Privacy Policy — SignalFortSkr

Effective Date: March 2026 · Last updated: August 21, 2026

1. Overview

SignalFortSkr ("the App") is published by Aardappvark, based in Melbourne, VIC, Australia. The App is a WiFi security monitoring tool for the Solana Seeker device. It monitors your WiFi environment for security threats including evil twins, rogue access points, and encryption downgrades, and optionally records SHA-256 hashes of security events on the Solana blockchain as immutable proof.

SignalFortSkr is built with privacy as a core principle. We do not collect personal data, we do not serve advertisements, and no personal data is stored in the cloud. The only server-side system we operate is an anonymous, aggregate usage counter that is incapable of receiving, storing, or processing personal data — described in full in Section 9. All personal data remains on your device.

2. What We Collect

SignalFortSkr collects WiFi scan data (SSID, BSSID, signal strength, frequency, encryption type) from your device's WiFi hardware. This data is processed and stored locally on your device only. No WiFi scan data is ever transmitted to any server, cloud service, or third party.

3. Location Permission

Android requires location permission (ACCESS_FINE_LOCATION) to access WiFi scan results including SSIDs and BSSIDs. SignalFortSkr does not use GPS, does not determine your physical location, does not store or transmit any GPS coordinates, and does not track your movements. The location permission is used exclusively to access WiFi scan data as required by the Android operating system.

4. Legal Basis for Data Processing

Under the EU General Data Protection Regulation (GDPR) and UK GDPR, the legal basis for processing your wallet public address (if you choose to connect a wallet) is legitimate interest (Article 6(1)(f)) — specifically, the legitimate interest in providing SGT verification and proof anchoring access that you voluntarily opt into by connecting your wallet. This processing is minimal, expected by the user, and proportionate.

The legal basis for processing WiFi scan data to detect security threats is consent (Article 6(1)(a)) — you explicitly enable WiFi scanning within the App, and you can disable it at any time.

Under the Australian Privacy Act 1988 and Australian Privacy Principles (APPs), the wallet public address is collected in accordance with APP 3 (collection of solicited personal information) for the primary purpose of on-chain identity verification and feature access. WiFi scan data processing is covered by APP 3 as information collected for the primary purpose of security monitoring at your request.

5. On-Chain Data

When you create an on-chain proof, the App writes a memo transaction to the Solana blockchain. The memo contains, in plaintext: the app tag and format version ("SIGNALFORTSKR|v1"), a SHA-256 hash of the security event, the event type name (e.g. EVIL_TWIN), the Unix timestamp of the proof, and an anonymised device fingerprint (a 16-character hash derived from your device model and a random per-install ID — it contains no serial number or personal identifier). Tier-achievement proofs additionally include the tier name. The SHA-256 hash is a one-way cryptographic digest that cannot be reversed to recover the underlying scan data. Your wallet address is visible on-chain as the transaction signer. On-chain data is permanent and cannot be deleted.

6. Data We Store Locally

WiFi Scan Data (Local Only)

App Settings (Local Only)

Wallet Public Address (Optional, Encrypted)

7. Data We Do NOT Collect

8. Security Reports

When you export a security report, a PDF is generated locally on your device. The file is stored in your device's cache directory and shared via Android's standard sharing mechanism. SignalFortSkr does not retain copies of exported reports and does not transmit report data to any server.

9. Anonymous Aggregate Analytics

SignalFortSkr does not include any third-party analytics SDKs, crash reporting services, advertising frameworks, or behavioural tracking systems. It does not collect user IDs, device identifiers, advertising IDs, wallet addresses, or any other identifier.

The single server-side system we operate is an anonymous, aggregate usage counter (a Vercel serverless function backed by our Cloudflare D1 database (aggregate counts only; our Cloudflare D1 database (with Vercel Blob as a short-term fallback) retained only as a short-term fallback if the primary store is unreachable)). It works as follows:

Legal basis (GDPR): the stored aggregate counts are anonymous information within the meaning of GDPR Recital 26 and therefore fall outside the scope of the GDPR. The momentary processing of your IP address by Vercel's edge to derive a country (before immediate discard) is based on legitimate interest (Art. 6(1)(f)); we have concluded that counting anonymous events, with the IP never stored and no identifiers ever collected, presents minimal privacy intrusion.

Retention: aggregate counters are retained indefinitely. They contain no personal data and cannot be traced back to any person or device.

10. No Third-Party Sharing

We do not sell, share, licence, rent, or transfer any user data to third parties. The complete list of services the App connects to — Solana RPC, our anonymous counter, and the third-party endpoints contacted by the optional Network Tools diagnostics — is set out in Section 14. None of them receives your WiFi scan data.

11. Wallet Connection (Optional)

SignalFortSkr supports optional wallet connection via Sign In With Solana (SIWS) using the Solana Mobile Wallet Adapter (MWA). Wallet connection enables:

The MWA protocol operates locally between apps on your device. No wallet data is transmitted to external servers by Aardappvark. We store only your wallet public address (encrypted). We never have access to your private keys or the ability to sign transactions on your behalf without your explicit approval in your wallet app.

12. Notifications

SignalFortSkr may send local notifications for security alerts, weekly digests, and scan results. These notifications are generated entirely on-device and do not involve any push notification service or external server.

13. Home Screen Widget

The optional home screen widget displays your current security score. Widget data is read from local SharedPreferences and does not involve any network requests.

14. Network Requests

The App makes the following network requests:

The optional Network Tools diagnostics contact additional third-party services, only when you run the corresponding tool:

Each of these services receives your IP address as part of standard internet protocol; none receives your WiFi scan data, wallet address, or any identifier from the App. All network communications use HTTPS/TLS encryption in transit except the two captive-portal check hosts listed above, which use HTTP by design (the App's network security configuration permits cleartext traffic to those two hosts only), and ICMP-style ping/traceroute probes, which are not HTTP at all.

15. IP Address Disclosure

The App does not collect or store your IP address. However, when the App makes network requests to the Solana RPC endpoint or the Network Tools endpoints listed in Section 14, your IP address is transmitted to those services as part of standard internet protocol. Aardappvark has no access to any logs or data collected by those third-party providers. We encourage you to review their respective privacy policies.

Requests to our own anonymous analytics counter (Section 9) also transmit your IP as part of standard internet protocol, but Vercel's edge uses it only to derive an approximate country and our code never logs or stores the IP itself.

16. Data Storage and Security

All personal data is stored locally on your device. No personal data is transmitted to any server owned or operated by Aardappvark — the only server-side system we operate is the anonymous aggregate counter in Section 9, which holds no personal data. Security measures include:

Android Backup: if Android Backup is enabled on your device, the App's settings and progress data are included in your device's encrypted Google backup, survive uninstalling the App, and may be restored when you reinstall. Wallet data is always excluded from backup. You can exclude the App from backup in Android Settings or delete the backup from your Google account.

While we use Android's EncryptedSharedPreferences for sensitive data, no method of electronic storage is 100% secure. We cannot guarantee the absolute security of your locally stored data.

17. No Accounts Created

SignalFortSkr does not create user accounts. There is no registration, no login system, and no user profiles. Wallet connection via SIWS is optional and used solely for SGT verification and proof anchoring payments. Disconnecting your wallet removes all wallet-related data from your device.

18. Third-Party Services

The App uses the following third-party libraries:

The App does NOT include any:

19. Data Retention

Your data is retained locally on your device for as long as the App is installed. Data is automatically deleted when you:

WiFi scan data, security events, app settings, and wallet data are removed when the App is uninstalled or its data is cleared. Note that if Android Backup is enabled, the App's settings and progress data may persist in your device's encrypted Google backup after uninstall (Section 16); wallet data is never backed up.

Note: SHA-256 hashes that have been recorded on the Solana blockchain are immutable and cannot be deleted. This is an inherent characteristic of blockchain technology. However, these on-chain hashes cannot be reversed to recover the original security event data.

20. Cross-Border Data Transfers

When making RPC calls, your wallet public address and IP address are transmitted to Solana RPC endpoints to retrieve on-chain data and submit proof transactions. Your wallet public address is already publicly visible on the Solana blockchain. No user-specific data is sent to Aardappvark servers (we have none).

We rely on the public nature of blockchain data and your explicit request to use this service as the basis for these transmissions. For EU/UK users, this processing is necessary for the performance of the service at your request (GDPR Article 49(1)(b)).

21. Your Rights

Right to Delete (Erasure)

You can delete all App data at any time by:

  1. Disconnecting your wallet within the App to remove wallet data
  2. Going to Android Settings > Apps > SignalFortSkr > Clear Data to remove all local data
  3. Uninstalling the App

This satisfies the right to erasure under GDPR Article 17, UK GDPR, and the Australian Privacy Act. Note that on-chain hashes cannot be deleted due to the immutable nature of blockchain technology, but they contain no personally identifiable information.

Right to Access

All data stored by the App is visible within the App itself (scan history, security events, app settings, and wallet connection status). You may also contact us to request a summary of any data associated with your wallet address.

Right to Rectification (GDPR Article 16)

As the only externally-sourced data is your wallet public address from the Solana blockchain, the App displays factual on-chain data. If you believe any data is inaccurate, you can disconnect and reconnect your wallet to refresh on-chain data.

Right to Restriction of Processing (GDPR Article 18)

You may restrict the processing of your wallet address at any time by disconnecting your wallet. You may disable WiFi scanning at any time to stop data processing. This stops all data processing and removes your wallet address from local storage. You may reconnect at any time to resume the service.

Right to Object

You may object to the processing of your wallet address at any time by disconnecting your wallet, which removes your wallet address from local storage. You may object to WiFi scan data processing by disabling scanning in the App settings.

Right to Portability

As all data is stored locally on your device, you have full control over your data at all times. Your wallet public address is the only externally-sourced data element and is already in your possession.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority:

22. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise your rights, use the in-app controls or contact us at the address below.

23. Brazilian Residents (LGPD)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with rights to access, correct, delete, and port your data. The legal basis for processing is your consent, given by connecting your wallet and enabling WiFi scanning. You may withdraw consent at any time by disconnecting your wallet and disabling scanning. Contact us to exercise your rights.

24. Canadian Residents (PIPEDA)

If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) provides you with rights regarding your personal information. The App processes only your wallet public address, stored locally on your device. You may withdraw consent at any time by disconnecting your wallet. No personal information is transferred to Aardappvark servers. To exercise your rights under PIPEDA, contact us at the address below or use the in-app controls.

25. South African Residents (POPIA)

If you are located in South Africa, the Protection of Personal Information Act (POPIA) provides you with rights to access, correct, and delete your personal information. Processing is based on the legitimate interest of providing the service you voluntarily opted into. Your wallet public address is stored locally on your device with AES-256 encryption. You may object to processing and request deletion at any time by disconnecting your wallet.

26. Japanese Residents (APPI)

If you are located in Japan, the Act on the Protection of Personal Information (APPI) provides you with rights to request disclosure, correction, suspension of use, and deletion of your personal data. The App stores only your wallet public address locally on your device. No data is provided to third parties as defined under APPI. To exercise your rights, use the in-app controls or contact us.

27. Indian Residents (DPDP Act)

If you are located in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) provides you with rights as a Data Principal including the right to access, correct, and erase your personal data. Consent is obtained when you connect your wallet and enable WiFi scanning. You may withdraw consent at any time by disconnecting your wallet and disabling scanning. The App does not process data of children (persons under 18). No personal data is transferred to Aardappvark servers.

28. Turkish Residents (KVKK)

If you are located in Turkey, the Kişisel Verilerin Korunması Kanunu (KVKK, Law No. 6698) provides you with rights to learn whether your data is processed, request information about processing, learn the purpose of processing, request correction, request deletion, and object to processing. Your wallet public address is the sole data element, stored locally with encryption. Contact us to exercise your rights under KVKK.

29. Swiss Residents (FADP/nDSG)

If you are located in Switzerland, the revised Federal Act on Data Protection (FADP/nDSG) provides you with rights to access, rectify, and delete your personal data. Processing is based on legitimate interest (providing the service you requested). Cross-border data transfers to RPC providers comply with FADP requirements as they involve only publicly available blockchain data and your IP address via standard internet protocol. Contact the FDPIC or us to exercise your rights.

30. Singapore Residents (PDPA)

If you are located in Singapore, the Personal Data Protection Act (PDPA) provides you with rights to access and correct your personal data, and to withdraw consent. The App processes only your wallet public address with your consent (given by connecting your wallet). You may withdraw consent at any time by disconnecting your wallet. The App does not use your data for marketing purposes.

31. Thai Residents (PDPA)

If you are located in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) provides you with rights to access, correct, delete, restrict, and port your personal data. Processing is based on your consent, given by connecting your wallet. You may withdraw consent at any time by disconnecting your wallet. The App does not collect sensitive data as defined under the Thai PDPA.

32. Nigerian Residents (NDPR)

If you are located in Nigeria, the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023 provide you with rights to access, rectify, and delete your personal data. Consent is obtained when you connect your wallet. The App processes minimal data (wallet public address only), stored locally with AES-256 encryption. No data is shared with third parties beyond RPC endpoints. Contact us to exercise your rights.

33. Indonesian Residents (PDP Law)

If you are located in Indonesia, Law No. 27 of 2022 on Personal Data Protection (PDP Law) provides you with rights to access, correct, delete, and withdraw consent for processing of your personal data. Consent is obtained when you connect your wallet. You may withdraw consent and delete all data at any time by disconnecting your wallet.

34. Vietnamese Residents (PDPD)

If you are located in Vietnam, Decree No. 13/2023/ND-CP on Personal Data Protection provides you with rights to be informed of, consent to, access, and delete your personal data. The App stores only your wallet public address locally on your device. No personal data is transferred to Aardappvark servers. Contact us to exercise your rights.

35. Korean Residents (PIPA)

If you are located in South Korea, the Personal Information Protection Act (PIPA) provides you with rights to access, correct, suspend processing, and delete your personal information. The App collects only your wallet public address, stored locally with encryption. No data is provided to third parties as defined under PIPA. Processing may be suspended at any time by disconnecting your wallet. Contact us or the Personal Information Protection Commission (PIPC) to exercise your rights.

36. Children's Privacy

SignalFortSkr is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. The App is intended for users who own a Solana Seeker device. If you believe a child under 18 has used this App and connected a wallet, please contact us and we will provide guidance on removing the data.

37. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the effective date above. We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.

38. Contact

For questions about this Privacy Policy, data protection inquiries, or to exercise your data rights, contact:

Aardappvark
Melbourne, VIC, Australia
Email: aardappvark@proton.me

We aim to respond to all data protection requests within 30 days.