The data controller responsible for the processing of your personal data under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), Turkish Personal Data Protection Law (KVKK, Law No. 6698), California Consumer Privacy Act (CCPA/CPRA), and other applicable international privacy statutes is:
- Controller Identity: Metic Apps — operated by sole proprietor Mert Verdi
- Registered Address: Izmir, Republic of Turkey
- Official Contact Email: metic.apps@gmail.com
- Promotional Website:
https://mining-rewards.vercel.app/
We adhere to strict data minimization principles. We collect only data strictly necessary to operate our simulation gameplay, prevent ad fraud, and securely deliver promotional rewards:
- Identifiers: Email address, player username, user identifier (UUID), avatar image URL, selected frame rarity, and title.
- Password Hashes: We never store or receive your plain text password. Passwords are salted and hashed using industry-standard cryptographic algorithms (Bcrypt with cost factor 10 / Argon2) inside Supabase Auth.
- Connection Telemetry: Connection IP address (
last_ip), country code derived from IP (ip_country, ISO 3166-1), session timestamps, and timezone. - Anti-Abuse Flags: VPN/proxy detection status (
is_vpn), VPN violation counter (vpn_strike_count), calculated fraud score (fraud_score), and server-side risk assessment cache (ip_risk_cachevia proxycheck.io). - Device Integrity: Device attestation token and integrity verification status (
device_fingerprint) via the Google Play Integrity API and safe_device root detection. - Two-Factor Authentication: For email 2FA challenges (
public.mfa_email_challenges), one-time 6-digit codes are stored exclusively as SHA-256 cryptographic hashes with a 10-minute expiry window. - Rate Limiting: Anonymous lookup requests (
anon_lookup_throttle) are tracked in 1-hour windows to prevent brute-force abuse.
- Gameplay Activity: Total lifetime mined simulation coins (MRC), active mining rig tier, device level, components inventory, drop history, and leaderboard ranking snapshots.
- Public Leaderboard & Showcase Display: By choosing a player gamertag/username and participating in the simulation, your pseudonymous username, ranking position, and mined simulation score may be displayed publicly on in-app leaderboards and on our official promotional web landing showcase. We never disclose your email address, real name, IP address, or device attestation identifiers. Players may request anonymous leaderboard display at any time by contacting support.
- Google Play Billing Records: Order ID, purchase token, purchase timestamp, and coin package credits (
coin_purchase_log). If a chargeback or refund occurs, any unbacked spent balance is tracked incoin_debt. We do not receive or store payment card numbers; all billing is executed by Google Play.
- Reward Request Data: Reward item ID, MRC cost, claim timestamp, status (
pending,approved,delivered,rejected), recipient email (delivery_info), and declared country of usage (usage_country).
We process personal information exclusively for the following operational purposes:
- To register, authenticate, maintain, and recover your player account.
- To calculate deterministic mining yields, hashrates, level upgrades, and streak milestones.
- To verify ad watches, enforce daily quotas, and credit rewarded simulation boosts via AdMob Server-Side Verification (SSV).
- To audit, fulfill, and deliver digital gift card reward codes to your verified email.
- To safeguard the integrity of the game economy by detecting emulators, auto-clickers, VPN bypasses, ad fraud, and multiple accounts.
- To resolve consumer support inquiries, data subject rights (DSR) requests, and bug reports.
Under GDPR Article 6(1) and KVKK Article 5, our lawful grounds for processing personal data are:
- Performance of a Contract (GDPR Art. 6(1)(b) / KVKK Md. 5(2)(c)): Providing the simulation game, managing player accounts, executing in-game progression, and delivering redeemed gift cards pursuant to our Terms of Use.
- Legitimate Interests (GDPR Art. 6(1)(f) / KVKK Md. 5(2)(f)): Protecting our platform from bot attacks, ad fraud, and financial abuse; auditing server-side nonces; enforcing anti-cheat rules; and ensuring server stability.
- Compliance with Legal Obligations (GDPR Art. 6(1)(c) / KVKK Md. 5(2)(ç)): Complying with statutory accounting records, tax obligations, and responding to judicial orders.
- Explicit Consent (GDPR Art. 6(1)(a) / KVKK Md. 5(1)): Where required for personalized advertising mediated through Google's User Messaging Platform (UMP), and push notification permissions.
We do not sell, rent, or trade your personal data. We disclose personal data only to vetted third-party data processors acting under binding data processing agreements:
- Supabase Inc. / AWS (Frankfurt, Germany): Backend PostgreSQL database, authentication, storage, and serverless edge functions. Operating inside the European Union (eu-central-1).
- Google LLC (USA): Google Play Billing, Google AdMob (advertising), Firebase Cloud Messaging, Firebase Crashlytics, and Google Play Integrity API. Certified under the EU-U.S. Data Privacy Framework (DPF).
- Unity Technologies (USA): In-app video advertising mediation via Google AdMob.
- Pangle / ByteDance Pte. Ltd. (Singapore / China): Rewarded video advertising mediation via Google AdMob.
- proxycheck.io (United Kingdom): Real-time IP address reputation, proxy, and VPN fraud scoring.
For the complete, dynamic catalog of processors, review our dedicated Subprocessors Directory.
Your primary database and user profile records are hosted in Frankfurt, Germany (European Union) on Supabase infrastructure. Because we operate globally, certain telemetry or advertising data may be transferred to service providers in the United States, Singapore, or the United Kingdom.
Safeguards under GDPR (Chapter V): Transfers to the United States rely upon the EU-U.S. Data Privacy Framework (DPF) adequacy decision or the European Commission's approved Standard Contractual Clauses (SCCs).
Safeguards under Turkish KVKK (Article 9): In accordance with the Regulation on the Transfer of Personal Data Abroad published in the Official Gazette on July 10, 2024 (No. 32598), cross-border transfers to Supabase, Google, Unity, and Pangle are governed by standard contractual clauses executed with each processor and notified to the Personal Data Protection Authority (KVKK) within five (5) business days where mandated.
We reject conditional consent ("tied consent") as a transfer basis under GDPR Article 7(4). All transfers are grounded in statutory adequacy decisions, contractual necessity, or approved SCCs.
We maintain automated database purge routines (pg_cron jobs) to ensure data is destroyed immediately upon expiration of its lawful retention purpose:
| Data Category | Retention Period (TTL) | Enforcement Mechanism |
|---|---|---|
| Account & Profile Data | Duration of active account + 30 days grace | Job 51 (purge_scheduled_account_deletions) |
| Reward Delivery Email (delivery_info) | 1 Year after delivery, then anonymized | Job 50 (nightly_cleanup sets to NULL) |
| Ad Watch & SSV Audit Logs | 30 Days rolling retention | Job 50 (nightly_cleanup hard delete) |
| GDPR JSON Data Export Archives | 7 Days after generation | Job 52 (clean_expired_exports) |
| Anonymous IP Rate Limits | 1 Hour rolling window | Job 50 (nightly_cleanup) |
| Admin Security & Audit Log | 2 Years for legal defense | Immutable audit logging |
Upon permanent deletion, game balance and mining telemetry are detached from all personal identifiers and retained strictly as aggregated, non-re-identifiable system statistics.
Depending on your jurisdiction, you have statutory rights concerning your personal data:
- Right to Access & Portability: Request a copy of your personal data in a structured, machine-readable JSON format via our in-app Data Export feature (Profile → Security → Export My Data).
- Right to Rectification: Correct inaccurate or incomplete profile data directly inside the App or by contacting us.
- Right to Erasure ("Right to be Forgotten"): Request full account and data deletion via Profile → Delete Account or via our Account Deletion Walkthrough.
- Right to Restriction & Objection: Object to processing grounded in legitimate interests or request temporary restriction of processing.
- Right to Withdraw Consent: Revoke advertising tracking consent at any time through the in-app Privacy Settings (UMP dialogue) without affecting earlier lawful processing.
Response Timelines: We respond to Data Subject Requests (DSR) within 30 calendar days (GDPR/KVKK), 15 business days (Brazil LGPD), or 45 calendar days (CCPA). Submit requests directly to metic.apps@gmail.com or through our Help & Support Portal.
This section applies to residents of California and other U.S. states with comprehensive privacy laws:
- Statutory Threshold Notice: Metic Apps is a micro-business operating below the statutory gross annual revenue threshold ($25 million) specified under California Civil Code § 1798.140(d). Nonetheless, we voluntarily extend baseline CCPA rights to all users.
- We Do Not Sell or Share Personal Information: We do not sell your personal information to third parties for monetary compensation, nor do we share your personal data for cross-context behavioral advertising outside user-controlled consent choices.
- Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of gameplay because you exercised your statutory privacy rights.
We do not subject users to decisions based solely on automated processing or machine-learning profiling that produce legal effects or significantly affect you. Our anti-fraud algorithms (such as VPN strike counting and fraud scoring) flag suspicious accounts for human operator review before permanent account revocation or reward disqualification takes place. You have the right to request human intervention and contest any enforcement decision via metic.apps@gmail.com.
We maintain comprehensive technical and organizational safeguards:
- Transport Encryption: All client-to-server and server-to-server communications utilize TLS 1.3 / SSL encryption with strict cipher suites.
- Row-Level Security (RLS): Every table in our PostgreSQL database enforces Row-Level Security policies; users can only read or write their own authorized records.
- Anti-Cheat Shielding: Sensitive user profile balances (MRC, XP, Level) are locked behind server-side PostgreSQL triggers (
enforce_user_profile_anticheat); direct client updates are blocked. - Credential Protection: Passwords and 2FA challenges are never stored in plaintext and rely on irreversible salted hashing.
Promotional Website: Our informational website (mining-rewards.vercel.app) operates on a Zero-Cookie & Zero-Tracker architecture. We do not place tracking, analytics, or advertising cookies on web visitors. All web fonts are self-hosted locally on our servers, ensuring no IP leakage to external CDNs (in compliance with the Munich Regional Court LG München I ruling).
Mobile Application: The App does not use HTTP cookies. It uses native local storage (SharedPreferences / Flutter Secure Storage) solely for session token caching and offline state. Advertising SDKs utilize Google Advertising ID (GAID) strictly subject to your UMP consent preferences. For details, see our Cookie Policy.
The Service may contain links to external websites, app stores, or dispute resolution portals. We do not control and are not responsible for the privacy practices, content, or policies of third-party websites. We encourage you to review their policies upon visiting.
We deliver in-app notifications and background push notifications via Firebase Cloud Messaging (FCM). Notifications follow deterministic schedules (e.g., daily streak reminders at 10:00 and 20:00 local time) and cover operational updates, reward fulfillment notices, and streak warnings. You may toggle individual notification channels or disable push notifications entirely at any time in your Android device settings or within the App settings.
In the event of a physical or technical security incident affecting your personal data, we will assess the risk to your rights. Where required by GDPR Articles 33 and 34 or KVKK Article 12, we will notify the competent supervisory authorities within 72 hours of becoming aware of the breach, and inform affected users without undue delay via in-app banners and/or registered email addresses.
We maintain an updated inventory of third-party processors on our Subprocessors Page. When we engage a new subprocessor or materially modify existing arrangements, we will publish the change at least thirty (30) calendar days in advance and announce it through an in-app notice, providing users an opportunity to object or terminate their accounts before processing begins.
Metic Apps is an individual enterprise established in Turkey. We actively monitor legislative initiatives, including the European Commission's Digital Omnibus proposal (COM(2025) 837) regarding simplified representative requirements for micro-enterprises. European Union and United Kingdom residents may contact the data controller directly at metic.apps@gmail.com for all inquiries, which will be handled in full accordance with GDPR and UK GDPR procedural standards.
Mining Rewards is designed for general audiences aged 16 and older. We do not knowingly solicit or collect personal information from children under the applicable age of digital consent:
| Jurisdiction | Minimum Consent Age | Statutory Legal Basis |
|---|---|---|
| European Union / EEA | 16 Years Old | GDPR Art. 8(1) default standard |
| United States (Federal) | 13 Years Old | COPPA (15 U.S.C. § 6501; 16 CFR Part 312) |
| United Kingdom | 13 Years Old | UK GDPR / DPA 2018 / ICO Children's Code |
| Republic of Turkey | 18 Years Old* | Turkish Civil Code (TMK Md. 11) / KVKK (*16-17 with parental consent) |
| Brazil | 18 Years Old | LGPD (Lei 13.709/2018) Art. 14 / ANPD Enunciado 1/2023 |
| India | 18 Years Old | DPDPA 2023 Section 9 & DPDP Rules 2025 |
| People's Republic of China | 14 Years Old | PIPL Article 31 (Minor Protection Standard) |
| Republic of Korea | 14 Years Old | PIPA Article 22-2 (Legal Representative Consent) |
If we discover that a user under the applicable minimum age has registered without verifiable parental authorization, we will terminate the account and purge all associated personal data immediately.
We may amend this Privacy Policy periodically. When revisions occur, we will update the "Last Updated" date and version string (kLegalVersion = '2026-09-01'). Material changes will be accompanied by an in-app consent notification requiring explicit acknowledgement before gameplay resumes.
Supervisory Authority Complaints: If you believe our data processing infringes applicable data protection law, you have the statutory right to lodge a complaint with your competent supervisory authority (in Turkey: Kişisel Verileri Koruma Kurumu — kvkk.gov.tr; in the EU: your national Data Protection Authority; in the UK: the Information Commissioner's Office — ico.org.uk).
For all inquiries, DSR requests, or privacy concerns, contact:
- Controller: Metic Apps — Mert Verdi
- Email: metic.apps@gmail.com
- Address: Izmir, Republic of Turkey