Legal
Privacy Policy
Last updated: 2026-08-11
In plain English
- CoinTap is run by HashCore AI, a sole trader in the United Kingdom. We are the data controller.
- To run your account and pay you, we hold your email address, display name, coin balance, transaction history and the payout identifier you give us (for example your PayPal email).
- We record the IP address you earned from and the IP address you cash out from. That is how we catch fake and duplicated accounts. It is the single most important fraud control we have.
- Our partners — survey networks, offer networks and Google's ad system — collect data directly from you inside their own screens. The profiling answers you give in a survey wall belong to that network. We never see them.
- We do not sell your personal data. We do not read your contacts, your location, your photos or your files, and CoinTap never asks for those permissions.
- CoinTap is for adults only — 18+.
- You can ask for a copy of your data, or ask us to delete it, at contact@hashcoreai.com.
Contents
- Who we are
- Scope
- What we collect
- IP addresses and fraud prevention
- Partners who collect data from you
- Why we use data, and our legal bases
- Advertising and consent
- Automated decisions
- Who we share data with
- International transfers
- How long we keep it
- Your rights
- Children
- Security
- Cookies and this website
- Changes and contact
1. Who we are
CoinTap is operated by HashCore AI, an independent software business established in the United Kingdom. For the purposes of the UK GDPR and the EU GDPR, HashCore AI is the controller of the personal data described in this policy.
Contact for anything in this policy, including all data protection requests: contact@hashcoreai.com.
We are not required to appoint a Data Protection Officer. Privacy questions go to the address above and are handled by the operator directly.
One important exception to our role: for the demographic and profiling answers you give inside a partner's survey wall, that partner is the controller of those answers, not us. See section 5.
2. Scope
This policy covers the CoinTap mobile app and these web pages. It does not cover third-party survey walls, offer walls, advertiser destinations or app stores, which operate under their own privacy notices.
3. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address, display name, sign-in method (email and password, Google, or Apple), your CoinTap user ID, account creation time | You, at sign-up, or your sign-in provider |
| Device and platform data | Platform (Android or iOS), app version, a Firebase installation identifier, device attestation results, and a push notification token if you allow notifications | Your device and the app |
| Earning and balance data | Coin balance, lifetime earned, full transaction history (what you earned, when, from which partner), maturation status, streaks, mini-game scores, your daily game-lives tally, loyalty tier, referral relationships | Generated by your use of CoinTap |
| Fraud-prevention data | The IP address recorded when a partner reports that you completed a survey or offer; the IP address recorded when you request a cashout; fraud-screening results for those addresses; reversal and clawback history; risk and ban notes | Partner callbacks, your cashout request, and our fraud-screening provider |
| Payout data | The payout identifier for the method you choose (for example your PayPal email address or a gift-card delivery email), the amount, the status of the request, timestamps, and our record of the payment | You, when you request a cashout |
| Support data | The content of emails you send us and our replies | You |
What we do not collect. CoinTap does not collect your contacts, your precise or approximate location, your photos, your files, your health data, your phone number or your biometric data, and it does not request the device permissions that would allow it to.
4. IP addresses and fraud prevention
We want to be explicit about this because it is the most privacy-sensitive thing we do.
- Earning-time IP. When a survey or offer network confirms a completion, its server-to-server callback can include the IP address you were using at the time. Where it does, we store that address alongside that transaction.
- Cashout-time IP. When you submit a cashout request, we record the IP address the request came from.
Why. Comparing the two answers the one question that decides whether a payout is safe: does the person earning and the person withdrawing look like the same real individual, in the same place? Without it, the most common fraud patterns — one person running dozens of accounts, a VPN used to reach offers from a country you are not in, or reward farming through proxies — are effectively invisible, and the cost lands on honest users in the form of higher cashout thresholds.
Screening. At manual review we may submit a cashout IP address to IPQualityScore, a fraud-screening provider, which tells us whether that address is a known proxy, VPN or data-centre address and which country it resolves to. We send the IP address only. We do not send your name, email, balance or transaction history.
Legal basis and balancing. This processing relies on our legitimate interests (Article 6(1)(f)) in preventing fraud and protecting the reward economy and our partners. We have weighed it against your interests: the data is limited to IP addresses already visible to any internet service, it is accessed only by the operator and only at review time, it is not used for advertising or profiling you as a customer, and the service could not pay honest users without it. You can object to this processing at any time (see section 12) — but be aware that we cannot approve cashouts we are unable to fraud-check.
5. Partners who collect data directly from you
Several partners collect data from you in their own screens, under their own privacy notices, as independent controllers. We do not receive that data unless stated.
Survey networks
We currently work with CPX Research GmbH (Germany). When you open a survey wall, CPX and the market-research buyers behind it collect the demographic and profiling answers you give inside that wall — age band, gender, household, employment, income band, interests and similar — together with your device data, IP address and the answers you give within each survey. Those answers stay with them. CoinTap does not receive them. What we receive back is only: your CoinTap user ID, an event identifier, the payout amount, whether it was a completion or a screen-out, and (where their callback provides it) the IP address you clicked from.
Read CPX Research's own privacy notice and consent choices inside their survey wall before answering profiling questions. Other survey networks, including BitLabs, may be enabled in future and will work the same way.
Offer networks
Offer walls such as ayeT-Studios and AdGem may be enabled in the app. When you open one, the network receives your CoinTap user ID (a pseudonymous identifier), your device and advertising identifiers, and your IP address, and it tracks whether you completed the advertised action in the advertiser's app. The advertiser may also collect data from you directly once you install or sign up. Both act as independent controllers for that processing.
Google AdMob
Rewarded video and other adverts in CoinTap are served by Google AdMob (Google Ireland Limited and Google LLC). Google receives your advertising identifier, IP address, device information and ad interaction data. See Google's Privacy Policy. Personalisation is consent-gated — see section 7.
Processors acting on our instructions
- Google Firebase and Google Cloud — authentication, database, serverless functions, app attestation, push delivery and hosting for these pages.
- IPQualityScore (United States) — IP fraud screening as described in section 4.
Payment and fulfilment
PayPal and gift-card fulfilment providers receive the payout identifier you supply and the amount, so the payment can be made. They are independent controllers for the payment itself and apply their own terms and privacy notices.
6. Why we use data, and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Create your account and sign you in | Account data | Performance of a contract, Art. 6(1)(b) |
| Credit coins; run balances, streaks, games, tiers and challenges | Earning and balance data | Performance of a contract |
| Process and pay your cashouts | Payout data, balance data | Performance of a contract |
| Prevent fraud, multi-accounting, VPN and proxy abuse; protect the reward pool and our partners | IP addresses, device and platform data, referral relationships, screening results | Legitimate interests, Art. 6(1)(f) |
| Keep accounting, tax and partner-reconciliation records | Transaction and payout records | Legal obligation, Art. 6(1)(c), and legitimate interests |
| Show personalised advertising and measure it | Advertising identifier and ad interaction data, held by Google | Consent, Art. 6(1)(a), plus consent for storing or accessing identifiers on your device |
| Show non-personalised advertising, and limit ad frequency and ad fraud | Limited device and ad-serving data | Legitimate interests, with consent where required for device access |
| Send you push notifications about rewards and challenges | Push token | Consent, given through the device permission and withdrawable in your system settings |
| Answer your support emails | Support data, account data | Legitimate interests in supporting our users |
| Comply with legal requests and defend legal claims | Whatever is relevant | Legal obligation and legitimate interests |
The profiling answers you give inside a survey network's wall are processed by that network on its own legal basis, normally the consent it collects from you in that wall.
7. Advertising and consent
CoinTap shows advertising, including the rewarded videos you can choose to watch in exchange for an extra mini-game round. Rewarded videos pay no coins.
- We do not serve personalised advertising without a lawful consent. Where personalised ads are served in your region, a consent prompt is shown before any such ads appear, and your choice can be revisited when it applies. On iOS, personalised advertising additionally requires App Tracking Transparency permission.
- Without that consent you still see adverts and can still watch rewarded video for the extra round it grants, but the adverts are non-personalised. Google still processes a limited amount of data in that case for ad delivery, frequency capping, fraud prevention and reporting.
- You can withdraw tracking permission at any time in your device's system privacy settings.
8. Automated decisions
Some checks are automatic: minimum thresholds, maturation, duplicate payout identifiers, owed-coin blocks and IP screening. These can delay or block a cashout request. However, a person reviews every payout before money moves, and account bans are decided by a person. We do not make decisions producing legal or similarly significant effects on you by automated means alone within the meaning of Article 22. If a decision goes against you, email us and we will look at it again.
9. Who we share data with
- The processors and partners listed in section 5.
- Partner networks, for reconciliation and reversal handling — identified by the pseudonymous user ID and event identifier we already exchanged with them.
- Our payment and gift-card fulfilment providers, for the payout you request.
- Professional advisers, such as our accountant, where necessary.
- Law enforcement, regulators or courts where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.
- A purchaser or successor, if the business is ever sold or restructured — you would be told beforehand.
We do not sell personal data, and we do not share it for cross-context behavioural advertising beyond the consent-gated advertising described in section 7.
10. International transfers
Some of our providers are outside the UK and EEA, principally in the United States (Google, IPQualityScore, PayPal). Where personal data is transferred there, we rely on appropriate safeguards: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and, where the provider is certified, the EU–US Data Privacy Framework and its UK Extension. You can ask us for details of the safeguards used for a specific provider.
11. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account exists, then deleted or anonymised within 90 days of closure, except where a row below requires longer |
| Transaction and payout records | 6 years after the transaction, to meet UK tax and accounting record-keeping requirements and to handle partner reversals and payment disputes |
| Fraud-prevention data (earning and cashout IP addresses, screening results, risk notes) | Up to 24 months, and longer for an account we have banned for fraud, for as long as necessary to keep that ban effective |
| Ban records, including the payout identifiers already used on a banned account | For as long as needed to enforce the ban and prevent re-registration |
| Support emails | Up to 24 months from the last message |
12. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, where no overriding reason to keep it applies.
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format.
- Object — object to processing based on legitimate interests, including our fraud-prevention profiling.
- Withdraw consent — for anything based on consent, such as personalised advertising or push notifications, at any time and without affecting what was done before you withdrew it.
- Complain — to a data protection authority.
How to exercise them: email contact@hashcoreai.com, ideally from the address on your account. We reply within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask you to confirm control of the account email address before we act — this protects you from someone else requesting your data.
Deleting your account, in the app: you do not have to email us to close your account. Open the You tab and tap Delete account; the app shows you exactly what is lost and asks you to type DELETE to confirm. Deletion is permanent and cannot be undone: your profile, balance, earning history, streak, tier and referral code are erased, and all your coins are forfeited, including pending coins and earnings still maturing. We cannot delete an account while a cashout is in review, so wait for it to finish first, and a suspended account cannot be deleted in the app — email us instead.
Limits to be aware of: we cannot delete records we are legally required to keep, principally transaction and payout records (see section 11), and we may retain the minimum fraud-prevention data needed to keep a ban effective. This applies equally to an in-app deletion: everything else goes, but those records remain. Coins are not money and cannot be transferred out except through an approved cashout, so request any cashout you are eligible for before you delete.
Complaints. If you are unhappy with how we handled your data, please tell us first so we can fix it. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk, or, if you are in the EEA, to the supervisory authority in your country of residence, work or the place of the alleged infringement.
13. Children
CoinTap is strictly for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. Anyone found to be under 18 will have their account closed and their data deleted, subject to the retention requirements in section 11, and any balance forfeited. If you believe a minor has registered, contact us and we will act.
14. Security
We use Firebase Authentication for credentials, app attestation to reject requests that do not come from a genuine CoinTap install, server-side security rules so balances cannot be written by the client, signed and IP-allowlisted partner callbacks, encrypted transport, secrets held in Google Secret Manager, and administrative access limited to the operator with actions written to an audit log. No system is perfectly secure; if a breach is likely to result in a high risk to your rights, we will notify you and the relevant authority as required.
15. Cookies and this website
These web pages are static. They set no cookies, run no analytics, and load no third-party scripts, fonts, images or trackers — everything on the page is served from this site.
The app itself does not use browser cookies for CoinTap's own purposes. Partner survey and offer walls open in a web view and may set their own cookies and storage under their own policies, and Google's advertising SDK uses on-device identifiers as described in section 7.
16. Changes and contact
We may update this policy. The date at the top always shows the current version, and material changes are announced on this page (and in the app where feasible) before they take effect.
HashCore AI — independent software business, United Kingdom.
Email: contact@hashcoreai.com