Back to home

Privacy notice

Last updated: 17 September 2026

SecurVault processes two pieces of data so it can recognise you when the Telegram Mini App opens. Below is what is processed, why, and for how long.

Data controller
The SauBlockchain team, Sakarya University. Built for the TEKNOFEST 2026 Blockchain Competition, team 981614. Contact: ekip@saublockchain.io
Data processed
Your Telegram display name and your Telegram user id. Telegram signs both and sends them the moment you open the app; the server verifies the signature before storing them. Nothing else is stored.
Data not processed
No identity documents, phone numbers, addresses, payment cards or real money details are collected. Your private keys never exist in plaintext anywhere; they are decrypted only inside the network isolated signing service, only at the moment of signing, and wiped immediately after.
Purpose and legal basis
To bind your session to you and your wallets to their owner. The legal basis is that processing is necessary to provide the service you requested.
Retention
Your record is kept until you ask for it to be removed, or until the competition period ends. All Devnet data is deleted at the end of the period.
Audit log
Every signing request writes an audit record, and that record cannot be altered by design. It holds no name and no Telegram id, only a pseudonymous caller id. Deleting your record breaks the link, after which the log can no longer be traced to a person.
Your rights
You may ask whether your data is processed, ask for it to be corrected, and ask for it to be deleted. Write to ekip@saublockchain.io; deletion requests are handled the same day.
Scope warning
This product is under development and runs only on Solana Devnet with test USDC. It is not ready for use with real assets.