SIGNET

Privacy Policy · Fantom Tech Labs · effective 9 July 2026

The short version: we collect nothing. No accounts, no analytics, no advertising identifiers, no trackers. Your messages, media, contacts, and payment amounts are end-to-end encrypted on your device before they ever reach a server — we could not read them if we wanted to.

No accounts

SIGNET has no sign-up. Your identity is a cryptographic key pair derived from a recovery phrase generated on your device. We never receive your name, phone number, email address, or any other identifier.

What our server stores

The delivery server relays sealed envelopes — ciphertext, padded to uniform sizes, encrypted with keys that exist only on your devices (MLS, RFC 9420). It holds, temporarily:

The server cannot see message content, media, contact names, group membership, or payment amounts. We publish a metadata honesty table describing exactly what any observer can and cannot learn.

Payments

The built-in wallet is self-custodial: keys are derived from your recovery phrase and never leave your device. We do not hold, transmit, or have access to your funds. Payments settle over the Lightning/Liquid networks via the Breez SDK; amounts are never visible to our server. The exchange rate shown for display is fetched by the server operator from a public price feed and served to the app; your amounts are converted on your device.

What stays on your device

Message history, contacts, and wallet state are stored in an encrypted database on your phone, protected by your device's security. Optional backups are encrypted with keys derived from your recovery phrase before they leave the app — a backup file is unreadable without your phrase.

Analytics and third parties

None. No analytics SDKs, no crash-reporting services, no advertising frameworks. The app makes network connections only to the delivery server configured in Settings and, for wallet operations, to Lightning/Liquid infrastructure via the Breez SDK.

Self-hosting

You may run your own delivery server and point the app at it — in that case, we operate no infrastructure for you at all.

Legal requests

We can only produce what we hold: sealed ciphertext and short-lived random routing identifiers. We cannot decrypt user content, identify users, or recover expired data, for anyone — including ourselves.

Changes & contact

Material changes to this policy will be published at this URL with a new effective date. Questions: team@hisignet.com.