NeonShift Privacy Policy
NeonShift turns verified daily movement into onchain progress on Solana devnet. This policy explains exactly which data leaves your phone, why, for how long, and how to delete it. tSKR is a devnet test token with no monetary value and is not the official SKR token.
1. What stays on your phone
- Raw Health Connect records (individual step records, sleep sessions, their timestamps and source apps) are read on the device only. They are never uploaded.
- Raw motion sensor samples used for the optional 20-second motion check are processed on the device and discarded.
- GPS routes recorded when you start a run or walk in the app are encrypted and kept only on this phone. We upload a summary (distance, elapsed time, pace, splits and a GPS-quality score) — never coordinates. Deleting a workout deletes its route. Precise location is requested only while you use the app; a visible notification shows while recording continues on the lock screen.
- Exercise sessions imported from Health Connect (runs and walks, distance, steps and calories from the same source app) are read on the device; only the per-session summary is uploaded, labelled with its source.
- Wallet authorization tokens and API session tokens are stored in Android Keystore-backed secure storage.
2. What we send to our servers, and why
| Data | Purpose | Retention |
|---|---|---|
| Wallet address | Sign-in (Sign In With Solana), linking your claims to your wallet | Until you delete your data |
| Daily step total and per-minute step counts for the mission day; sleep session minutes; the Health Connect source app names | Verifying that a mission goal was met and detecting fake data before we sign an onchain attestation | At most 30 days |
| Motion-check statistics (cadence, rhythm, amplitude summaries — not raw samples) | Anti-cheat signal for step claims | At most 30 days |
| Tournament step totals reported during a weekend tournament | Leaderboard and settlement | At most 30 days after the tournament |
| App version, device model, Android API level | Compatibility and fraud detection | At most 30 days |
| Request logs (IP address, timestamps, request IDs, error codes) | Security, rate limiting and support | At most 30 days |
We never receive your health data outside of a mission or tournament claim you initiate, and we never sell or share it with third parties. There are no advertising SDKs in the app.
3. What is public on the blockchain
Your wallet address, mission claim receipts (task day and type, tSKR amount), gear level and XP, tournament entries and results, and achievement collectibles (NFTs) are recorded on Solana devnet. Blockchain data is public and permanent; it cannot be deleted by us. No step counts, sleep durations or other health values are written onchain — only whether a mission goal was met.
The in-app Gallery shows other players' wallet address, level, XP, streak and collectibles, all derived from public onchain events. It never shows health values.
4. Deleting your data
In the app, open Profile → Delete my backend data. This immediately signs you out on all devices and deletes your health summaries, verification records and request caches from our servers. If you have a stake in a tournament that has not settled, the tournament summary is kept until settlement and never longer than 30 days; you will see the exact date in the app. Signing in again afterwards is treated as new consent.
You can revoke Health Connect access at any time in Android Settings → Health Connect; NeonShift then stops reading health data.
5. Permissions we ask for
- Health Connect: Steps, Sleep (and optional background read) — to check daily missions.
- Activity recognition / motion sensors — optional 20-second on-device motion check.
- Internet — to talk to our API and Solana devnet.
6. Security
Traffic is TLS only. Session tokens are short-lived (15 minutes) with revocable refresh tokens. Every claim is signed by your wallet; server-side attestation keys are held in an isolated signer service. Our servers never hold your wallet private key.
7. Children
NeonShift is not directed at children under 16 and does not knowingly collect their data.
8. Changes and contact
We will post updates to this page and change the effective date above. Questions or deletion requests: privacy@neonshift.cc.