There are two kinds of privacy, and people constantly mistake one for the other.
The first kind is architectural: the data simply does not exist in a collectable form. No one can hand over what was never gathered. The second kind is promissory: someone can see everything and pledges not to look, not to keep it, or not to tell. Those pledges hold right up until a court says otherwise.
Lightning's privacy is mostly the first kind. Spark's is mostly the second. The moment you connect a Spark wallet to a public identity, like a Nostr account, you convert your payment history into exactly the kind of asset a warrant can reach.
Why Lightning is hard to subpoena
On the Lightning Network, individual payments never land on the blockchain, and onion routing ensures each hop only learns its immediate neighbors. No participant is designed to hold the full path from sender to receiver. If a court served a routing node, there would be little to produce: a fragment at most, with no reliable link to the real endpoints. You cannot compel disclosure of a picture nobody assembled. That is architectural privacy, and it is robust precisely because it does not depend on anyone's good behavior.
Why Spark is easy to subpoena
Spark works the opposite way. The operators co-sign every transfer, so by construction they can see who paid whom, how much, and when. The privacy you get is whatever the operators choose to offer on top of that full visibility: a privacy mode you have to enable, a policy, an assurance that logs are not kept. Critics have a blunt and accurate name for this: VPN-style privacy, where your protection is a company's promise not to reveal its logs.
Promises are only as good as the pressure they can withstand. No-logs assurances in the VPN industry have faced this test in court more than once, with the same lesson each time: a pledge not to look is worthless against a subpoena that demands you produce what you can see.
Nostr is the join key
On its own, the operator's view is pseudonymous. It sees accounts and payments, not necessarily names. Privacy advocates hold on to that thread, and it is exactly the thread a public identity snaps.
A Nostr identity is a public key, usually tied to a persistent and often real-world-linked persona. Nostr users routinely publish a Lightning address in their profile so people can zap them. Trace the chain. Your public Nostr identity points to your Lightning address. That address resolves through a Spark-backed wallet, which in many current implementations uses a single static identifier for all of your activity. The operator already sees every payment tied to that identifier. Link one to the other and the pseudonym collapses into a named person with a complete payment ledger.
This is not theoretical. In mid-2026, a tool called SparkStalker demonstrated that for some Spark-based wallets you could enter a human-readable username and pull up the transaction history linked to it. The builder was not trying to encourage surveillance. He wanted to make the exposure visible, because people were using these wallets for sensitive payments without realizing their history could be looked up by anyone. In a hostile environment that is not a privacy inconvenience; it is a safety risk.
The compelled-disclosure chain
Once identity and payments are joined inside the operator, privacy stops being a cryptography question and becomes a legal-process question. That is a fight the individual almost always loses.
The Spark operators are not shadowy. They are named, regulated companies in known jurisdictions. For custody, that is reassuring. For disclosure, it is the opposite: a named, regulated company is precisely the entity that receives, and must answer, warrants, subpoenas, and reporting demands. One independent review noted that Flashnet, one of the named operators, reserves the ability to take compliance-based action. The regulatory machinery is already visibly in motion: the same MiCA and DAC8 reporting rules that pushed Wallet of Satoshi to shut its custodial service across the EU in early 2026 are built around obligations to collect and hand over data. Some of these regimes do not even wait for a warrant; they require proactive reporting.
There is often a gag attached too. Under many compelled-disclosure orders, the company cannot tell you it happened. The failure mode is not a scary letter in your mailbox. It is your payment history quietly leaving the building without you ever finding out.
Two precisions
First, note where the identity link comes from. Spark itself has largely avoided KYC so far; part of its appeal to wallets is adding Lightning while sidestepping identity collection for now. In most cases the operator is not the one attaching your name. You are, by wiring a public Nostr profile or a published Lightning address to an account the operator can already see. For a privacy-conscious audience that is the bitter irony: people deanonymize themselves through their own public identity while believing they are on permissionless rails.
Second, keep two operator behaviors apart. Spark operators deleting old key material is real, but that is forward secrecy for custody. It stops them from reversing or stealing a past transfer. It says nothing about whether they retain a queryable log of who paid whom. That is a separate policy choice, and if they keep such a log, it is discoverable.
The line that matters
Spark relocates your payment privacy from something no one can be forced to surrender into something a company can be compelled to hand over. Nostr is the join key that makes the compelled data about you specifically.
I am not a lawyer, and what is actually compellable varies by jurisdiction and by what each operator stores. The structural point holds regardless of the fine print: architectural privacy fails closed, promissory privacy fails open, and a public identity decides which one you have.
Next: why this is not only a problem for Spark users, and how concentrating the network erodes the anonymity every Lightning payment depends on.
