VaultMemo

Privacy Policy

VaultMemo v1.3.3  ·  no10messi.skr  ·  Last updated: May 2026
Local-first. Zero servers.
VaultMemo does not operate any proprietary servers. Your memo content is never transmitted to any server or recorded on the blockchain. Only a cryptographic hash fingerprint and transaction metadata are recorded on-chain.

Data Collection

VaultMemo collects no personal information. No account or registration is required.

Local Data Storage

The following data is stored locally on your device only and never transmitted to any server:

In-App File Management

VaultMemo includes an in-app file list that reads encrypted .vam files from the user-selected SAF folder. All file operations are performed locally on-device only.

On-Chain Integrity Verification

When you tap "Verify On-Chain" on a decrypted file, VaultMemo:

Encryption Certificate

VaultMemo allows users to generate a shareable encryption certificate image. The certificate is generated entirely on-device and contains only:

Sharing is performed through the Android system share sheet. No certificate data is transmitted to VaultMemo servers (none exist).

File Storage (On-Device)

Upon user action, VaultMemo writes encrypted .vam files to the user-selected SAF folder (chosen once via the Android system folder picker). SAF permissions persist across app reinstalls, so files remain accessible without re-granting permission.

Each file contains the AES-256-GCM encrypted memo (base64), the Solana TxID, and a timestamp. Memo content is never readable without the correct encryption key.

Blockchain Data (Public)

When you save a memo, VaultMemo submits a Solana transaction containing:

Your wallet address and the above data are visible on the public Solana blockchain. Your memo content is never included in or derivable from the on-chain record.

Hardware Security (Seed Vault)

VaultMemo uses the Solana Mobile Seed Vault as the hardware security element for session authentication. Signing is performed entirely within the Seed Vault chip — the app never receives private keys or raw biometric data. Because the encryption key is derived from the Seed Vault signature, it is hardware-bound and cannot be extracted from the device.

Wallet Security

VaultMemo does not access your private keys or seed phrase. All signing is handled exclusively via the Solana Mobile Seed Vault (built-in on Saga/Seeker devices) through the Mobile Wallet Adapter (MWA) protocol.

Third-Party Services

VaultMemo does not integrate advertising or analytics services. It communicates with the following external services only:

Solana RPC
primaryrpc.ankr.com/solana
fallbackapi.mainnet-beta.solana.com
Transaction submission, balance queries, and on-chain verification. Only your public wallet address and TxID are included.
Jupiter Price API
api.jup.ag — Real-time SKR/SOL price for fee calculation. No personal data is transmitted.
CoinGecko API
api.coingecko.com — Fallback price source. No personal data is transmitted.
Firebase Remote Config (Google)
Used to deliver app announcements and dynamic pricing configuration. Firebase Remote Config may collect a Firebase Installation ID and basic device/app metadata (OS version, app version) as part of its standard operation. No memo content or wallet private keys are transmitted.
firebase.google.com/support/privacy  ·  Google Privacy Policy
Solscan
solscan.io — Opened in your browser when you tap a TxID. No data is sent by the app itself.

Children's Privacy

VaultMemo does not knowingly collect any data from anyone, including children under 13.

Changes to This Policy

If this policy is updated, the new version will be published at this URL with a revised date.