The technical side
Everything between your browser and our servers travels over encrypted HTTPS/TLS, access to systems holding personal data is restricted, and we run continuous security monitoring. No platform can honestly promise absolute security, so we will not - but the measures above are in place and maintained.
If a personal data breach ever did occur, we are required to notify the Hungarian data protection authority (NAIH) within 72 hours of becoming aware of it under Article 33 GDPR, and to notify you directly if the breach is likely to put your rights at high risk under Article 34.
How long each type of data is kept
Retention is not one blanket period. Each category has its own limit and its own legal reason for existing:
| Data | Kept for | Why |
|---|---|---|
| Account data (email, username) | Life of the account + up to 5 years | Legal obligation and fraud prevention |
| Transaction and withdrawal records | 5 to 8 years | Tax and anti-money-laundering law |
| KYC identity documents | Deleted immediately once verification succeeds | Retained up to 7 years only where the law requires it |
| Biometric data (via Verisoul) | Max 3 years from last interaction | Deleted within 45 days of a deletion request |
| Server logs and IP addresses | Up to 90 days | Security |
| Blacklisted emails from deleted accounts | Up to 5 years | Stops banned users re-registering |
Worth knowing about KYC. Your identity documents are deleted as soon as verification succeeds. We do not keep a copy of your passport or ID sitting on a server after it has done its job - see why KYC verification matters.
Who else handles your data
We do not sell your data, and the only companies that process it are the ones needed to actually run the service. Each is a contracted data processor, not a buyer:
- Verisoul - identity verification and fraud prevention. See why we use Verisoul.
- Tremendous - processing PayPal payouts and gift card rewards.
- NOWPayments - processing cryptocurrency withdrawals.
- Cloudflare - CDN and protection against attacks.
- Hostinger - server hosting.
Other members see far less than you might expect. Your username and earnings can appear on public leaderboards, and nothing else - your email, balance and payout details are never exposed. You can turn even the username off; see who can see your profile information.
Your eight GDPR rights
If you are in the EU or EEA, you can exercise any of these by emailing [email protected]. We respond within 30 days, extendable by two months for genuinely complex requests, with notice:
- Access (Art. 15) - a copy of the data we hold about you.
- Rectification (Art. 16) - correction of anything inaccurate.
- Erasure (Art. 17) - deletion, except where law requires retention or a fraud investigation is open.
- Restriction (Art. 18) - pause processing while something is contested.
- Portability (Art. 20) - your data in a machine-readable format.
- Objection (Art. 21) - object to legitimate-interest processing. For direct marketing this right is unconditional.
- Withdraw consent (Art. 7(3)) - at any time, without affecting what was lawful before.
- Human review of automated decisions (Art. 22) - if an automated system flags your account, you can insist a person looks at it.
That last one matters in practice. Fraud checks here are partly automated, and Article 22 gives you the right to have a human review any significant automated decision rather than accept it as final.
Deleting your account
You can request deletion from your account settings or by emailing [email protected]. Most of your personal data is permanently removed within 30 days.
Two things survive deletion, and both are deliberate. Transaction records stay for the 5 to 8 years tax and AML law demands, and your email address goes onto a restricted-access blacklist for up to 5 years so that a banned account cannot simply be re-created with the same address. Nothing on that list is used for any other purpose or shared. The full detail is in the account deletion policy.
Withdraw first. Deleting the account does not pay out your balance. Cash out before you submit the request - see the fee breakdown for the cheapest way to do it.
The authoritative document is the full Privacy Policy, which lists every legal basis article by article. If you believe we have handled your data improperly, you also have the right to complain directly to your national supervisory authority. On the security side of your own account, see account security tips.

