Privacy Policy — VeriCapture

Effective Date: August 2026 · App version 1.2.0

1. Overview

VeriCapture ("the App") is published by MidMightBit Games, based in Melbourne, VIC, Australia. The App is a media verification tool for the Solana Seeker device. It creates SHA-256 hashes of photos and videos captured or selected on your device and records those hashes on the Solana blockchain as immutable proof that the media existed in a specific state at a specific time.

VeriCapture is built with privacy as a core principle. We do not collect personal data, we do not use third-party tracking or advertising services, we do not store your content in the cloud, and we do not serve advertisements. Your media and your proof records stay on your device.

Two things do leave the device, and both are described in full below: (a) your wallet public address and IP address reach the Solana RPC provider whenever the App reads or writes the blockchain, and (b) the App sends anonymous, aggregate usage counts — an event name and a coarse country, nothing else — to an analytics endpoint we operate. The analytics can be switched off at any time in Settings › Privacy. Separately, the on-chain memo the App writes for each proof is public and permanent; see section 3A.

Critical Privacy Commitment: VeriCapture does NOT upload, transmit, or store your photos or videos on any server. No media files ever leave your device. Only cryptographic hashes — short, fixed-length strings derived from the file content — are submitted to the Solana blockchain. These hashes cannot be reversed to reconstruct the original media.

2. Legal Basis for Data Processing

Under the EU General Data Protection Regulation (GDPR) and UK GDPR, the legal basis for processing your wallet public address (if you choose to connect a wallet) is legitimate interest (Article 6(1)(f)) — specifically, the legitimate interest in providing SGT verification and hash recording access that you voluntarily opt into by connecting your wallet. This processing is minimal, expected by the user, and proportionate.

The legal basis for processing media files to generate hashes is consent (Article 6(1)(a)) — you explicitly select which photos and videos to hash within the App, and you initiate each hashing operation yourself.

Under the Australian Privacy Act 1988 and Australian Privacy Principles (APPs), the wallet public address is collected in accordance with APP 3 (collection of solicited personal information) for the primary purpose of on-chain identity verification and feature access. Media file processing is covered by APP 3 as information collected for the primary purpose of hash generation at your request.

3. How Hashing Works

VeriCapture uses a two-stage hash chain to verify media integrity and detect tampering:

Stage 1 — Content Hash Commitment

Stage 2 — Sealed Hash for Tamper Detection

At no point does any media file content leave your device. Only the cryptographic hashes are recorded on-chain. The raw file data is never read into memory beyond what is required for hash computation.

3A. What Is Written to the Public Blockchain

Each proof writes one Solana Memo Program transaction. The memo is public, permanent and readable by anyone. It contains exactly:

The transaction is signed by your wallet, so your wallet’s public address is also visible on-chain, as it is for any Solana transaction. No media content is ever written on-chain and a hash cannot be reversed into the original file. If a file name would reveal something you would rather not publish, rename the file before proving it.

Sealed copies of your files also carry your wallet public address inside their embedded proof data. Anyone you send a sealed file to can read it.

4. Data We Store Locally

Proof Chain Records (Local Only)

App Settings (Local Only)

Wallet Public Address (Optional, Encrypted)

5. Data We Do NOT Collect

We receive none of the following, on any server of ours:

What we do receive is limited to anonymous aggregate usage counts — see section 9A.

6. Permissions

VeriCapture declares exactly these Android permissions, and no others:

The list above is the complete set of permissions in the installed APK, including those contributed by third-party libraries.

VeriCapture requests no location permission (fine, coarse or background), no contacts, no microphone, no phone-state, no exact-alarm and no overlay permission.

Important: These permissions are used exclusively to read media file content for SHA-256 hash computation. The App does not upload, copy, or transmit any media files. All file content is processed locally on your device, hashed immediately, and the raw data buffer is released from memory. No media file content is retained beyond the duration of the hash computation.

7. Wallet Connection (Optional)

VeriCapture supports optional wallet connection via Sign In With Solana (SIWS) using the Solana Mobile Wallet Adapter (MWA). Wallet connection enables:

The MWA protocol operates locally between apps on your device. No wallet data is transmitted to external servers by MidMightBit Games. We store only your wallet public address (encrypted). We never have access to your private keys or the ability to sign transactions on your behalf without your explicit approval in your wallet app.

8. Payments and Transactions

Recording and verifying proofs is free — you pay only the Solana network fee. The only purchase is a one-time VeriCapture Pro unlock for 0.01 SOL or 10 SKR, which is free for Seeker Genesis Token holders. It is processed entirely on the Solana blockchain:

9. Network Requests

The App contacts exactly these endpoints, and no others:

The App enforces HTTPS for all connections and does not permit cleartext traffic.

9A. Anonymous Usage Analytics

The App sends anonymous, aggregate usage events to vericapture-analytics.vercel.app, an endpoint we operate on Vercel. Each event is a single HTTPS POST whose entire body is one event name from a fixed list (for example app_open, proof_verified, payment_sol, settings_opened).

All network communications use HTTPS/TLS encryption in transit. The App enforces HTTPS for all connections and does not permit cleartext traffic.

10. IP Address Disclosure

We do not log or store your IP address. However, when the App makes network requests — to api.mainnet-beta.solana.com and to our analytics endpoint at vericapture-analytics.vercel.appyour IP address is transmitted as part of standard internet protocol, and is visible to those services and to their hosting providers (Solana Labs and Vercel respectively). Our analytics endpoint uses the request only to derive a coarse country and does not retain the address. We have no access to logs kept by the RPC provider; we encourage you to review its privacy policy.

11. Data Storage and Security

Your media, proof records and settings are stored locally on your device. The only data that reaches a server we operate is the anonymous aggregate event counts described in section 9A. Security measures include:

12. No Accounts Created

VeriCapture does not create user accounts. There is no registration, no login system, and no user profiles. Wallet connection via SIWS is optional and used solely for SGT verification and hash recording payments. Disconnecting your wallet removes all wallet-related data from your device.

13. Third-Party Services

The App uses the following third parties:

Our analytics are first-party and purpose-built: the App contains no third-party analytics, advertising, attribution or crash-reporting SDK. Specifically the App does NOT include any:

14. Data Retention

Your data is retained locally on your device for as long as the App is installed. Data is automatically deleted when you:

Proof chain records, app settings, and wallet data are removed when the App is uninstalled or its data is cleared. Because Android backup is disabled for this App, none of it is retained in your Google account — and a VeriCapture Pro unlock must therefore be restored from the blockchain after a reinstall. Anonymous aggregate analytics counters (section 9A) contain no personal data and are retained indefinitely; they cannot be tied to you, so there is nothing in them to delete on request.

Note: SHA-256 hashes that have been recorded on the Solana blockchain are immutable and cannot be deleted. This is an inherent characteristic of blockchain technology. However, these on-chain hashes cannot be reversed to recover the original media content.

15. Cross-Border Data Transfers

When making RPC calls, your wallet public address and IP address are transmitted to Solana RPC endpoints to retrieve on-chain data and submit hash transactions. Your wallet public address is already publicly visible on the Solana blockchain. No user-specific data is sent to MidMightBit Games servers (we have none).

We rely on the public nature of blockchain data and your explicit request to use this service as the basis for these transmissions. For EU/UK users, this processing is necessary for the performance of the service at your request (GDPR Article 49(1)(b)).

16. Your Rights

Right to Delete (Erasure)

You can delete all App data at any time by:

  1. Disconnecting your wallet within the App to remove wallet data
  2. Going to Android Settings > Apps > VeriCapture > Clear Data to remove all local data
  3. Uninstalling the App

This satisfies the right to erasure under GDPR Article 17, UK GDPR, and the Australian Privacy Act. Note that on-chain hashes cannot be deleted due to the immutable nature of blockchain technology, but they contain no personally identifiable information.

Right to Access

All data stored by the App is visible within the App itself (proof chain history, app settings, and wallet connection status). You may also contact us to request a summary of any data associated with your wallet address.

Right to Rectification (GDPR Article 16)

As the only externally-sourced data is your wallet public address from the Solana blockchain, the App displays factual on-chain data. If you believe any data is inaccurate, you can disconnect and reconnect your wallet to refresh on-chain data.

Right to Restriction of Processing (GDPR Article 18)

You may restrict the processing of your wallet address at any time by disconnecting your wallet. Media files are only processed when you explicitly select them for hashing — the App never processes files without your direct action. Disconnecting your wallet stops all data processing and removes your wallet address from local storage. You may reconnect at any time to resume the service.

Right to Object

You may object to the processing of your wallet address at any time by disconnecting your wallet, which removes your wallet address from local storage. Media file hashing is always initiated by you and can be stopped at any time by simply not selecting files for verification. Anonymous usage analytics can be switched off in Settings › Privacy.

Right to Portability

As all data is stored locally on your device, you have full control over your data at all times. Your wallet public address is the only externally-sourced data element and is already in your possession.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority:

17. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise your rights, use the in-app controls or contact us at the address below.

18. Brazilian Residents (LGPD)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with rights to access, correct, delete, and port your data. The legal basis for processing is your consent, given by connecting your wallet and selecting media files for hashing. You may withdraw consent at any time by disconnecting your wallet. Contact us to exercise your rights.

19. Canadian Residents (PIPEDA)

If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) provides you with rights regarding your personal information. The App processes only your wallet public address, stored locally on your device. You may withdraw consent at any time by disconnecting your wallet. No personal information is transferred to MidMightBit Games servers. To exercise your rights under PIPEDA, contact us at the address below or use the in-app controls.

20. South African Residents (POPIA)

If you are located in South Africa, the Protection of Personal Information Act (POPIA) provides you with rights to access, correct, and delete your personal information. Processing is based on the legitimate interest of providing the service you voluntarily opted into. Your wallet public address is stored locally on your device with AES-256 encryption. You may object to processing and request deletion at any time by disconnecting your wallet.

21. Japanese Residents (APPI)

If you are located in Japan, the Act on the Protection of Personal Information (APPI) provides you with rights to request disclosure, correction, suspension of use, and deletion of your personal data. The App stores only your wallet public address locally on your device. No data is provided to third parties as defined under APPI. To exercise your rights, use the in-app controls or contact us.

22. Indian Residents (DPDP Act)

If you are located in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) provides you with rights as a Data Principal including the right to access, correct, and erase your personal data. Consent is obtained when you connect your wallet and select media files for hashing. You may withdraw consent at any time by disconnecting your wallet. The App does not process data of children (persons under 18). No personal data is transferred to MidMightBit Games servers.

23. Turkish Residents (KVKK)

If you are located in Turkey, the Kişisel Verilerin Korunması Kanunu (KVKK, Law No. 6698) provides you with rights to learn whether your data is processed, request information about processing, learn the purpose of processing, request correction, request deletion, and object to processing. Your wallet public address is the sole data element, stored locally with encryption. Contact us to exercise your rights under KVKK.

24. Swiss Residents (FADP/nDSG)

If you are located in Switzerland, the revised Federal Act on Data Protection (FADP/nDSG) provides you with rights to access, rectify, and delete your personal data. Processing is based on legitimate interest (providing the service you requested). Cross-border data transfers to RPC providers comply with FADP requirements as they involve only publicly available blockchain data and your IP address via standard internet protocol. Contact the FDPIC or us to exercise your rights.

25. Singapore Residents (PDPA)

If you are located in Singapore, the Personal Data Protection Act (PDPA) provides you with rights to access and correct your personal data, and to withdraw consent. The App processes only your wallet public address with your consent (given by connecting your wallet). You may withdraw consent at any time by disconnecting your wallet. The App does not use your data for marketing purposes.

26. Thai Residents (PDPA)

If you are located in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) provides you with rights to access, correct, delete, restrict, and port your personal data. Processing is based on your consent, given by connecting your wallet. You may withdraw consent at any time by disconnecting your wallet. The App does not collect sensitive data as defined under the Thai PDPA.

27. Nigerian Residents (NDPR)

If you are located in Nigeria, the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023 provide you with rights to access, rectify, and delete your personal data. Consent is obtained when you connect your wallet. The App processes minimal data (wallet public address only), stored locally with AES-256 encryption. No data is shared with third parties beyond RPC endpoints. Contact us to exercise your rights.

28. Indonesian Residents (PDP Law)

If you are located in Indonesia, Law No. 27 of 2022 on Personal Data Protection (PDP Law) provides you with rights to access, correct, delete, and withdraw consent for processing of your personal data. Consent is obtained when you connect your wallet. You may withdraw consent and delete all data at any time by disconnecting your wallet.

29. Vietnamese Residents (PDPD)

If you are located in Vietnam, Decree No. 13/2023/ND-CP on Personal Data Protection provides you with rights to be informed of, consent to, access, and delete your personal data. The App stores only your wallet public address locally on your device. No personal data is transferred to MidMightBit Games servers. Contact us to exercise your rights.

30. Korean Residents (PIPA)

If you are located in South Korea, the Personal Information Protection Act (PIPA) provides you with rights to access, correct, suspend processing, and delete your personal information. The App collects only your wallet public address, stored locally with encryption. No data is provided to third parties as defined under PIPA. Processing may be suspended at any time by disconnecting your wallet. Contact us or the Personal Information Protection Commission (PIPC) to exercise your rights.

31. Children's Privacy

VeriCapture is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. The App is intended for users who own a Solana Seeker device. If you believe a child under 13 has used this App and connected a wallet, please contact us and we will provide guidance on removing the data.

32. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the effective date above. We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.

33. Contact

For questions about this Privacy Policy, data protection inquiries, or to exercise your data rights, contact:

MidMightBit Games
Melbourne, VIC, Australia
Email: aardappvark@proton.me

We aim to respond to all data protection requests within 30 days.