"No-log" is a claim anyone can print on a page. Here's what it means for us specifically, across each product, so you can check it rather than trust it.
Search queries are processed in memory and discarded once the response is sent. No query, IP, or session identifier is written to disk at any point. Crawl targets and the resulting document index are the only persistent data — both are already public on the dashboard.
Standard web server access logs (IP, timestamp, path) are disabled at the edge, not filtered afterward. There's nothing to filter because nothing is written.
No analytics SDK, no crash reporter, no update pinger. The client only makes outbound connections you initiate, joining a server, checking for an update if you ask it to. A full list of endpoints it can reach is in the docs shipped with the download.
[Placeholder — space reserved for an independent audit of the retention setup above, once one has been commissioned. Until then, treat the claims on this page as self-reported.]
There's a signed warrant canary on this site, updated monthly. If it stops updating, assume the worst and act accordingly, see contact for the current signature and key.
This page describes current practice, not a legal contract. It will be updated if anything here changes, and the change will be noted on the roadmap.