Privacy Policy
Last updated: 12 September 2026
This policy sets out what the platform collects about you, why, how long it is kept, and who else sees it. It describes what the system actually does rather than following a generic template.
We do not collect your identity documents
This comes first because it is a deliberate choice: the platform does not collect or hold your ID documents, legal name, date of birth or home address. There is no identity verification step and nowhere for document photos to be stored.
The name on your profile is a display name you choose. It is not a legal name.
What is collected
Account: email, password (stored as a one-way argon2id hash, which the platform cannot reverse), country, interface language, time zone, wallet currency.
Optional, from you: a display name and a contact phone number. The phone number is not used to sign in and not used to recover a password, it is not verified, and it is only there so we can reach you if needed. Leaving it blank changes nothing.
Two-factor authentication: if you enable it, the secret is stored encrypted with AES-256-GCM and recovery codes are stored hashed.
Tasks and money: the tasks you took, the order numbers and amounts you submitted, the payment screenshots you uploaded, obstacle declarations and their evidence images, your wallet balance and full transaction history, and your withdrawal requests.
Payout accounts: account details are stored encrypted with AES-256-GCM, and only a masked summary is shown in lists. A separate, irreversible fingerprint is kept so we can spot several accounts sharing one payout address.
Risk: the IP address used at sign-in and when taking a task, the country that IP resolves to, a browser/device fingerprint, the User-Agent, and whether a proxy or VPN was detected. When you take a task your live IP country is compared with your registered country — that is what makes the task possible at all.
Support: the messages you exchange with support and any images you send there.
Why it is collected
To send tasks to people who can actually complete them (country, IP country, credit level).
To settle money to you accurately and keep an auditable financial record.
To detect fraud: fabricated proof, many accounts from one device, several accounts sharing one payout address.
To run sanctions screening where the law requires it.
To answer you when you contact support.
Other people’s data that you see
A task may contain a recipient’s name, address and phone number. That is a third party’s personal data, not yours. It is released only after you take the task, hidden automatically once the order reaches a final state, watermarked on screen and not copyable.
You are under a duty of confidentiality for that data and must not pass it on or use it outside the task.
How long it is kept
Financial records (ledger entries, settlements and withdrawals) are kept long-term and cannot be altered, as accounting and audit obligations require. Records of this kind must be retained even if you close your account.
Payment proof, obstacle evidence and support images are kept for their purpose and deleted once any dispute is resolved and the retention period has passed.
Risk records (device fingerprints, IP addresses) are deleted with the account when it is closed.
Exchange-rate history is kept for 90 days.
Your rights
See and correct: your account details are under Profile. Your display name and contact phone can be changed or cleared at any time.
Export and delete: contact support to request an export or deletion of your personal data. Note that the financial records described above are subject to accounting and audit obligations and cannot be deleted on request; where that applies we will delete what we can and tell you what was kept and why.
Withdraw: the contact phone is optional and you can clear it whenever you like.
If you are in the European Economic Area you also have the right to object to processing, to restrict processing, and to data portability.
Security
Passwords are stored as argon2id hashes and cannot be reversed by the platform. Payout details and two-factor secrets are encrypted with AES-256-GCM.
Isolation by agent is enforced at the database level. Every back-office access to a payout account is logged.
Changing your password invalidates every session issued before it — so if you suspect your account has been taken over, changing the password signs the other devices out.
Contact
If you have any question about this policy, or want to exercise any of the rights above, reach us through support in the app.