Sol Clock is developed and maintained by an independent developer operating under Australian law.
com.solclock.appFor the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.
Sol Clock is designed with a privacy-first, local-only architecture. All personal data is stored on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences); if Android Backup is enabled, settings and progress data are also included in your device's encrypted Google backup (see Section 7). The only server-side system we operate is an anonymous, aggregate usage counter that is incapable of receiving, storing, or processing personal data — it is described in full in Section 3.
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| Wallet public address | Display balance on clock face (opt-in) | Consent (Art. 6(1)(a)) |
| Wallet app name | Show which wallet was used to sign in | Consent (Art. 6(1)(a)) |
| SGT status & member number | Display Seeker Genesis Token verification | Consent (Art. 6(1)(a)) |
| App preferences | Clock display settings, world clock cities, themes | Contract (Art. 6(1)(b)) |
| Engagement data | Streak counts and daily interaction counters | Contract (Art. 6(1)(b)) |
| Device timezone | Display local time and location label | Contract (Art. 6(1)(b)) |
Sol Clock screens for jurisdictions subject to international sanctions without requesting any location permission. The check runs once at app startup and reads only:
Each of these values is read on-device, evaluated immediately, and not stored, not logged, and not transmitted to any server. Sol Clock does not declare or request ACCESS_COARSE_LOCATION or any other location permission, and does not use Android location services or the Geocoder.
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. We have conducted a balancing test and determined that the compelling legal obligation to screen for sanctioned regions outweighs the minimal privacy intrusion of a single on-device check of carrier/timezone values that are never stored or transmitted.
Sol Clock does not operate any backend servers, databases, or cloud storage that hold personal data. All personal data exists exclusively in your device's app-private storage and is inaccessible to other applications.
The single server-side system we operate is an anonymous, aggregate usage counter (a Cloudflare Worker). It works as follows:
Legal basis (GDPR): the stored aggregate counts are anonymous information within the meaning of GDPR Recital 26 and therefore fall outside the scope of the GDPR. The momentary processing of your IP address by Cloudflare's edge to derive a country/city (before immediate discard) is based on legitimate interest (Art. 6(1)(f)); we have conducted a balancing test and concluded that counting anonymous events, with the IP never stored and no identifiers ever collected, presents minimal privacy intrusion.
Retention: aggregate counters are retained indefinitely. They contain no personal data and cannot be traced back to any person or device.
Sol Clock makes read-only API requests to the following third-party services to retrieve publicly available data. These requests are HTTPS-encrypted and no user-specific data is included in the requests except where noted:
| Service | Endpoint | Data retrieved | User data sent |
|---|---|---|---|
| Jupiter API | lite-api.jup.ag | SOL and SKR token prices | None |
| Raydium API | api-v3.raydium.io | SOL and SKR token prices (fallback) | None |
| CoinGecko API | api.coingecko.com | Prices and 24-hour change data (fallback) | None |
| Solana RPC | api.mainnet-beta.solana.com | Blockchain slot height; wallet SOL balance | Wallet public address* |
| Sol Clock analytics (operated by us on Cloudflare) | sol-clock-analytics.aardappvark.workers.dev | Nothing (write-only counter) | Anonymous event name only (see Section 3) |
* Your Solana wallet public address is sent to the Solana RPC endpoint only when you have opted in by signing in with your wallet. Wallet public addresses are publicly visible on the Solana blockchain and are not generally considered personal information, though GDPR may classify pseudonymous identifiers as personal data. The legal basis for this processing is your explicit consent (Art. 6(1)(a) GDPR).
To verify Seeker Genesis Token status, submit payments, and restore purchases, the App sends your wallet's public address to the Solana RPC provider api.mainnet-beta.solana.com. The provider receives your IP address and the public address. Private keys never leave your wallet.
Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between Sol Clock and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:
After a successful sign-in (or a disconnect), Sol Clock increments the anonymous "wallet connected" (or "wallet disconnected") counter described in Section 3. The event contains no wallet address, wallet name, or any other data — it is a bare count.
We implement the following security measures to protect locally stored data:
EncryptedSharedPreferences with AES-256-SIV encryption (via Google Tink)All data is stored locally on your device and is retained until you explicitly delete it. You can delete all Sol Clock data at any time by:
Android Backup: If Android Backup is enabled on your device, the App's settings and progress data are included in your device's encrypted Google backup, survive uninstalling the App, and may be restored when you reinstall. Wallet data is always excluded from backup. You can exclude the App from backup in Android Settings or delete the backup from your Google account.
Since no personal data is stored on our servers, deleting the App's data from your device (and, if you use Android Backup, from your Google account) constitutes complete deletion of your personal data. The server-side aggregate counters described in Section 3 contain no personal data and cannot be linked to you, your device, or your wallet — there is nothing identifiable to delete.
Sol Clock does not transfer personal data to our servers. However, when Sol Clock makes API calls to third-party services (see Section 4), network requests may be routed through servers located outside your country of residence, including servers in the United States. The anonymous event counters described in Section 3 are received by Cloudflare's globally distributed edge network and stored, as anonymous aggregates only, in a Cloudflare D1 database; because they contain no personal data, data-transfer restrictions do not apply to them.
For users in the EEA or UK: these API calls are limited to fetching publicly available price data and, where you have consented, querying your wallet's public balance. We rely on the derogation under Article 49(1)(a) GDPR (explicit consent for wallet balance queries) and Article 49(1)(c) (necessary for the performance of the contract for price data retrieval).
If you are located in the EEA or UK, you have the following rights under the GDPR:
Under the Australian Privacy Principles (APPs), you have the right to:
If you are a California resident, you have the right to:
If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.
If you are located in South Korea, you have the right to:
All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.
If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.
Sol Clock is not directed at, marketed to, or intended for use by children under the age of 16 (or 13 in jurisdictions where that threshold applies, including the United States under COPPA). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.
Sol Clock performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's informational features. You may contact us to contest this decision.
We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:
Sol Clock does not track users. The anonymous event counters described in Section 3 contain no identifiers, cannot distinguish one user from another, and cannot follow anyone across apps, sites, or sessions — so Do Not Track (DNT) signals are inherently honoured. There is no user-level tracking to disable.
For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: Sol Clock stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of Sol Clock after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:
We aim to respond to all privacy inquiries within 30 days.
This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.