Solulu Wallet 隐私政策
Privacy Policy
生效日期 / Effective: 2026-10-06
中文
Solulu Wallet 是非托管钱包。除下方「推送通知」一节列明的内容外,我们不收集你的任何个人数据。
在你的设备本地生成,仅存储于设备的安全区(iOS Keychain / Android Keystore),不参与 iCloud 或 Google 云备份,永远不会传输给 Solulu 或任何第三方。我们没有任何技术手段访问你的资产。
聊天身份的「终极密钥」同样在本机生成。你可以选择把它备份到 iCloud 钥匙串(由 Apple 端到端加密,Apple 与 Solulu 均无法读取)或手动导出保存;不备份则换机时需要手动导入。
我们不收集姓名、邮箱、电话、设备标识符、使用分析或任何个人信息。App 内没有账户系统,无需注册。唯一的例外是你主动开启推送通知时所必需的数据,详见下方「推送通知」。
App 会向公共区块链节点(RPC)与行情服务(CoinGecko)发起网络请求以显示余额与价格。这些请求包含你的钱包地址(本身即公开的链上信息)与 IP 地址,遵循对应服务方的隐私政策。我们不在服务器端记录这些请求。
聊天走 Solulu 自研的协议和自建服务器(位于新加坡)。消息在设备上用开源 Olm / Megolm 引擎端到端加密,服务器只存储和转发密文,无法解密。为此服务器会保存:你的设备公钥、各会话的成员表、群名和群简介(不加密,用于管理群和展示群邀请)、消息密文(供你的其它设备同步历史),以及用终极密钥派生的密钥加密的房间密钥备份(服务器解不开)。图片、视频、文件和语音短讯在设备上加密后上传到我们的媒体存储:服务器只保存密文,无法解密,并在上传 24 小时后自动删除;缩略图随消息本身端到端传递。你对联系人的备注、昵称和资料卡只存在本机及你自己的设备之间。
红包金额锁定在 BNB Smart Chain 上的公开智能合约中,24 小时无人领取自动退回。区块链交易是公开且永久的:任何人都能看到发送方地址、接收方地址和金额。
开启推送通知后,我们会收集并存储:
- 设备推送令牌(Apple/Google 分发推送所必需的标识符)
- 你的聊天身份标识(终极密钥地址)和设备标识——聊天服务器按会话成员表判断哪些离线设备需要被叫醒,推送服务器只收到「叫醒哪台设备」的信号。
因此,我们的聊天服务器知道每个会话有哪些成员、什么时间有新消息;推送服务器只知道某台设备在什么时间被叫醒过。这是提供聊天与推送服务无法避免的元数据。
我们的推送服务器永远无法知道:消息的内容(密文不经过它)、发送者是谁、消息有多长。推送通知本身不包含任何内容——没有发件人、没有正文、没有金额,只有一句「你有新消息」这样的固定提示。真正的内容只在你解锁设备、打开 App 之后在本地解密展示。
推送服务运行在独立的服务器上(push.solulu.io),使用独立的数据库,与网站会员体系完全隔离:它不知道、也无法查询你的会员资料、真实姓名或任何 KYC 信息。
关闭系统通知或重置钱包时,我们会删除对应的推送令牌;长期未活跃的令牌(180 天)也会被自动清除。我们不记录推送内容日志。
一对一语音通话的媒体密钥只在双方设备之间通过端到端加密的聊天消息交换。通话音频经我们的通话中继服务器转发,但服务器只经手密文,无法解密。为建立连接,服务器能知道:通话双方的聊天账户标识、通话开始与结束的时间。我们不录音,也不保存通话内容。
来电通知(VoIP 推送)只包含通话编号;锁屏上显示的来电者名称来自你本机存储的备注或对方的钱包地址,我们的服务器不参与名称解析。请知悉:锁屏上的来电者名称可能被旁人看到。
English
Solulu Wallet is a non-custodial wallet. Apart from what is listed under “Push Notifications” below, we do not collect any personal data.
Generated and stored locally in the device’s secure area (iOS Keychain / Android Keystore), excluded from iCloud and Google cloud backups. They are never transmitted to Solulu or any third party. We have no technical means to access your assets.
The chat identity’s master key is generated on your device as well. You may choose to back it up to iCloud Keychain (end-to-end encrypted by Apple; neither Apple nor Solulu can read it) or export it manually; without a backup, you import it yourself on a new phone.
No name, email, phone number, device identifiers, analytics, or any personal information. No account or registration exists in the app. The only exception is the data required when you choose to enable push notifications — see “Push Notifications” below.
The app makes network requests to public blockchain RPC nodes and the CoinGecko price API to display balances and prices. These requests contain your wallet address (already public on-chain data) and IP address, subject to those services' privacy policies. We do not log these requests server-side.
Chat runs on Solulu's own protocol and self-hosted servers (located in Singapore). Messages are end-to-end encrypted on your device with the open-source Olm / Megolm engine; the server only stores and forwards ciphertext it cannot decrypt. To do that, the server keeps: your devices' public keys, the member list of each conversation, group names and descriptions (unencrypted, used to manage groups and show group invites), message ciphertext (so your other devices can sync history), and a backup of room keys encrypted to a key derived from your master key, which the server cannot open. Photos, videos, files and voice messages are encrypted on your device before being uploaded to our media storage: the server keeps only ciphertext it cannot decrypt, and deletes it automatically 24 hours after upload. Thumbnails travel end-to-end inside the message itself. Contact notes, nicknames and profile cards exist only on your own devices.
Red-packet funds are locked in a public smart contract on BNB Smart Chain and refunded automatically if unclaimed after 24 hours. Blockchain transactions are public and permanent: anyone can see the sender address, the recipient address and the amount.
If you enable push notifications, we collect and store:
- Your device push token (the identifier Apple/Google require to deliver notifications)
- Your chat identity (master-key address) and device identifier — the chat server uses conversation membership to decide which offline devices to wake, and the push server only receives a “wake this device” signal.
As a result, our chat server knows who is in each conversation and when it receives a new message; the push server only knows when a given device was woken. This metadata is inherent to providing chat and push delivery.
Our push server can never know: the content of any message (ciphertext does not pass through it), who sent it, or how long it is. Push notifications themselves contain no content — no sender, no message text, no amounts — only a fixed line such as “You have a new message.” Actual content is decrypted and shown only on your device, after you unlock it and open the app.
The push service runs on separate infrastructure (push.solulu.io) with its own database, fully isolated from the website account system: it does not know and cannot query your membership profile, legal name, or any KYC information.
When you disable notifications or reset your wallet, we delete the corresponding push token; tokens inactive for 180 days are purged automatically. We do not keep logs of notification contents.
For one-to-one voice calls, the media key is exchanged only between the two devices, inside an end-to-end encrypted chat message. Call audio is relayed by our call server, which only handles ciphertext and cannot decrypt it. To set up the connection, the server knows the chat account identifiers of both parties and when the call starts and ends. We do not record calls or store their contents.
Incoming-call (VoIP) pushes contain only a call identifier. The caller name shown on your lock screen comes from your device’s local contact notes or the caller’s wallet address; our servers play no part in resolving it. Be aware that the caller name on the lock screen may be visible to bystanders.