← Nightjar Browser

This is the version that shipped with Nightjar Browser 0.2.1. The current one is at /privacy.html.

Privacy Policy — Nightjar Browser

Status: draft. Not legal advice. This describes what the software does, written from the code rather than from intent, and is accurate as of the date below. It needs review by a lawyer in your jurisdiction before you publish it, and the placeholders marked […] must be filled in.

Last updated: 2026-08-19 · Applies to: Nightjar Browser 0.2.0


The short version

Nightjar Browser has no servers. There is no account, no login, no telemetry, and no analytics. Nobody operating this software receives your browsing history, the pages you open, what you type, or what you ask the assistant — because there is nowhere for that to be sent.

Being a browser, it still contacts the websites you visit, exactly as any browser must. The rest of this document is about the handful of other things it contacts, and what it keeps on your own computer.


1. What we collect

Nothing. No usage data, no crash telemetry, no analytics, no unique identifier, no advertising ID.

This is a property of the code, not a promise about our conduct: the application contains no telemetry client and no endpoint to send one to.

2. The AI assistant

The assistant runs entirely on your machine. Model weights are executed by llama-server, a child process on localhost. There is no API key and no inference provider.

The page you are reading, your chat messages, files you attach, and text the assistant writes into form fields are processed locally and are never transmitted to us or to any third party.

3. When Nightjar Browser contacts the network

Beyond the websites you choose to visit:

What Where When
New-tab page and address-bar searches google.com Every new tab; every non-URL search
Model downloads huggingface.co Only when you choose to download a model
Inference runtime downloads github.com Only when a runtime is installed or updated
Update check api.github.com Only when you press "Check for updates"
Ad/tracker filter lists easylist.to Only if "Update the blocklist automatically" is on
Model catalogue sync remote registry Only if "Registry sync" is on (off by default)
Address-bar suggestions your search provider Only if "Online suggestions" is on (off by default)

Each of these sees your IP address, as any web request does. The update check sends a User-Agent of NightjarBrowser/<version> and nothing identifying the machine.

The new-tab page is worth calling out. It opens google.com, so a new tab contacts Google before you type anything, and Google receives that request as it would from any browser. You can change this: set homepage in Settings to the bundled offline start page, which makes no network request at all.

4. What is stored on your computer

In your application data folder (%LOCALAPPDATA%\NightjarBrowser on Windows, ~/Library/Application Support/NightjarBrowser on macOS):

None of this is synchronised, backed up, or transmitted. Deleting the folder deletes all of it.

Cookies. Private browsing is on by default: cookies are held in memory and discarded when the browser closes, so you sign in again each launch. Turning it off in Settings keeps them on disk instead.

5. Crash reports

If the application crashes it writes a report to your own machine and shows it to you. Nothing is uploaded. There is no crash-reporting endpoint. If you choose to send it, you do so yourself, by email, having read it.

A report contains the error, a hardware and OS description, which model was last loaded, and the app's own startup errors. It deliberately excludes browsing history, page URLs, page content, chat messages, attachments, cookies, and the inference server's log.

6. What we send on your behalf

Nightjar Browser sends Global Privacy Control with your requests — Sec-GPC: 1 and DNT: 1 headers, and the navigator.globalPrivacyControl property. Under CCPA/CPRA and several other laws this is a binding instruction to a site not to sell or share your personal information.

On Windows the headers accompany the page itself and the request types that carry tracking — scripts, XHR, fetch, websockets, beacons. They are not attached to images, media, fonts or stylesheets: a video fragment is not something a site makes a selling decision about, and stamping every one of them measurably destabilised the browser during playback.

On macOS they accompany top-level page loads only; WKWebView provides no way to attach headers to subresource requests. The JavaScript property is present everywhere on both platforms.

It also blocks requests to known advertising and tracking hosts, and suppresses cookie-consent banners, before those requests are made.

7. Third parties

Nightjar Browser is not affiliated with the sites you visit. When you download a model or a runtime, that download is subject to the terms and privacy practices of the host (Hugging Face, GitHub) and the licence of the model itself. When you search or open a new tab, that is subject to Google's terms and privacy policy.

8. Children

Nightjar Browser is not directed to children under 13, and collects no personal information from anyone.

9. Your rights

Because we hold no data about you, there is nothing for us to disclose, correct, export, or delete. Everything the software stores is on your computer and under your control. Requests of that kind should be directed to the sites you visited, not to us.

10. Changes

Material changes will be noted here with a new date. Because there is no account, we have no way to notify you individually.

11. Contact

[CONTACT EMAIL] [LEGAL ENTITY NAME AND ADDRESS, IF ANY]