Privacy policy
Desktop
app
No telemetry, no analytics, no accounts. Conflux talks to the servers you download from, and to GitHub for updates.
Overview
Conflux is a free, open-source Windows download manager. It has no telemetry, no analytics, no crash reporting and no accounts. It talks to the servers you tell it to download from, and checks GitHub for updates. Everything else stays on your PC.
What the app contacts
- The URLs you add. For each download the engine sends HTTP requests (a probe, then ranged
GETs) to that URL and any redirect targets, from each network adapter you enabled. The server you download from can see your IP address for each adapter. That is how bonding works. - GitHub Releases, for update checks. With Settings > Check for updates on start on (the default), the app fetches a small
latest.jsonfrom the project's GitHub releases about 10 seconds after launch, and again when you click Check for updates. Turn the setting off to stop the automatic check. Installing an update always needs your click. GitHub sees your IP address and the request, as with any download from GitHub. The app adds no identifier or usage data. - A link you paste into the Add dialog. The dialog probes the URL after a paste or edit, to show the file name and size, before you press Download. The server sees that request.
That is all. There are no other outbound connections.
How this was verified
This is checked against the code, not assumed. On 2026-10-01 we searched the Rust crates and the UI for network use and for analytics or crash-reporting dependencies.
- The only HTTP client is
reqwestinconflux-core, used for probes and downloads of URLs you supply. - The updater is configured with a single GitHub Releases endpoint. It is the only call beyond the download engine.
- The UI makes no network calls. Its Content Security Policy only allows local IPC, so even a bug could not make the page contact the internet.
The full audit is in PRIVACY.md. If you find any other call, please report it as a bug.
What is stored on your PC
- Settings: theme, chunk size, adapter toggles and folders, in
%APPDATA%\com.conflux.desktop. - Download history: the URLs, file names and paths of your downloads, in the same folder.
- Update resume list: downloads paused for an update, in
resume_after_update.json. It is deleted once read. - Resume files:
<file>.conflux.jsonnext to a partial download, recording which pieces are done and the server's validators. - Logs: typically in
%LOCALAPPDATA%\com.conflux.desktop\logs. URL credentials and query strings are redacted. URL paths are not.
Nothing here is uploaded. Delete the folders to remove it, and use Settings > Open logs folder to see the logs. Uninstalling never deletes your downloaded files.
Diagnostics
Copy diagnostics puts a text report on your clipboard only when you click it. It is never sent anywhere. You decide whether to paste it into a bug report.
It is built from an allow-list: app, OS and WebView versions, settings values, adapter names, types and state, the subnet of each adapter address with the host part masked (for example 192.168.1.x), and the last warning and error log lines with URLs, file paths and IP addresses scrubbed. Adapter names appear as Windows reports them, so glance at the text before posting it.
Downloaded files
Downloaded files get the standard Windows "downloaded from the internet" marker (Zone.Identifier), containing the source URL without credentials, so Windows can warn you before you open an executable. The marker lives with the file on your disk.
Browser extension
The optional browser extension has its own, shorter policy: browser extension privacy policy.
Contact
Questions? Open an issue on our GitHub Issues page, or email Manjeet Singh at manjeetsgh11@gmail.com.