SIGNET

Privacy Policy · Fantom Tech Labs · effective 6 September 2026

The short version: we collect nothing. No accounts, no analytics, no advertising identifiers, no trackers. Your messages, media, contacts, and payment amounts are end-to-end encrypted on your device before they ever reach a server — we could not read them if we wanted to.

No accounts

SIGNET has no sign-up. Your identity is a cryptographic key pair derived from a recovery phrase generated on your device. We never receive your name, phone number, email address, or any other identifier.

What our server stores

The delivery server relays sealed envelopes — ciphertext, padded to uniform sizes, encrypted with keys that exist only on your devices (MLS, RFC 9420). It holds, temporarily:

One thing it keeps permanently, and only if you ask for it: if you claim a public @handle so people can pay you, the server stores that handle, the identity key it points at, and a signed, append-only record of every time either changed. A handle is a public address by design, and that record is served to anyone precisely so a substitution cannot be hidden. Claiming a handle is optional, and without one we hold no identity key and no name for you.

The server cannot see message content, media, contact names, group membership, or payment amounts. We publish a metadata honesty table describing exactly what any observer can and cannot learn.

Payments

The built-in wallet is self-custodial: keys are derived from your recovery phrase and never leave your device. We do not hold, transmit, or have access to your funds. Bitcoin payments settle over Lightning and USDt (Tether USD) settles on the Liquid network, both through the Breez SDK; amounts are never visible to our server. Each network charges its own fee, and USDt is issued by Tether, so holding it is a claim on Tether rather than on bitcoin. The exchange rate shown for display is fetched by the server operator from a public price feed and served to the app; your amounts are converted on your device, and a USDt amount is already in dollars, so no rate is applied to it at all.

SIGNET Pro

SIGNET Pro is an auto-renewable subscription sold by Apple through the App Store and verified on your device. We run no account server, our delivery server carries no record of who subscribed, and the receipt never leaves your phone. Apple handles the purchase and can see it, as it can see any App Store purchase; we cannot. Pro changes payment limits and adds on-device spending insights and CSV statements. No security or privacy feature is ever behind it.

What stays on your device

Message history, contacts, and wallet state are stored in an encrypted database on your phone, protected by your device's security. That database is excluded from iPhone and iCloud device backups, so no copy of it rides along to Apple. SIGNET backups to your private iCloud (on by default, can be turned off) are encrypted with keys derived from your recovery phrase before they leave the app: a backup file is unreadable without your phrase, and erasing the app does not remove a backup already in your iCloud.

You can lock the app with Face ID, which closes the encrypted database and drops its key rather than merely covering the screen, and Erase this device destroys the keys first and then the messages, media and payment history, so what was on the phone is not recoverable from it. Deleted rows are overwritten rather than left as free pages. Notification previews are decrypted and drawn on the device; the push that wakes the app carries no content and no sender.

Analytics and third parties

None. No analytics SDKs, no crash-reporting services, no advertising frameworks. The app makes network connections only to the delivery server configured in Settings and, for wallet operations, to Lightning/Liquid infrastructure via the Breez SDK.

Self-hosting

You may run your own delivery server and point the app at it — in that case, we operate no infrastructure for you at all.

Legal requests

We can only produce what we hold: sealed ciphertext, short-lived routing identifiers, push tokens, and the public @handle log for people who claimed one. We cannot decrypt content, recover expired data, or identify anyone who has not claimed a public handle.

Changes & contact

Material changes to this policy will be published at this URL with a new effective date. Questions: team@hisignet.com.