← Siner

Privacy Policy

Last updated: June 19, 2026

Siner is a client for the Nostr protocol with a built-in Lightning wallet. Your identity is a cryptographic keypair you control — not an account on our servers — and your wallet is self-custodial, with keys that stay on your device. Siner is built to collect as little as possible: there are no ads, no third-party tracking, and no data sales. The limited telemetry we do collect — crash diagnostics and anonymous, aggregated product analytics — is never linked to your identity and can be turned off. This policy explains the data Siner processes, what's public by design, and the choices you have.

Your keys stay with you

Your private key (your "nsec") is generated on your device and stored in the iOS Keychain, marked so it does not sync to iCloud or other devices. Siner never transmits or stores your private key in readable form — every post, message, and signature is signed on your device.

Email & account recovery

Email is optional and only used if you turn on encrypted backup. When you do, we use your email address to send a one-time verification code through our email provider (Resend). The code is single-use and expires after about 15 minutes; we don't keep your email address after that. Your backup itself is stored under a one-way hash of your email, so the stored backup is not linked to a readable address.

Encrypted key backup

If you enable backup, your key is encrypted on your device with your chosen password (PBKDF2 with 600,000 iterations, then AES-256-GCM) before anything is uploaded. Our server stores only the resulting ciphertext and the parameters needed to decrypt it on your device — it has no ability to decrypt your key. This also means that if you lose your backup password, no one (including us) can recover your key. Save it somewhere safe.

Your wallet & funds

Siner includes a built-in, self-custodial Lightning wallet (powered by the Breez "Spark" SDK). The wallet is secured by a seed generated on your device and stored only in the iOS Keychain (it does not sync to iCloud); we never receive it, and it has its own 12-word recovery phrase, separate from your Nostr key. Using the wallet means your device communicates with Breez/Spark infrastructure and the Lightning Network to send and receive payments. If instead you connect your own external wallet over Nostr Wallet Connect (NWC), its connection string is stored in your device Keychain and used to ask that wallet to pay or receive — Siner does not hold those keys either. Either way, Siner is not a custodian: we cannot access, freeze, or recover your funds, and if you lose your device without your recovery phrase, the funds in the built-in wallet cannot be recovered.

What's public by design

Nostr is a public network. When you post, update your profile, react, repost, zap, or file a report, that event is published to relays as signed, public data and is effectively permanent — relays and other people can keep copies indefinitely, including copies on relays we don't operate.

This includes: your profile (display name, bio, picture, lightning address), your posts and the media in them, your reactions and reposts, your zaps (which publicly link who tipped whom and how much), and abuse reports (which publicly link your key to the content you reported).

Camera, microphone & media you upload

Siner uses your camera and microphone only while you're actively capturing a photo or video to publish, and your photo library only for items you choose to attach. Captured or selected media stays on your device until you publish it. When you do publish, images and videos are uploaded to our content delivery network and served at public HTTPS URLs — anyone with the URL can view them, and other servers may cache them. Publishing is public by design — don't upload anything you wouldn't want to be public and persistent.

Location & device details

Siner can attach proof-of-authenticity context to autographs — capture time, and optionally your GPS location and device model. Location and device sharing are controlled by toggles in Privacy settings. When a toggle is off, that detail is left out of both the public event and the image you upload. When it is on, your location and/or device can appear in the public post, its proof metadata, and the image's embedded EXIF data. Turn these off before capturing if you don't want that information shared.

Direct messages & postcards

Direct messages are end-to-end encrypted (NIP-17 gift wrapping). The decrypted text is cached only on your device; only ciphertext, addressed to your recipient, is sent to relays. We cannot read your messages. Metadata minimization is applied (timing is jittered and delivery defaults to our relay), but as with all messaging, your recipient and the relays involved can observe that an encrypted message was sent.

Postcards — sealed pieces you send to one person instead of posting publicly — are delivered the same encrypted way: only you and the recipient can open them, and we cannot read their contents.

Handles (NIP-05)

If you claim a username@siner.me handle, we store a mapping from that name to your public key so others can verify you. That mapping is served publicly so any Nostr client can resolve it.

Greeting card invites

If you invite someone who isn't on Siner to a group greeting card, you provide their email address so we can send them an invite (delivered through our email provider, Resend) with a one-time claim link. You're responsible for having that person's consent to email them. We store a claim record — the email or a claim token plus the card and pubkey references needed to activate the card — which expires automatically after about 60 days. We don't use these addresses for marketing, and you can ask us to remove an invite record at support@siner.me.

Proofs & the Siner Seal

A Siner Seal is a proof bundle for autographs and similar content. It contains content hashes, signing metadata, optional location/device context (per your toggles above), timestamps, and a cryptographic signature, and it can be anchored to the Bitcoin blockchain via OpenTimestamps (only a hash is sent to public timestamp servers — never your content). Seal bundles are stored under their content hash and are publicly retrievable so anyone can re-verify them. Don't put anything in a proof you don't want public.

No tracking, no advertising

Siner contains no advertising and no third-party tracking SDKs. The app does not use an advertising identifier and does not ask to track you across apps or websites; our privacy manifest declares no cross-app tracking. We do not sell your data. The only data that leaves your device beyond what you publish is the first-party, anonymous telemetry described next (diagnostics and product analytics), which you can turn off.

Diagnostics (crash & performance)

To find and fix bugs, the app may send crash and performance reports using Apple's MetricKit. These are diagnostics — not linked to your identity and containing no message content. Apple delivers them roughly once a day. They're reflected in the app's privacy manifest (Crash Data and Performance Data, used for app functionality).

Product analytics (anonymous & optional)

To understand how Siner is used and where it frustrates people — for example, which step of a flow people abandon, or which screen they bounce off — the app sends anonymous, aggregated product analytics. This data is tied to a random per-install identifier generated on your device, never to your npub, name, email, or any personal information, and it carries no message or post content. Events are aggregated into totals on our server (counts of how features and screens are used); we do not build per-person activity profiles. You can turn this off at any time in Settings → Privacy, and we can disable it remotely. It is declared in the app's privacy manifest as Product Interaction data used for analytics, not linked to your identity and not used for tracking.

Content moderation

To keep Siner safe, content you publish to our relay and media on our CDN may be reviewed when reported and, where enabled, automatically screened for prohibited material (such as illegal content). When automated screening is enabled, the public post text and public image URLs are sent to our AI moderation providers — OpenAI (its moderation service) and/or Anthropic (Claude) — to classify them; they receive only public content, never your direct messages. This applies only to public content on the infrastructure we operate. Your direct messages are end-to-end encrypted and are never scanned or readable by us. See our Community Guidelines for what's enforced and how to appeal.

Network basics (IP addresses)

Like any internet app, connecting reveals your IP address to the servers you contact. That includes our relay and CDN, and also third parties you reach directly — the hosts of other users' images, lightning-address providers when you zap, and public timestamp servers. We don't use IP addresses to build profiles of you; our relay keeps standard short-lived web-server logs for security and reliability.

Service providers

We rely on a small set of providers, each handling only what its function needs: DigitalOcean (hosts our Nostr relay and the media CDN), Resend (sends recovery and greeting-card invite emails), Cloudflare (DNS, and depending on configuration may route traffic to our domain), Breez (provides the self-custodial Lightning wallet SDK and Spark infrastructure the built-in wallet connects to), OpenAI and Anthropic (classify public content for our automated moderation screening, when enabled — they receive no private messages), Apple (an optional, currently-inactive device-integrity check for Seals), and the public OpenTimestamps calendars (receive only a hash to anchor a proof). When you zap, you also contact the recipient's Lightning-address provider directly.

Your choices & rights

You control what you share: location and device toggles, whether to enable account backup, whether to claim a handle, and whom to mute or block. You can export a copy of your data from Privacy settings, and you can delete your account at any time in Settings → Account & Security → Delete Account. Your built-in wallet has its own 12-word recovery phrase (Settings → Wallet) so you can move your funds independently of your account.

For access, correction, or deletion requests under laws like the GDPR or CCPA, email support@siner.me with the subject "Data Subject Request." Most of your data lives on your own device and on the public network rather than on our servers; we'll help with what we hold.

The limits of deletion

Deleting your account removes your local data and keys from your device, broadcasts a deletion request to relays, and deletes the media we host for you. But because Nostr is decentralized, content you already published may persist on relays and caches we don't control, and a deletion request is a request other relays may not honor. If you created an encrypted backup, note that the (unreadable) backup may persist on our servers after account deletion; email support@siner.me to have it removed. Deleting your account does not move or destroy the funds in your built-in wallet — that wallet is controlled by its own recovery phrase, so back it up and withdraw your sats before deleting if you want to keep them.

Children

Siner is not directed to children. You must meet the minimum age required in your jurisdiction and by the App Store rating to use it. We don't knowingly collect data from children; contact us if you believe a child has used the app and we'll help.

Changes

We'll update this policy as Siner evolves and revise the date above. If we add anything that changes what we collect — for example, optional diagnostics — we'll describe it here and surface material changes in the app before it takes effect.

Contact

Questions about this policy: support@siner.me. The data controller is Siner.me, Dubai, United Arab Emirates.

Last updated: June 19, 2026

Questions? support@siner.me

A creator network on Nostr.