← Back to Legal

Privacy Policy

Effective date: 13 February 2025 · Last updated: 12 August 2026 · Version 1.3
Summary: Sol Clock stores all personal data locally on your device. We do not collect personal information or track your behaviour. The only network requests are read-only API calls to fetch publicly available price and blockchain data, plus anonymous, aggregate usage counters (e.g. "the app was opened") that contain no identifiers of any kind and cannot be linked to you or your device — see Section 3. You can verify everything we hold at our public transparency endpoint.

1. Data Controller

Sol Clock is developed and maintained by an independent developer operating under Australian law.

For the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.

2. What Data Sol Clock Collects

Sol Clock is designed with a privacy-first, local-only architecture. All personal data is stored on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences); if Android Backup is enabled, settings and progress data are also included in your device's encrypted Google backup (see Section 7). The only server-side system we operate is an anonymous, aggregate usage counter that is incapable of receiving, storing, or processing personal data — it is described in full in Section 3.

2.1 Data stored locally on your device

Data typePurposeLegal basis (GDPR)
Wallet public addressDisplay balance on clock face (opt-in)Consent (Art. 6(1)(a))
Wallet app nameShow which wallet was used to sign inConsent (Art. 6(1)(a))
SGT status & member numberDisplay Seeker Genesis Token verificationConsent (Art. 6(1)(a))
App preferencesClock display settings, world clock cities, themesContract (Art. 6(1)(b))
Engagement dataStreak counts and daily interaction countersContract (Art. 6(1)(b))
Device timezoneDisplay local time and location labelContract (Art. 6(1)(b))

2.2 Region screening (no location permission)

Sol Clock screens for jurisdictions subject to international sanctions without requesting any location permission. The check runs once at app startup and reads only:

Each of these values is read on-device, evaluated immediately, and not stored, not logged, and not transmitted to any server. Sol Clock does not declare or request ACCESS_COARSE_LOCATION or any other location permission, and does not use Android location services or the Geocoder.

Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. We have conducted a balancing test and determined that the compelling legal obligation to screen for sanctioned regions outweighs the minimal privacy intrusion of a single on-device check of carrier/timezone values that are never stored or transmitted.

2.3 Data we do NOT collect

3. Server-Side Systems: Anonymous Aggregate Analytics Only

Sol Clock does not operate any backend servers, databases, or cloud storage that hold personal data. All personal data exists exclusively in your device's app-private storage and is inaccessible to other applications.

The single server-side system we operate is an anonymous, aggregate usage counter (a Cloudflare Worker). It works as follows:

Legal basis (GDPR): the stored aggregate counts are anonymous information within the meaning of GDPR Recital 26 and therefore fall outside the scope of the GDPR. The momentary processing of your IP address by Cloudflare's edge to derive a country/city (before immediate discard) is based on legitimate interest (Art. 6(1)(f)); we have conducted a balancing test and concluded that counting anonymous events, with the IP never stored and no identifiers ever collected, presents minimal privacy intrusion.

Retention: aggregate counters are retained indefinitely. They contain no personal data and cannot be traced back to any person or device.

4. Third-Party API Calls

Sol Clock makes read-only API requests to the following third-party services to retrieve publicly available data. These requests are HTTPS-encrypted and no user-specific data is included in the requests except where noted:

ServiceEndpointData retrievedUser data sent
Jupiter APIlite-api.jup.agSOL and SKR token pricesNone
Raydium APIapi-v3.raydium.ioSOL and SKR token prices (fallback)None
CoinGecko APIapi.coingecko.comPrices and 24-hour change data (fallback)None
Solana RPCapi.mainnet-beta.solana.comBlockchain slot height; wallet SOL balanceWallet public address*
Sol Clock analytics (operated by us on Cloudflare)sol-clock-analytics.aardappvark.workers.devNothing (write-only counter)Anonymous event name only (see Section 3)

* Your Solana wallet public address is sent to the Solana RPC endpoint only when you have opted in by signing in with your wallet. Wallet public addresses are publicly visible on the Solana blockchain and are not generally considered personal information, though GDPR may classify pseudonymous identifiers as personal data. The legal basis for this processing is your explicit consent (Art. 6(1)(a) GDPR).

To verify Seeker Genesis Token status, submit payments, and restore purchases, the App sends your wallet's public address to the Solana RPC provider api.mainnet-beta.solana.com. The provider receives your IP address and the public address. Private keys never leave your wallet.

Note on IP addresses: When Sol Clock makes HTTP requests to the above APIs, your device's IP address is inherently transmitted as part of the network protocol. This is standard for all internet-connected applications. We do not control how these third-party services handle IP addresses — please refer to their respective privacy policies.

5. Mobile Wallet Adapter (MWA)

Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between Sol Clock and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:

After a successful sign-in (or a disconnect), Sol Clock increments the anonymous "wallet connected" (or "wallet disconnected") counter described in Section 3. The event contains no wallet address, wallet name, or any other data — it is a bare count.

6. Data Security

We implement the following security measures to protect locally stored data:

7. Data Retention and Deletion

All data is stored locally on your device and is retained until you explicitly delete it. You can delete all Sol Clock data at any time by:

Android Backup: If Android Backup is enabled on your device, the App's settings and progress data are included in your device's encrypted Google backup, survive uninstalling the App, and may be restored when you reinstall. Wallet data is always excluded from backup. You can exclude the App from backup in Android Settings or delete the backup from your Google account.

Since no personal data is stored on our servers, deleting the App's data from your device (and, if you use Android Backup, from your Google account) constitutes complete deletion of your personal data. The server-side aggregate counters described in Section 3 contain no personal data and cannot be linked to you, your device, or your wallet — there is nothing identifiable to delete.

8. International Data Transfers

Sol Clock does not transfer personal data to our servers. However, when Sol Clock makes API calls to third-party services (see Section 4), network requests may be routed through servers located outside your country of residence, including servers in the United States. The anonymous event counters described in Section 3 are received by Cloudflare's globally distributed edge network and stored, as anonymous aggregates only, in a Cloudflare D1 database; because they contain no personal data, data-transfer restrictions do not apply to them.

For users in the EEA or UK: these API calls are limited to fetching publicly available price data and, where you have consented, querying your wallet's public balance. We rely on the derogation under Article 49(1)(a) GDPR (explicit consent for wallet balance queries) and Article 49(1)(c) (necessary for the performance of the contract for price data retrieval).

9. Your Rights

9.1 European Economic Area & United Kingdom (GDPR / UK GDPR)

If you are located in the EEA or UK, you have the following rights under the GDPR:

9.2 Australia (Privacy Act 1988)

Under the Australian Privacy Principles (APPs), you have the right to:

9.3 California, USA (CCPA / CPRA)

If you are a California resident, you have the right to:

9.4 Japan (Act on Protection of Personal Information — APPI)

If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.

9.5 South Korea (Personal Information Protection Act — PIPA)

If you are located in South Korea, you have the right to:

All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.

9.6 Singapore (Personal Data Protection Act — PDPA)

If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.

10. Children's Privacy

Sol Clock is not directed at, marketed to, or intended for use by children under the age of 16 (or 13 in jurisdictions where that threshold applies, including the United States under COPPA). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.

11. Automated Decision-Making

Sol Clock performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's informational features. You may contact us to contest this decision.

12. Data Protection Impact Assessment

We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:

13. Do Not Track

Sol Clock does not track users. The anonymous event counters described in Section 3 contain no identifiers, cannot distinguish one user from another, and cannot follow anyone across apps, sites, or sessions — so Do Not Track (DNT) signals are inherently honoured. There is no user-level tracking to disable.

14. Local Storage Disclosure (ePrivacy)

For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: Sol Clock stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of Sol Clock after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

16. Contact

For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:

We aim to respond to all privacy inquiries within 30 days.

17. Governing Law

This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.