Effective Date: 25 August 2026
CallSealSkr ("the App") is published by MidMightBit Games, based in Melbourne, VIC, Australia. The App is a communication verification tool for the Solana Seeker device. It records that a phone call took place — its direction, timestamp and duration — creates a SHA-256 hash of that metadata, and records the hash on the Solana blockchain as immutable proof that a call occurred. It does not read your messages, your call log or your contacts, and it does not store the other party's number.
CallSealSkr is built with privacy as a core principle. We store no communication data in the cloud, we use no third-party analytics or tracking SDKs, and we serve no advertisements. Everything the App records stays on your device. Only two things ever leave it: your wallet's public address, sent to a public Solana RPC provider when you check SGT status, pay, or restore a purchase; and an anonymous, aggregate usage count — a single event name such as app_open with no identifier of any kind — sent to an endpoint of ours. Both are described in section 9, the analytics in section 11a, and you can switch the analytics off in Settings > Privacy.
Critical Privacy Commitment: CallSealSkr never captures call audio and never transmits the content of a call or message anywhere. Nothing but a SHA-256 hash is ever sent on-chain, and that hash cannot be reversed to recover the original metadata.
What is stored on your device: the App keeps a local log of the communication events it observes. That log holds only the type of call, its timestamp and its duration. It does not hold the other party's phone number, which the App discards and never stores. Both settings are in Settings > Privacy, where you can also set records to auto-delete after 7, 30 or 90 days. This data never leaves your device.
Under the EU General Data Protection Regulation (GDPR) and UK GDPR, the legal basis for processing your wallet public address (if you choose to connect a wallet) is legitimate interest (Article 6(1)(f)) — specifically, the legitimate interest in providing SGT verification and hash recording access that you voluntarily opt into by connecting your wallet. This processing is minimal, expected by the user, and proportionate.
The legal basis for processing communication metadata to generate hashes is consent (Article 6(1)(a)) — you explicitly enable call monitoring within the App, and you can disable it at any time.
Under the Australian Privacy Act 1988 and Australian Privacy Principles (APPs), the wallet public address is collected in accordance with APP 3 (collection of solicited personal information) for the primary purpose of on-chain identity verification and feature access. Communication metadata processing is covered by APP 3 as information collected for the primary purpose of hash generation at your request.
When you enable communication monitoring, CallSealSkr processes metadata as follows:
At no point does any raw communication metadata leave your device. Only the cryptographic hash is recorded on-chain.
"Collect" here means sent to us or to any third party. Nothing in this list is transmitted off your device, and the items in section 4 are stored on your device only.
CallSealSkr requests only these permissions:
READ_CALL_LOG,
RECEIVE_SMS, READ_SMS and READ_CONTACTS. These are gone.
The App no longer reads your call log, your messages or your contacts, and no longer records
SMS at all. Google Play Protect blocks installation of apps requesting SMS or call-log
permissions when they are not distributed through Google Play, so those features could not be
offered to you at all — and removing them means the App now holds far less about you.
CallSealSkr supports optional wallet connection via Sign In With Solana (SIWS) using the Solana Mobile Wallet Adapter (MWA). Wallet connection enables:
The MWA protocol operates locally between apps on your device. No wallet data is transmitted to external servers by MidMightBit Games. We store only your wallet public address (encrypted). We never have access to your private keys or the ability to sign transactions on your behalf without your explicit approval in your wallet app.
CallSealSkr charges 0.0607 SOL or 651 SKR for one hash credit (one credit = one record hashed on-chain), and 0.0607 SOL or 682 SKR (614 SKR for SGT holders) as a one-off for Premium, which unlocks automatic hashing without per-hash credits. Seeker Genesis Token holders who installed before 8 September 2026 hash for free and need neither. These transactions are processed entirely on the Solana blockchain:
The App makes the following network requests:
api.mainnet-beta.solana.com: one of the App’s two network destinations. To verify Seeker Genesis Token status, fetch a recent blockhash, submit payments and hash memos, and restore purchases, the App sends your wallet's public address to this provider. The provider receives your IP address and that public address. Private keys never leave your wallet. No fallback or alternative RPC provider is used.app_open) and nothing else. No
phone number, no message, no proof, no wallet address, no device identifier. Approximate
country is derived at the edge from the request; the raw IP is never logged or stored.
See “Anonymous Analytics” below — you can switch this off in Settings.All network communications use HTTPS/TLS encryption in transit. The App enforces HTTPS for all connections and does not permit cleartext traffic.
The App does not collect or store your IP address. However, when the App makes network requests to Solana RPC endpoints, your IP address is transmitted to those services as part of standard internet protocol. MidMightBit Games has no access to any logs or data collected by third-party RPC providers. We encourage you to review their respective privacy policies.
All of your call and proof data is stored locally on your device. The only information sent to a server we operate is the anonymous, aggregate usage count described in “Anonymous Analytics” below — never your numbers, messages, contacts, proofs or wallet address. Security measures include:
CallSealSkr reports anonymous, aggregate usage counts to our own endpoint (callsealskr-analytics.vercel.app) so we can see which features are used.
What is sent: one event name and nothing else. The whole request body is
{"event_type":"app_open"}. Never a phone number, a message, a message preview, a
contact, a hash, a proof, a wallet address, a device or advertising identifier, an install id,
a session id or an IP address.
Purchases are counted too. The counted event names include purchase outcomes — that a payment in SOL or SKR was made, that premium was unlocked, or that a purchase was restored. Even for those, the request carries only the event name: never an amount, a price, a wallet address or a transaction signature. Your payments are on the public Solana blockchain either way; what we hold is a count, not a link to you.
What is stored: a running count per event, per approximate country, per day. Country comes from the edge; the raw IP is never logged. Because no identifier is ever sent, two events cannot be linked to each other or to you — so no profile, no session history and no per-user retention can be built from it.
Turning it off: Settings → Privacy → “Anonymous analytics”. When off, nothing is sent at all.
Because the data is anonymous and aggregate it is not personal information under the Australian Privacy Act 1988, and is consistent with GDPR (Recital 26), CCPA, LGPD, APPI and PIPA without requiring consent.
CallSealSkr does not create user accounts. There is no registration, no login system, and no user profiles. Wallet connection via SIWS is optional and used solely for SGT verification and hash recording payments. Disconnecting your wallet removes all wallet-related data from your device.
The App uses the following third-party libraries:
The App does NOT include any:
Your data is retained locally on your device for as long as the App is installed. Data is automatically deleted when you:
Communication records, hashes, app settings and wallet data are removed when the App is uninstalled or its data is cleared. The App sets allowBackup="false", so none of it is copied into an Android cloud backup and none of it survives uninstalling the App.
Disconnecting your wallet removes the wallet address, label and SGT status. It does not delete your communication records or app settings — delete those with the auto-delete setting or with Clear Data.
Because nothing survives uninstalling, a paid SKR Premium unlock would otherwise be lost. Settings > Wallet > Restore purchases re-reads your own payment from the blockchain and restores the unlock. Per-hash credits are single-use consumables and are not restorable.
Note: SHA-256 hashes that have been recorded on the Solana blockchain are immutable and cannot be deleted. This is an inherent characteristic of blockchain technology. However, these on-chain hashes cannot be reversed to recover the original communication metadata.
When making RPC calls, your wallet public address and IP address are transmitted to Solana RPC endpoints to retrieve on-chain data and submit hash transactions. Your wallet public address is already publicly visible on the Solana blockchain. No user-specific data is sent to MidMightBit Games servers (we have none).
We rely on the public nature of blockchain data and your explicit request to use this service as the basis for these transmissions. For EU/UK users, this processing is necessary for the performance of the service at your request (GDPR Article 49(1)(b)).
You can delete all App data at any time by:
This satisfies the right to erasure under GDPR Article 17, UK GDPR, and the Australian Privacy Act. Note that on-chain hashes cannot be deleted due to the immutable nature of blockchain technology, but they contain no personally identifiable information.
All data stored by the App is visible within the App itself (hash history, app settings, and wallet connection status). You may also contact us to request a summary of any data associated with your wallet address.
As the only externally-sourced data is your wallet public address from the Solana blockchain, the App displays factual on-chain data. If you believe any data is inaccurate, you can disconnect and reconnect your wallet to refresh on-chain data.
You may restrict the processing of your wallet address at any time by disconnecting your wallet. You may disable call monitoring at any time to stop metadata processing. This stops all data processing and removes your wallet address from local storage. You may reconnect at any time to resume the service.
You may object to the processing of your wallet address at any time by disconnecting your wallet, which removes your wallet address from local storage. You may object to communication metadata processing by disabling monitoring in the App settings.
As all data is stored locally on your device, you have full control over your data at all times. Your wallet public address is the only externally-sourced data element and is already in your possession.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise your rights, use the in-app controls or contact us at the address below.
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with rights to access, correct, delete, and port your data. The legal basis for processing is your consent, given by connecting your wallet and enabling communication monitoring. You may withdraw consent at any time by disconnecting your wallet and disabling monitoring. Contact us to exercise your rights.
If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) provides you with rights regarding your personal information. The App processes only your wallet public address, stored locally on your device. You may withdraw consent at any time by disconnecting your wallet. No personal information is transferred to MidMightBit Games servers. To exercise your rights under PIPEDA, contact us at the address below or use the in-app controls.
If you are located in South Africa, the Protection of Personal Information Act (POPIA) provides you with rights to access, correct, and delete your personal information. Processing is based on the legitimate interest of providing the service you voluntarily opted into. Your wallet public address is stored locally on your device with AES-256 encryption. You may object to processing and request deletion at any time by disconnecting your wallet.
If you are located in Japan, the Act on the Protection of Personal Information (APPI) provides you with rights to request disclosure, correction, suspension of use, and deletion of your personal data. The App stores only your wallet public address locally on your device. No data is provided to third parties as defined under APPI. To exercise your rights, use the in-app controls or contact us.
If you are located in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) provides you with rights as a Data Principal including the right to access, correct, and erase your personal data. Consent is obtained when you connect your wallet and enable communication monitoring. You may withdraw consent at any time by disconnecting your wallet and disabling monitoring. The App does not process data of children (persons under 18). No personal data is transferred to MidMightBit Games servers.
If you are located in Turkey, the Kişisel Verilerin Korunması Kanunu (KVKK, Law No. 6698) provides you with rights to learn whether your data is processed, request information about processing, learn the purpose of processing, request correction, request deletion, and object to processing. Your wallet public address is the sole data element, stored locally with encryption. Contact us to exercise your rights under KVKK.
If you are located in Switzerland, the revised Federal Act on Data Protection (FADP/nDSG) provides you with rights to access, rectify, and delete your personal data. Processing is based on legitimate interest (providing the service you requested). Cross-border data transfers to RPC providers comply with FADP requirements as they involve only publicly available blockchain data and your IP address via standard internet protocol. Contact the FDPIC or us to exercise your rights.
If you are located in Singapore, the Personal Data Protection Act (PDPA) provides you with rights to access and correct your personal data, and to withdraw consent. The App processes only your wallet public address with your consent (given by connecting your wallet). You may withdraw consent at any time by disconnecting your wallet. The App does not use your data for marketing purposes.
If you are located in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) provides you with rights to access, correct, delete, restrict, and port your personal data. Processing is based on your consent, given by connecting your wallet. You may withdraw consent at any time by disconnecting your wallet. The App does not collect sensitive data as defined under the Thai PDPA.
If you are located in Nigeria, the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023 provide you with rights to access, rectify, and delete your personal data. Consent is obtained when you connect your wallet. The App processes minimal data (wallet public address only), stored locally with AES-256 encryption. No data is shared with third parties beyond RPC endpoints. Contact us to exercise your rights.
If you are located in Indonesia, Law No. 27 of 2022 on Personal Data Protection (PDP Law) provides you with rights to access, correct, delete, and withdraw consent for processing of your personal data. Consent is obtained when you connect your wallet. You may withdraw consent and delete all data at any time by disconnecting your wallet.
If you are located in Vietnam, Decree No. 13/2023/ND-CP on Personal Data Protection provides you with rights to be informed of, consent to, access, and delete your personal data. The App stores only your wallet public address locally on your device. No personal data is transferred to MidMightBit Games servers. Contact us to exercise your rights.
If you are located in South Korea, the Personal Information Protection Act (PIPA) provides you with rights to access, correct, suspend processing, and delete your personal information. The App collects only your wallet public address, stored locally with encryption. No data is provided to third parties as defined under PIPA. Processing may be suspended at any time by disconnecting your wallet. Contact us or the Personal Information Protection Commission (PIPC) to exercise your rights.
CallSealSkr is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. The App is intended for users who own a Solana Seeker device. If you believe a child under 13 has used this App and connected a wallet, please contact us and we will provide guidance on removing the data.
We may update this Privacy Policy from time to time. Changes will be reflected in the effective date above. We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.
For questions about this Privacy Policy, data protection inquiries, or to exercise your data rights, contact:
MidMightBit Games
Melbourne, VIC, Australia
Email: aardappvark@proton.me
We aim to respond to all data protection requests within 30 days.
This section applies if you are in the European Union or the European Economic Area, and explains how Regulation (EU) 2016/679 (GDPR) applies to CallSealSkr.
MidMightBit Games, a sole trader established in Australia, is the data controller. Contact: aardappvark@proton.me. We have not appointed a Data Protection Officer; we are not required to.
We have not designated a representative in the Union. We rely on the exemption in Article 27(2)(a): our processing of EU personal data is occasional, does not include large-scale processing of special categories of data under Article 9 or data relating to criminal convictions under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons. You can contact us directly at aardappvark@proton.me about any GDPR matter, and we answer in English.
You can stop this processing at any time from the App's Settings screen, where the privacy section carries the control. Turning it off stops all event sending immediately.
CallSealSkr stores settings on your device using Android's app-private storage. That storage is strictly necessary to provide the service you asked for, so it does not require separate consent. The App sets no cookies, uses no advertising identifier, no device fingerprinting and no third-party analytics SDK, and does not read information stored on your device for any purpose other than running the App.
We are established in Australia, so where we receive anything it is processed in Australia. Australia is not the subject of an adequacy decision under Article 45. Our analytics endpoint is operated for us in the United States by our hosting provider. The transferred payload is a single event name and contains no identifier and no personal data, so in our assessment Chapter V is not engaged by it; to the extent it is, we rely on Article 46(2)(c) standard contractual clauses with our provider, or the EU–US Data Privacy Framework where that provider is certified. Public Solana RPC providers you interact with may be located outside the EEA and receive your IP address and wallet public address as an unavoidable part of any internet request.
Data on your device is kept until you delete it, clear the App's data, or uninstall the App. Aggregate daily counters hold no personal data and are kept indefinitely as statistics. We operate no user accounts and hold no profile of you.
You have the rights of access (Article 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21), and the right to withdraw consent at any time where consent is the basis. Because your data lives on your device and we hold no identifier for you, you exercise most of these directly: the data is visible in the App, and clearing the App's data or uninstalling it erases it. For anything else, email aardappvark@proton.me — we respond within one month, free of charge.
There is no automated decision-making producing legal or similarly significant effects, and no profiling within the meaning of Article 22.
You have the right to lodge a complaint with the supervisory authority of your Member State of residence, place of work, or of the alleged infringement (Article 77). A list is published by the European Data Protection Board at edpb.europa.eu. We would appreciate the chance to resolve it first.