Last updated: July 2026
Sol Rosary ("the App") is a virtual rosary prayer companion application for Android devices. The App provides guided rosary prayers, mystery meditations, saint quotes, and devotional tools to support Catholic prayer life. Sol Rosary also offers optional Solana wallet connection for Saga Genesis Token (SGT) verification via the Sign In With Solana (SIWS) protocol.
This Privacy Policy explains how Sol Rosary handles information when you use our App. We are committed to protecting your privacy and being transparent about our data practices. Sol Rosary is designed with a privacy-first architecture: we collect no personal data and no prayer content. The App's only external usage signal is a small, anonymous, aggregate analytics event (for example, that the App was opened, or that a prayer was completed) — described in full in Section 5. These events carry no identifier of any kind and cannot be linked back to you.
This policy applies to all users of the Sol Rosary application, regardless of location or jurisdiction.
The data controller responsible for the App is:
MidMightBit Games
Melbourne, VIC, Australia
Email: aardappvark@proton.me
For all privacy-related enquiries, requests, or complaints, please contact us at the email address above.
Sol Rosary collects no personal data. The only data that leaves your device is a stream of anonymous, aggregate usage events that cannot be linked to you (see Section 5.3).
We do not collect, store, transmit, or process any of the following:
The App sends anonymous, aggregate analytics events to a backend service we operate for the sole purpose of understanding how many people use the App and in which countries. This service records only counts — never any identifier, and never anything that could single you out. It is described in full in Section 5.3.
Sol Rosary stores a limited amount of functional data locally on your device using Android's SharedPreferences and EncryptedSharedPreferences mechanisms. This data never leaves your device.
| Data Type | Purpose | Storage Method |
|---|---|---|
| App settings and preferences | Remember your chosen settings (e.g., prayer speed, haptic feedback, notification preferences) | SharedPreferences |
| Prayer progress | Track your position within a rosary session so you can resume | SharedPreferences |
| Favourite prayers or meditations | Save your preferred selections for quick access | SharedPreferences |
| Wallet verification status | Remember whether SGT verification was completed (optional feature) | EncryptedSharedPreferences |
| Notification schedules | Store prayer reminder times set by you | SharedPreferences |
Local data is not synchronised to any server, cloud service, or third-party platform. It exists solely on your device and is fully removed when you uninstall the App or clear its data through your device settings.
Sol Rosary makes minimal network requests, limited to the following:
Endpoint: api.mainnet-beta.solana.com
Purpose: Verify Saga Genesis Token (SGT) ownership when you optionally connect a Solana wallet
Data sent: Wallet public address only (no PII)
When: Only when you explicitly initiate wallet connection via SIWS
A Solana wallet public address is a pseudonymous blockchain identifier. It is not linked to your real-world identity within our App. We do not store, log, or transmit this address to any server we control. The RPC request is made directly from your device to the Solana network.
Wallet connection uses the Solana Mobile Wallet Adapter protocol with Sign In With Solana (SIWS). This communication occurs locally between the App and your installed wallet app (e.g., Solflare, Phantom) via Android intents. No data is sent to MidMightBit Games servers.
Endpoint: sol-rosary-analytics.vercel.app
Purpose: Understand how many people use the App and in which countries, so we can maintain and improve it
Data sent by the App: A single event name only (e.g. app_open), with no accompanying data
When: On app open, and at a small number of milestone moments (see below)
Sol Rosary sends anonymous usage "pings" to an analytics service that we operate on Vercel's edge network. This is the only backend service the App communicates with. It is engineered so that it is technically incapable of identifying you:
app_open. No user ID, no device ID, no wallet address, no advertising ID, no session token, and no prayer content is ever attached.The events the App reports are limited to: opening the App; accepting the in-app disclaimer; completing onboarding; completing a prayer; connecting or disconnecting a wallet; the result of an optional SGT check (found / not found); enabling prayer reminders; and being blocked by the sanctions screen. Each is sent as a bare event name with no further data.
You can independently verify exactly what is collected. Our live, unauthenticated aggregate figures are published at sol-rosary-analytics.vercel.app/public-stats — this is the complete extent of the data we hold.
Because these events are anonymous and aggregate, they do not constitute personal data once recorded (GDPR Recital 26). Where the transient edge processing of an IP address is treated as personal data, our legal basis is our legitimate interest (GDPR Article 6(1)(f)) in understanding App usage and reach, balanced against the negligible privacy impact of a system that stores no identifiers.
If you choose to buy an optional supporter unlock, the payment is an ordinary Solana blockchain transaction that you sign and submit from your own wallet (Sections 5.1–5.2), sending SOL or the SKR token to the developer's wallet. Like all blockchain activity, that transaction — your wallet address, the amount, and the timestamp — is inherently public on the Solana ledger; that is a property of the blockchain, not something we publish. We do not collect or store any additional personal data for a purchase: no name, no email, no card details (there are no card payments). Your unlock status is stored locally on your device (encrypted) and can be re-derived from the public blockchain when you reconnect the same wallet. We never receive custody of your funds or keys.
Apart from the Solana RPC (Section 5.1), the Mobile Wallet Adapter (Section 5.2), the anonymous analytics (Section 5.3), and optional supporter payments (Section 5.4), Sol Rosary makes no other network requests. There are no advertising networks, crash reporting services, remote configuration servers, third-party trackers, or any other external connections.
Sol Rosary requests the following Android permissions, each for a specific and limited purpose:
| Permission | Purpose | Details |
|---|---|---|
INTERNET |
Solana RPC access and anonymous analytics | Required to communicate with the Solana blockchain for optional wallet/SGT verification, and to send the anonymous, aggregate usage events described in Section 5.3. No personal data is transmitted. |
ACCESS_COARSE_LOCATION |
Sanctions screening only | Used exclusively to determine whether the device is located in a sanctioned region. Location data is checked locally on-device against a list of sanctioned jurisdictions. Location is never stored, logged, recorded, or transmitted to any server. The check is performed once and the result (permitted/blocked) is retained locally as a boolean value only. |
POST_NOTIFICATIONS |
Prayer reminders | Allows the App to send local notifications for prayer reminders that you configure. Notifications are generated entirely on-device. No notification data is sent externally. |
VIBRATE |
Haptic feedback | Provides tactile feedback during prayer bead progression. Purely a local device function. |
RECEIVE_BOOT_COMPLETED |
Notification rescheduling | Allows the App to re-register your prayer reminder notifications after your device restarts. Without this permission, scheduled reminders would be lost on reboot. |
No permission is used to collect, store, or transmit personal data. Each permission serves a specific functional purpose as described above.
Sol Rosary performs one form of automated decision-making: sanctions compliance screening.
When the App starts, it may check your device's SIM card country, mobile carrier information, and/or system locale settings to determine whether you are located in or associated with a sanctioned jurisdiction. This check is:
If the screening determines that you are in a sanctioned region, access to the App will be restricted. This is required for compliance with Australian sanctions law, US OFAC regulations, and EU restrictive measures.
Sol Rosary does not engage in any profiling, behavioural analysis, automated scoring, or algorithmic decision-making beyond the sanctions screening described above.
Sol Rosary is not directed at children under the age of 13. We do not knowingly collect any information from children under 13. Since the App collects no personal data from any user, there is no risk of inadvertent collection of children's data.
If you believe a child under 13 is using the App in a manner that concerns you, please contact us at aardappvark@proton.me. However, since we collect no personal data, there is no personal data to delete.
The App complies with the US Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR) provisions on children's consent (Article 8), and the Australian Privacy Act 1988 as it applies to minors.
No personal data leaves your device. The only data transmitted is anonymous, aggregate analytics that does not identify you.
Because Sol Rosary transmits no personal data, there is no international transfer of personal data to consider. Your locally stored preferences, prayer progress, and intentions remain on your device in your jurisdiction at all times.
The anonymous analytics events described in Section 5.3 are processed on Vercel's globally distributed edge network and stored in managed storage operated through Vercel, which may be located outside your country. Because these events contain no identifier and are stored only as aggregate counts, they do not constitute personal data once recorded, and their processing is not an international transfer of personal data within the meaning of the GDPR, CCPA, or equivalent regulations. Vercel acts as our infrastructure provider under its own data-protection commitments.
The only network communication (Solana RPC requests) involves a pseudonymous wallet public address sent directly from your device to the decentralised Solana network. This is not a transfer of personal data as defined by the GDPR, CCPA, or equivalent regulations.
Although Sol Rosary does not transmit personal data, we take reasonable measures to protect locally stored information:
Depending on your jurisdiction, you may have various rights concerning your personal data. Since Sol Rosary collects no personal data, most of these rights are automatically satisfied. We set out below how each major privacy framework applies:
Under the GDPR, you have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Since Sol Rosary collects and processes no personal data:
sol-rosary-analytics.vercel.app at the device or network level, and the App continues to function normally.Legal basis for processing: legitimate interest (Art. 6(1)(f)) for both sanctions compliance and the anonymous, aggregate usage analytics described in Section 5.3. The recorded analytics data is anonymous and aggregate (GDPR Recital 26) and is not personal data.
Under the CCPA/CPRA, California residents have rights regarding personal information. Since Sol Rosary does not collect, sell, or share personal information:
Sol Rosary does not constitute a "business" under the CCPA as we do not meet the applicable thresholds, but we voluntarily respect these rights for all users.
Under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), you have rights regarding your personal information. As Sol Rosary collects no personal information:
Complaints may be directed to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Under Brazil's LGPD, data subjects have rights including confirmation of processing, access, correction, anonymisation, portability, deletion, and information about sharing. Since Sol Rosary collects no personal data, all of these rights are inherently satisfied. You may contact us or Brazil's National Data Protection Authority (ANPD) with any enquiries.
Under Japan's APPI, individuals have the right to request disclosure, correction, suspension of use, and deletion of personal data. Sol Rosary holds no personal data, and thus these rights are automatically fulfilled. Enquiries may be directed to us or the Personal Information Protection Commission (PPC).
Under South Korea's PIPA, data subjects have rights including access, correction, deletion, and suspension of processing. Since we collect no personal information, these rights are inherently satisfied. The Personal Information Protection Commission (PIPC) oversees PIPA compliance.
Under Thailand's PDPA, data subjects have rights of access, rectification, erasure, restriction, portability, and objection. Sol Rosary collects no personal data, so these rights are automatically met.
Under Singapore's PDPA, individuals have rights of access and correction regarding personal data held by organisations. Sol Rosary holds no personal data. Enquiries may be directed to us or the Personal Data Protection Commission (PDPC).
Sol Rosary does not retain any personal data on any server or cloud service. All App data is stored locally on your device.
Sol Rosary honours Do Not Track (DNT) browser signals and similar privacy preferences. In practice, this is inherently satisfied because we do not track users in any way, regardless of whether a DNT signal is present. There is no tracking to disable.
In compliance with the EU ePrivacy Directive (2002/58/EC as amended by 2009/136/EC), we disclose that Sol Rosary stores data locally on your device using Android's SharedPreferences and EncryptedSharedPreferences mechanisms.
This local storage is used exclusively for:
This storage falls under the "strictly necessary" exemption of Article 5(3) of the ePrivacy Directive, as it is required for the App to function as expected by the user. No consent is required for this functional storage.
No cookies, web storage, or tracking technologies are used.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
We encourage you to review this policy periodically. Given that Sol Rosary collects no personal data, substantive changes to this policy are unlikely.
This Privacy Policy is governed by and construed in accordance with the laws of the Commonwealth of Australia and the State of New South Wales. Any disputes arising from or relating to this policy shall be subject to the exclusive jurisdiction of the courts of New South Wales, Australia.
This choice of law does not deprive you of any mandatory consumer protections available under the laws of your country of residence, where those protections cannot be excluded by contract.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
MidMightBit Games
Email: aardappvark@proton.me
We will endeavour to respond to all enquiries within 30 days.
This section applies if you are in the European Union or the European Economic Area, and explains how Regulation (EU) 2016/679 (GDPR) applies to Sol Rosary.
MidMightBit Games, a sole trader established in Australia, is the data controller. Contact: aardappvark@proton.me. We have not appointed a Data Protection Officer; we are not required to.
We have not designated a representative in the Union. We rely on the exemption in Article 27(2)(a): our processing of EU personal data is occasional, does not include large-scale processing of special categories of data under Article 9 or data relating to criminal convictions under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons. You can contact us directly at aardappvark@proton.me about any GDPR matter, and we answer in English.
You can stop this processing at any time from the App's Settings screen, where the privacy section carries the control. Turning it off stops all event sending immediately.
Sol Rosary stores settings on your device using Android's app-private storage. That storage is strictly necessary to provide the service you asked for, so it does not require separate consent. The App sets no cookies, uses no advertising identifier, no device fingerprinting and no third-party analytics SDK, and does not read information stored on your device for any purpose other than running the App.
We are established in Australia, so where we receive anything it is processed in Australia. Australia is not the subject of an adequacy decision under Article 45. Our analytics endpoint is operated for us in the United States by our hosting provider. The transferred payload is a single event name and contains no identifier and no personal data, so in our assessment Chapter V is not engaged by it; to the extent it is, we rely on Article 46(2)(c) standard contractual clauses with our provider, or the EU–US Data Privacy Framework where that provider is certified. Public Solana RPC providers you interact with may be located outside the EEA and receive your IP address and wallet public address as an unavoidable part of any internet request.
Data on your device is kept until you delete it, clear the App's data, or uninstall the App. Aggregate daily counters hold no personal data and are kept indefinitely as statistics. We operate no user accounts and hold no profile of you.
You have the rights of access (Article 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21), and the right to withdraw consent at any time where consent is the basis. Because your data lives on your device and we hold no identifier for you, you exercise most of these directly: the data is visible in the App, and clearing the App's data or uninstalling it erases it. For anything else, email aardappvark@proton.me — we respond within one month, free of charge.
There is no automated decision-making producing legal or similarly significant effects, and no profiling within the meaning of Article 22.
You have the right to lodge a complaint with the supervisory authority of your Member State of residence, place of work, or of the alleged infringement (Article 77). A list is published by the European Data Protection Board at edpb.europa.eu. We would appreciate the chance to resolve it first.