Legal

Privacy Policy

Effective
<date>
Last updated
<date>

What the platform stores about you, why it stores it, who can see it, and what you can ask us to do about it. It describes the platform as it works today, including the parts that are deliberately limited.

1. Who we are

The platform is operated by [LEGAL ENTITY NAME] ("we", "us"), whose registered address is [REGISTERED ADDRESS]. For the purposes of applicable data-protection law, [LEGAL ENTITY NAME] is the controller of the personal data described in this policy.

This policy covers the website at the address you are reading it on and the Android application. It does not cover any other site or service you reach from ours.

2. What we collect

Everything in this section is stored by the platform itself. Nothing is inferred, bought, or obtained from a data broker, because no such integration exists.

WhatWhen it is collectedWhy
Account details — the display name you choose, your handle, your country and your language.When you create an account, and when you change them.To identify your account to you and to show the right language and region.
Sign-in address — the email address you register with.When you create an account.To have a way to reach you about your account, and to prevent two accounts sharing one address.
Password — stored only as a one-way hash produced by Argon2id, with the algorithm recorded beside it.When you create an account.To sign you in without the platform ever holding your password.
Device details — a randomly generated installation identifier, the platform, and optionally the app and operating-system versions you sign in from.On sign-in, and again when you sign in from a device that reports a newer version.To show you where your account is signed in, so a device you do not recognise is visible to you.
Sign-in sessions — a hashed token for each session, its type, the device it belongs to, and when it was last used.On sign-in.To keep you signed in, and to let a session be ended.
Activity — the opportunities you start, what you submit, the outcome, and the rewards that follow.As you use the earning features.To decide whether a reward is due, and to keep a record of why it was decided.
Rewards and balances — every reward the platform credits or reverses, and the resulting balance.As rewards are earned, confirmed, reversed or withdrawn.This is the money record. It is the reason a balance can be explained line by line.
Spin and daily-reward records — the tickets granted and spent, and each spin’s result.As you use those features.To apply their limits and to record what was awarded.
Referral records — your referral code, who you invited where the platform can tell, and the state of each referral.When a code is issued, and when an account is created with one.To operate the referral programme and to show you where each invitation stands.
Progress — experience points, levels reached, and daily counters.As you take part.To move you through the platform’s levels.
Withdrawal details — the amount requested, the method, a **masked** form of the destination, the state of the request, and the provider’s reference for it.When you request a payout.To make the payment, to review it, and to answer a question about it later. The destination is kept masked in the platform’s own records.
Support correspondence — anything you send us through a contact form, where one is offered.When you send it.To answer you.
Security and audit records — for actions that matter, what was done, when, by which kind of actor, and the reason code recorded for it. For actions taken through the API this includes **the IP address and the browser’s user-agent string**.As those actions happen.To investigate abuse, to satisfy the platform’s own accounting rules for money movement, and to make an audit trail that cannot be quietly edited — the records are chained with a hash.

About the IP address

We do not track where you browse. We do store an IP address and a user-agent string on the audit records of significant actions — sign-in, registration, token revocation, rate limiting, and money movement. That is a record of the action, not a history of your visits. Many of the platform’s own automated records deliberately store neither.

The platform asks for no special categories of data. Please do not send identity documents, medical information, or anything of that kind through a support form — nothing in the service needs it, and no form asks for it.

3. What we do not do

  • **No analytics and no tracking.** The website loads no analytics service, no advertising network, no social plug-in, and no third-party script of any kind. Fonts are the ones already on your device, so not even a font is fetched from elsewhere.
  • **No selling of personal data.** We do not sell it, and there is no arrangement under which anybody else may use it for their own marketing.
  • **No device fingerprinting of the hardware kind.** The device identifier the app sends is a random value generated on install. No IMEI, advertising identifier, MAC address, or serial number is collected or stored.
  • **No location tracking.** Country and language are the values you supplied, not a derived location. The app requests no location permission.
  • **No marketing email.** The platform runs no mailing list, and no delivery provider is wired in at all.

It follows from the last point that the platform **cannot currently send you an email** — not a receipt, not a notification, not a password reset. That limitation is real and is why the account features that would depend on email are still to come.

4. How we use it

We use the information described above to provide the service you asked for, and for the things that cannot be separated from providing it:

  • Creating and securing your account, including recognising that a device is not one you have used before.
  • Recording activity, deciding rewards, and holding the balance those rewards produce.
  • Assessing whether a referral qualifies under the programme’s published rules.
  • Reviewing and processing payouts, and keeping the record of each one.
  • Detecting and handling abuse — duplicate accounts, manipulated referrals, automated earning — and taking the action the Terms allow.
  • Meeting the platform’s own accounting obligations: every movement of value is recorded in a ledger that balances, and those records are not deleted on request.
  • Answering you when you contact us.

We do not use your information to build a profile for advertising, because there is nowhere for such a profile to be used — no advertising exists in the service.

5. Who can see it

Two groups can, and nobody else:

  • **The platform’s own operators.** Staff who review payouts, referrals or abuse cases can see the account and the records relevant to the case they are handling. Every action they take is written to the audit trail, which is chained so that a record cannot be altered without the chain showing it.
  • **Our payment providers, when you request a payout.** A payout is made by a third party — a mobile financial service or a digital-asset network. When you request one, the amount and the destination you supplied are given to the provider that carries it out. That destination is the one you entered, and it is what the provider needs to deliver the funds.

Payout providers are not active yet

The platform’s payout providers are configured but blocked: no live payout has been made, and no data has been sent to one. When a provider is switched on, that is the moment the paragraph above becomes true in practice as well as in design, and this policy will be updated with the provider’s identity before it is.

Beyond those two, we disclose information only where the law requires it, or where it is necessary to establish or defend a legal claim. If we are ever compelled to disclose something about your account, we will tell you unless we are legally forbidden from doing so.

7. How long we keep it

Retention differs by record, because the records are not alike:

  • **Account and identity details** are kept while the account exists.
  • **Money records** — rewards, ledger entries and payouts — are kept for as long as the platform must be able to explain a balance. They are not removed when an account is closed, because a payout made last year has to remain explicable.
  • **Security and audit records** are kept for the same reason, and because they are what an investigation would need. The audit trail is chained, so removing a record part-way through it would invalidate the evidence after it.
  • **Idempotency records**, which stop the same request being applied twice, are deleted automatically after about a day. They are the only category with an automatic expiry.
  • **Support correspondence** is kept while it is useful, and for as long as we may need to show what was said.

We have not written fixed periods for each category into this policy, because the platform has no automated deletion that would honour them and a period nobody could observe would be a promise rather than a description. Closing that gap — a retention schedule the system actually enforces — is part of the work to come, and this clause will change when it does.

8. Your choices

You can ask us to do the following. Some of them the platform supports directly today, and some of them are handled by a person — this section says which, so you are not left writing to a form that does nothing.

What you can ask forHow it works today
Correct your name or handleDirectly, in the app: the profile screen lets you change your display name.
See where your account is signed in, and end a sessionDirectly, in the app: the security settings list your devices and can sign the others out, leaving the device you are holding signed in.
A copy of the personal data we hold about youBy writing to [CONTACT EMAIL]. A person assembles it. There is no export button yet, and we will not pretend otherwise.
Correction of something that is wrong and that you cannot change yourselfBy writing to [CONTACT EMAIL], and we will correct it or explain why the record must stay as it is — a ledger entry, for instance, is a record of what happened rather than a statement about you.
Deletion of your accountBy writing to [CONTACT EMAIL]. We will close the account and remove the details that are not needed to explain its history. The money and audit records are kept, as described above, and this is the one part of a deletion request we cannot simply carry out.
Objection to processing we base on a legitimate interestBy writing to [CONTACT EMAIL]. We will stop, unless we have a reason that overrides — and we will tell you which and why.

If you are in a jurisdiction that gives you a right to complain to a supervisory authority, you may do so. We would rather you came to us first, but that is your choice and not a condition of anything.

There is no self-service deletion button

An account is closed by asking us. The platform has no delete-my-account control, and we would rather say so than describe one that does not exist.

9. Where your information is processed

The platform’s database and application run on infrastructure that [LEGAL ENTITY NAME] operates, and that infrastructure has a location — [DATA PROTECTION CONTACT] should be asked to confirm which, because the answer depends on the hosting that is chosen at launch and not on anything in the software.

If information is processed outside the country you live in, we will put in place the safeguards the applicable law requires — and we will name them here, with the infrastructure, rather than describe a mechanism in the abstract.

10. Children

The platform is not for children. It is not offered to anyone below [MINIMUM AGE], and an account found to be held by someone below that age will be closed.

Nothing in the service is designed to be attractive to a child, and we do not knowingly collect information from one. If you believe an account belongs to a child, write to [CONTACT EMAIL] and we will act on it.

11. How it is protected

  • Passwords are stored as Argon2id hashes. The platform never holds the password itself.
  • Sign-in tokens are stored as SHA-256 hashes. A copy of the database does not contain a usable token.
  • Every session belongs to a device you can see and end from inside the app.
  • Significant actions are written to an append-only, hash-chained audit log, so that altering one record breaks the chain and the break is detectable.
  • Access from the platform’s own staff is role-based and every action they take is recorded.
  • Transport is encrypted in transit, and the platform holds no card numbers, no bank credentials, and no recovery phrases, because no part of it asks for them.

We are not going to describe this as unbreakable, and we do not claim a certification we have not been audited for. Security is a practice, not a badge, and the honest summary is: the platform is built with care, and no system is beyond risk.

12. Changes to this policy

When this policy changes, the new version is published here with a new effective date. The date at the top of the page is the date of the version you are reading.

If a change materially affects what we do with your information, we will make it visible rather than quietly reissuing the text — by notice in the app, since email is not available. Continuing to use the platform after a change takes effect means the new version applies.

Contact

Questions about this policy go to [CONTACT EMAIL]. The help centre answers questions about how the platform works, and the app itself is where an account is managed.

Related policies

Back to top