“No analytics or tracking by default.”
The repository also calls Luczystrap offline-first and says network calls are limited. This is the developer’s published intent, not a field-by-field privacy disclosure.
Privacy map · versioned evidence
Luczystrap is designed as a local-first Windows bootstrapper, but “local-first” is not the same as “no network traffic.” This page maps local storage, optional integrations, historical endpoints, and what remains unverified in release 1.4.9.
Diagram, not a packet capture. Destinations shown are established from documentation or historical public code. Exact 1.4.9 traffic remains an open verification task.
01 / Reading the claim
A privacy promise, a historical implementation, and current binary behavior are different facts. Combining them would produce a confident answer the evidence cannot support.
The repository also calls Luczystrap offline-first and says network calls are limited. This is the developer’s published intent, not a field-by-field privacy disclosure.
The same settings model enabled activity tracking and Discord Rich Presence by default, while optional server data features called ipinfo.io and RoValra. “Analytics off” did not mean “all network features off.”
The current app source is absent. There is no public endpoint inventory, event schema, retention schedule, clean traffic capture, or source-to-binary build proof for 1.4.9.
02 / Interactive data map
Each route separates what may stay on your PC, what may leave it, the best available control, and the version of the evidence. Choose a feature to inspect its privacy surface.
Feature or operation
Luczystrap keeps settings, state, logs and downloaded components on Windows. Installing or updating Roblox and checking Luczystrap releases requires network services even when analytics is disabled.
03 / Evidence ledger
This is a disclosure page, not a substitute for a formal legal privacy policy. It names confirmed historical behavior and keeps current unknowns visible until they are answered with reproducible evidence.
EnableAnalytics = false..ROBLOSECURITY in historical 1.3 code.04 / Data and controls
The matrix is deliberately versioned. “Historical” means the route was found in tag 1.3; it does not silently claim that closed-source 1.4.9 behaves identically.
| Feature | Data or context | Destination / storage | Best control | Evidence |
|---|---|---|---|---|
| Settings, mods and logs | Configuration, feature state, diagnostic messages and local assets | Documented portable folder, AppData config and LocalAppData logs | Keep diagnostic bundles private; remove local data only when no longer needed | README |
| Analytics | Exact events and identifiers are not documented | Current destination unknown | Leave analytics disabled; verify after every update | 1.3 default only |
| Discord Rich Presence | Experience, creator, server type, session time, images; optional account and join context | Discord desktop RPC / Discord | Disable Rich Presence, account display and join buttons | 1.3 source |
| Server location | Roblox server IP address; city, region and country response | ipinfo.io and local runtime cache | Leave server details/location off | 1.3 source |
| Server uptime | Place ID and server/job ID; first-seen estimate | RoValra endpoints and local runtime cache | Leave server uptime off | 1.3 source |
| Historical Account Switcher | Session cookie, user ID, username, display name, avatar URL | Local settings protected with Windows DPAPI; Roblox APIs for validation | Do not paste the cookie; use Roblox’s official web Account Switcher | Sensitive · 1.3 |
| Plugins and custom integrations | Whatever executable third-party code can access with the process permissions | Plugin-defined local or remote destination | Install only inspected code; remove anything you cannot verify | No sandbox proven |
Privacy control is feature-specific. Disabling analytics does not disable updates, Roblox traffic, a user-enabled integration, or network access performed by third-party plugin code.
05 / Minimum-sharing setup
There is no verified “privacy mode” switch that controls every data path. Minimize exposure by enabling one capability at a time and treating integrations, account tools, plugins and diagnostic bundles as separate decisions.
Do not block all traffic blindly. Roblox installation, updates and play need network access. The goal is to remove optional routes while preserving the operation you intentionally requested.
Begin without plugins, custom integrations, Account Switcher or server enrichment.
Confirm the setting after installation and after upgrades; a historical default is not permanent proof.
Turn off Rich Presence, account display, join buttons, server details and uptime independently.
The core launcher does not require your Roblox session cookie. Prefer Roblox’s official switcher.
Inspect author, source, release and network behavior before loading executable code.
A clean Windows capture across install, idle, update, launch and play is still required for the 1.4.9 endpoint inventory.
06 / FAQ
Every answer names the version boundary. That is more useful than repeating “private,” “offline,” or “safe” without defining the data, destination and control.
A complete current answer is not yet verifiable. Historical 1.3 code stored settings, logs and optional account data locally and made feature-dependent requests to Roblox, GitHub, ipinfo.io, RoValra and Discord-related components. The current 1.4.9 application source and a clean network capture are not public, so this page does not promise zero collection.
No complete offline guarantee can be supported. The README describes Luczystrap as offline-first and offline-friendly, but installation, Roblox updates, version checks and some integrations depend on network services. Offline-first is a design goal, not proof of zero network traffic.
The public 1.3 Settings model set EnableAnalytics to false by default, and the current README says no analytics or tracking by default. The event schema, destination, retention, consent flow and exact 1.4.9 behavior are not publicly documented, so disabled-by-default is the strongest supportable statement.
Historical public code contains requests to Roblox services and CDN, GitHub, ipinfo.io for server location, RoValra for server uptime and Discord Rich Presence components. The exact 1.4.9 endpoint list still requires a clean network capture; see the integration evidence map for feature-level detail.
The core launcher does not need it. Historical 1.3 Account Switcher code optionally requested the cookie, validated it with Roblox, encrypted the saved value with Windows DPAPI for the current user and logged a short plaintext preview when applying it. Current 1.4.9 behavior is not verifiable, so I recommend that you do not paste a session cookie into the app.
Historical code could publish the experience, creator, server type, session timing, images and optional account identity or join buttons through Discord Rich Presence. Disable Rich Presence and account display if you do not want gameplay context shown to Discord contacts.
A plugin is executable code running with the permissions of its host process. The public SDK does not establish a permission sandbox. Review the exact plugin source and release before installing it, and assume it may access files or the network until proven otherwise.
Use the core launcher only; leave analytics, activity tracking, Discord Rich Presence, account display, server details, server uptime, Account Switcher, plugins and custom integrations off unless you need them. Keep the network access needed for the chosen operation, then verify the current build with a clean traffic capture.
07 / Evidence
Official documentation and public code establish product claims and historical implementation. Automated binary analysis is labeled separately and never treated as proof of collection.
Checked August 5, 2026. “Current” refers to the latest published Luczystrap release found during review: 1.4.9, published November 5, 2025. This page describes technical evidence and user controls; it is not a contractual privacy notice and does not invent a controller, retention period, or deletion right that the project owner has not yet published.