistant model, the host phone fetches the file from Hugging Face, or from a web address the host enters. That request is between the host phone and that site and contains no LOAM user data.

Android permissions

  • Nearby Wi-Fi devices and location: Android requires these to start a local hotspot. LOAM does not read or record your location.
  • Notifications: used to show that the phone is hosting a network.
  • Foreground service and wake lock: keep the network running while the screen is off.
  • Bluetooth and Wi-Fi Aware (mesh, experimental): used to find nearby LOAM devices to exchange sealed messages.

Children

LOAM is not directed at children under 13 and collects no information that would identify a child.

The loamnet.com website

The website uses PostHog analytics, hosted in the EU, to count page visits and clicks on the download and GitHub links. It sets no cookies and stores nothing on your device, and it creates no profile of you. PostHog receives the page address, your browser type and your IP address, from which it derives an approximate country. The site is hosted by Vercel, which keeps standard server logs.

Downloads of the app are served by GitHub (or Google Play), under their own privacy policies.

Contact and changes

Questions about this policy go to Magic Zebra Ltd through the LOAM issue tracker. Questions about data on a particular LOAM network go to that network's host, who holds it. Changes to this policy are published on this page with a new date.

LOAM

Off-grid, local-first messaging.

How it works Features Privacy GitHub
loamnet.com AGPL-3.0 · © 2026 Magic Zebra Ltd