This is the version that shipped with Nightjar Browser 0.3.1. The current one is at /privacy.html.
Status: draft. Not legal advice. This describes what the software does,
written from the code rather than from intent, and is accurate as of the date
below. It needs review by a lawyer in your jurisdiction before you publish it,
and the placeholders marked […] must be filled in.
Every factual claim here is checked against the code by
tests/test_legal_docs_match_the_code.py, so a change that makes one of them
untrue fails the test suite rather than sitting here unnoticed. TERMS.md
covers using the software and LICENSE covers the software itself.
Last updated: 2026-09-29 · Applies to: Nightjar Browser 0.3.1
The current version is the one at trynightjar.com/privacy.html. It supersedes any other copy, including one that came with an earlier download. What changed, and when, is in §10, with each earlier version kept on the site.
Nightjar Browser has no servers. There is no account, no login, no telemetry, and no analytics. Nobody operating this software receives your browsing history, the pages you open, what you type, or what you ask the assistant — because there is nowhere for that to be sent.
Being a browser, it still contacts the websites you visit, exactly as any browser must. The rest of this document is about the handful of other things it contacts, and what it keeps on your own computer.
Nothing. No usage data, no crash telemetry, no analytics, no unique identifier, no advertising ID.
This is a property of the code, not a promise about our conduct: the application contains no telemetry client and no endpoint to send one to.
The assistant runs entirely on your machine. Model weights are executed by
llama-server, a child process on localhost. There is no API key and no
inference provider.
The page you are reading, your chat messages, files you attach, and text the assistant writes into form fields are processed locally and are never transmitted to us or to any third party.
One setting can change that, and only if you set it. Under AI settings you may point the browser at another OpenAI-compatible engine. Nightjar also offers engines it finds already running on this computer — Ollama, LM Studio, llama.cpp, vLLM — on their usual loopback ports; those are other programs on your own machine, and using one sends nothing over a network, though what that program does with what it receives is governed by that program and not by us.
An engine at an address that is not this computer is different in kind: everything the assistant reads is sent to it, which means the open page, your chat messages and any file you attached leave this machine and are handled by whoever runs that server. Nightjar warns before saving such an address, marks it as remote in the model picker, and never selects one on its own. Discovery of local engines can be turned off entirely in the same settings pane.
Beyond the websites you choose to visit:
| What | Where | When |
|---|---|---|
| Searches | google.com |
Only when you search, from the start page or the address bar |
| Model downloads | huggingface.co |
Only when you choose to download a model |
| Inference runtime downloads | github.com |
Only when a runtime is installed or updated |
| Update check | api.github.com |
Once on launch, and when you press "Check for updates". Sends the version you have and nothing else. Switch it off in Privacy & blocking |
| Ad/tracker filter lists | easylist.to |
The first time the browser starts, then every three days while "Update the blocklist automatically" is on (on by default). A plain download: nothing identifying is sent |
| Model catalogue sync | remote registry | Only if "Registry sync" is on (off by default) |
| Address-bar suggestions | your search provider | Only if "Online suggestions" is on (off by default) |
Each of these sees your IP address, as any web request does. The update check
sends a User-Agent of NightjarBrowser/<version> and nothing identifying the
machine.
The new-tab page makes no request at all. Opening a tab loads a page that ships inside the application: a search box, no script, no fonts or images fetched from anywhere. Nothing is contacted until you search, and searching goes to Google exactly as typing the same words into the address bar does.
You can change this under Settings → Privacy & blocking → New tabs open on, which also offers Google's own page and a blank tab.
In your application data folder
(%LOCALAPPDATA%\NightjarBrowser on Windows,
~/Library/Application Support/NightjarBrowser on macOS):
Settings — your preferences, in settings.json.
Browsing history — off by default. Nothing is written down unless you turn on Remember the pages I visit under Privacy & blocking, and turning it back off deletes what was recorded. When on: recent addresses, kept locally and capped.
The tabs you had open — their addresses only, so a crash puts them back rather than losing them. Not scroll position, not what you typed into a page, not per-tab history. Removed by Clear browsing data along with everything else.
Closing the browser normally does not bring them back next launch: a new window starts on a new tab, as in every other browser, and the addresses are erased as it closes. They are kept past a normal close only if you turn on "Reopen my tabs when I start the browser" in Settings.
Sites you have made a choice about — where you allowed ads, allowed or blocked pop-ups, or turned on form autocomplete. Only the site names, only the ones you chose, shown one at a time in the shield panel while you are on that site. On Windows they are encrypted at rest with DPAPI, like your profile; on macOS they are stored in the same owner-only file as the other settings.
Bookmarks — locally. These are kept whatever the history setting says: a bookmark is something you asked to keep.
A list of what you downloaded — the address, filename and where it was saved. Follows the history setting: with history off it is emptied when you close the browser. The downloaded files are never touched — deleting your own file would be data loss rather than privacy.
Saved conversations — off by default. Chats stay in the window and are gone when you close it, unless you tick Save conversations on this computer above the Recent chats list. Turning it off deletes what was saved. When on, they are stored locally and never uploaded.
Downloaded models — often several gigabytes.
Filter lists — the compiled ad/tracker block list.
A key for the local AI engine — a random token in engine-key.txt,
rewritten each time the engine starts and deleted when it stops. It authenticates this browser to the llama-server process on your own
machine; it is not an account, and it is not sent anywhere.
Profile and password data — encrypted at rest using Windows DPAPI or the macOS Keychain, so it is readable only by your operating system account.
None of this is synchronised, backed up, or transmitted. Deleting the folder deletes all of it.
Cookies. Private browsing is on by default: cookies are held in memory and discarded when the browser closes, so you sign in again each launch. The same goes for the page cache and the web engine's own record of pages visited — the browser runs its web engine in InPrivate mode, which keeps them in memory only. Turning it off in Settings keeps them on disk instead.
If the application crashes it writes a report to your own machine and shows it to you. Nothing is uploaded. There is no crash-reporting endpoint. If you choose to send it, you do so yourself, by email, having read it.
A report contains the error, a hardware and OS description, which model was last loaded, and the app's own startup errors. On Windows it also lists what Windows Error Reporting recorded: the faulting module and exception code. It deliberately excludes browsing history, page URLs, page content, chat messages, attachments, cookies, and the inference server's log.
fatal.log. Some crashes kill the process outright, giving the application
no chance to write anything. For those, a Python stack trace is written to
fatal.log in the data folder as the process goes down. It holds file names,
line numbers and function names — not variables, not page text, not chat
messages. It does contain the full paths of the files involved, which on
Windows include your user name.
Crash dumps are a different thing, and are not ours. If you or your system
administrator have switched on Windows' LocalDumps for this application,
Windows writes a memory dump to %LOCALAPPDATA%\CrashDumps. A full dump is a
copy of everything the process had in memory, which can include the page you
were reading and what you asked about it. Nightjar does not create these, does
not read them, and never attaches one to a report — it only tells you
that one exists, so you can decide what to do with it. Deleting them is safe.
Send feedback in the ⋮ menu writes a report and shows you all of it before anything happens to it. Nothing is uploaded. The buttons copy it to your clipboard and open a feedback form in a tab, or save it to a file; the browser itself makes no request. You choose between a mail draft, which opens your own mail app with the report ready to send, and copying it to paste into a feedback form — and in both cases what leaves is a decision you take, after reading it.
The report carries the version, your hardware and OS, which model and runtime are loaded, whether Smart App Control is on, and the recent lines from the Activity tab. It excludes browsing history, page content, chat messages, attachments and the inference server's log — the same exclusions the crash report makes, for the same reason.
The page you are on and your last question can be added by ticking a box. It is off by default, and the preview grows to show exactly what ticking it adds, so nothing travels that you have not read.
Nightjar Browser sends Global Privacy Control with your requests —
Sec-GPC: 1 and DNT: 1 headers, and the navigator.globalPrivacyControl
property. Under CCPA/CPRA and several other laws this is a binding instruction
to a site not to sell or share your personal information.
On Windows the headers accompany the page itself and the request types that carry tracking — scripts, XHR, fetch, websockets, beacons. They are not attached to images, media, fonts or stylesheets: a video fragment is not something a site makes a selling decision about, and stamping every one of them measurably destabilised the browser during playback.
On macOS they accompany top-level page loads only; WKWebView provides no way to attach headers to subresource requests. The JavaScript property is present everywhere on both platforms.
It also blocks requests to known advertising and tracking hosts, and suppresses cookie-consent banners, before those requests are made.
This policy covers the website as well as the software, because the two are published by the same company and the site is where you are most likely to be reading it.
The site sets no analytics. No Google Analytics, no Plausible, no telemetry, no advertising pixel, no tracking cookie. There is no account and no login, so there is nothing to log you into.
What it does contact. The download button asks api.github.com for the
latest release so the version and file size shown are current. GitHub receives
that request, including your IP address, as it would for any page that embeds
a resource. That is the only third party the site talks to.
Do Not Track. Several laws, California's among them, require a site to say how it responds to a browser's Do Not Track signal. The honest answer here is that it makes no difference: the site does not track visitors whether the signal is present or not, so there is no behaviour for it to change. Global Privacy Control is treated the same way, for the same reason.
Cookies. The site sets no cookie for its own purposes. A component library used in the layout can set one to remember whether a panel is open; it is functional, stays on your device, and identifies nothing.
Legal pages. The privacy policy, terms, licence and third-party notices on this site are generated from the product's own repository, which is the copy its test suite checks against the code. Where the two could ever disagree, the repository copy is the one that has been verified.
Nightjar Browser is not affiliated with the sites you visit. When you download
a model or a runtime, that download is subject to the terms and privacy
practices of the host (Hugging Face, GitHub) and the licence of the model
itself — LICENSE §5 lists the components that ship inside the application and
the licences they arrive under. When you search or open a new tab, that is subject to Google's terms
and privacy policy.
Nightjar Browser is not directed to children under 13, and collects no personal information from anyone.
Because we hold no data about you, there is nothing for us to disclose, correct, export, or delete. Everything the software stores is on your computer and under your control. Requests of that kind should be directed to the sites you visited, not to us.
Material changes are listed here, newest first, with the date and the release they apply to. Because there is no account, we have no way to notify you individually. Each earlier version is kept at trynightjar.com, linked at the foot of this page.
trynightjar@outlook.com
Purple Comet LLC, a California limited liability company.