This policy is for the Android app Lantern, published as app.lantern. It is not the policy for lantern.io, GetLantern, or “Lantern: Fast & Private VPN” (org.getlantern.lantern).
1. Who we are
Lantern is a device-local reader and peer mesh. You capture pages and keep files on your phone, then optionally share offered copies with nearby phones over Bluetooth and local Wi-Fi. The developer does not operate an account system or a content server for the app.
For privacy questions, use the support email shown on this app’s Google Play store listing. That listing is the official contact point for app.lantern.
2. Short version
- No Lantern account. No sign-in.
- Library pages, captured articles, and files stay on your phone unless you offer them on the mesh.
- We do not run a backend that receives your library, files, location, or browsing history.
- Capture fetches a URL you type. That request goes to the site, not to us.
- Mesh uses Google Play services Nearby Connections on a channel you choose. Nearby radios can be observed.
- Mesh sharing is sold as a Google Play subscription. Google processes the purchase.
- Location permission is used to discover nearby devices. The app does not read, store, or upload GPS coordinates.
3. Information the app stores on your device
The following stays in app storage on the phone (SQLite, files, and preferences) unless you delete it or uninstall the app.
| Data | What it is | Why |
|---|---|---|
| Captured pages | URL, title, site, excerpt, stored HTML/text, size, time, whether it is offered | Offline reading |
| Field pack pages | Bundled reference articles shipped in the app | Offline reading without a network |
| Files (“drops”) | Name, type, size, copy of the file, whether it is offered, optional sender id | Keep and open files; optional mesh share |
| Callsign and channel | A display name and shared mesh word (default “circle” until changed) | Find the right nearby phones |
| Mesh settings | Whether radios are on and whether new captures are offered | Remember your choices |
| Play entitlement cache | Timestamp that a current mesh subscription was last seen | Allow mesh for up to 35 days without a live Play check |
Android backup, if enabled on the device, may include app files and preferences. The app does not transmit that backup to the developer.
4. Information we do not collect
- Name, email, phone number, or government ID
- Precise or approximate location coordinates
- Address book, photos (except files you explicitly import), or SMS
- Advertising IDs or analytics events
- A browsing history, other than URLs you choose to capture, stored locally
- Payment card details; Google Play handles payment
There is no crash-reporting SDK, advertising SDK, or developer analytics SDK in the production app.
5. Network activity (what leaves the phone)
Capture
When you save a page, the app requests that URL over the internet (HTTPS when the site supports it). The destination site, your ISP, and anyone on that path can see that a device fetched the page. The request uses a generic Android browser user-agent plus “Lantern”. Tracking query parameters are stripped from the stored URL when recognized. Images and scripts from the live site are not kept. Captured pages are stored as text/HTML on device.
Tapping a link in the reader opens it in your system browser. That browser has its own policy.
Google Play Billing
Mesh sharing requires the Play product mesh_monthly. Google processes the subscription, receipt, and fraud checks under Google’s Privacy Policy. The app only learns whether entitlement is active and stores a local timestamp.
Google Play services — Nearby Connections
If you tap Start on Mesh, the app advertises and discovers other Lantern phones on the same channel using Bluetooth, Wi-Fi, and Wi-Fi Direct through Google Play services. Nearby devices, not only Lantern users, may observe that a radio is advertising. Offered titles and files are sent only after a link is accepted, and only to that peer. You can compare a short PIN shown on both phones before trusting a link.
Mesh is off until you start it. Library, capture, and reading work without mesh.
6. Location permission
Android requires location permission for Bluetooth and Wi-Fi peer discovery on many versions. Lantern requests approximate and precise location only so Nearby Connections can find phones on your channel.
- The app does not read the GPS fix.
- The app does not show a map of you.
- The app does not send coordinates to the developer or a Lantern server.
- Bluetooth scan and nearby Wi-Fi permissions are declared as not used for location.
If you deny location or related nearby-device permissions, mesh discovery will fail. Capture and reading still work.
7. What other people can see
| Situation | Who can see it |
|---|---|
| Page kept private (Offer off) | Only this phone |
| Page or file offered, mesh off | Still only this phone until you Start mesh |
| Offered item, mesh live, same channel | A linked Lantern phone on that channel can see the title and pull a copy |
| Default channel “circle” | Any nearby Lantern user on “circle” can attempt to link. Change the channel if that is not your circle. |
| Capture while online | The site you fetch, and the network path to it |
| Play subscription | Google, as your Play account holder |
Pulled pages arrive with Offer off on the receiving phone. Files you receive are kept on that phone. Anyone you share a channel with is a person you must trust with whatever you offered.
8. Children
Lantern is not directed at children under 13 (or the equivalent age of digital consent in your country). We do not knowingly collect personal information from children. If you believe a child has stored personal data in the app, uninstall it or use Burn on this device in Settings, and contact us via the Play listing.
9. Retention, deletion, and your controls
- Delete a page in the reader.
- Remove a file with a long-press in Files.
- Stop offering with Offer on a page, or long-press a file.
- Stop radios with Stop on Mesh.
- Burn on this device in Settings clears local identity, library data, and files on that phone. It does not erase copies already pulled by someone else.
- Uninstall removes remaining app storage on that phone.
- Cancel the subscription in Google Play. Mesh locks when entitlement lapses; a 35-day local cache may still allow mesh after a last successful Play check.
We cannot remotely delete data from your phone or from a peer who already pulled a copy. There is no developer-side profile to access, export, or erase.
10. Security — honest limits
Local storage is not encrypted beyond whatever Android provides for the app sandbox. Mesh traffic uses Google Nearby Connections; treat offered items as visible to a determined nearby observer and to anyone on your channel who links. Capture is an ordinary web request. Cached pages are a snapshot; they do not make you invisible on later live visits. Do not treat Lantern as a VPN, anonymity network, or warrant-proof archive.
11. Legal bases (EEA / UK / similar)
- Contract / requested service: storing pages and files you save; running mesh you start.
- Legitimate interests: local entitlement cache so a paid mesh user can still share in a blackout.
- Legal obligation: if a lawful request is ever made about the developer; note we hold no user library.
Google Play is an independent controller for your Google account and payments. Nearby Connections runs in Google Play services on the device.
12. International processing
The developer does not host user content. If you use Capture or Play, those third parties may process data in other countries under their own terms.
13. Changes
We will update this policy when the app’s data practices change and will change the date above. Material changes will be reflected in the Play listing privacy URL.
14. Play Data safety summary
- Personal data: No developer collection. Data stays on device or is shared peer-to-peer when offered.
- Location: Not collected. Permission is used for device discovery only.
- Photos/files: Not collected by the developer.
- Web browsing history: Not collected by the developer.
- Ads: Not sold or used for ads.
- Third-party sharing: No developer data share. Google Play and capture destinations are services you contact.
- Developer-server encryption: Not applicable; there are no developer servers.
- Deletion: Available on-device through delete, burn, or uninstall.
15. Contact
Developer contact: the email address published on the Google Play store listing for Lantern (app.lantern).
Android application ID: app.lantern