The entity responsible for your personal information is:
This Privacy Policy applies to all users worldwide and is written to address GDPR (EU), KVKK (Turkey), CCPA/CPRA (California), LGPD (Brazil), and COPPA (US) requirements.
2.1 — Information You Provide
- Email address — for authentication and account recovery
- Username — for profile identification
- Password — stored only as a cryptographic hash; we never see your plain-text password
- Profile photo / avatar — optional, only if you choose to upload one
- Referral code — optional, only if you were invited by another user
2.2 — Collected Automatically
- IP address — for security, fraud prevention, and session management
- Device type and user-agent string — browser and operating system information
- Timezone — for accurate time display and mining calculations
- Login timestamps and session data
- Last activity timestamps
2.3 — In-Game Activity Data
- MRC (Mining Rewards Coin) balance and activity history
- Mining activity records — hashrate, daily earnings, mining blocks
- In-game shop activity history — items purchased, quantities, costs
- In-app purchase records — coin packages acquired through Google Play
- Reward redemption requests — digital gift card requests, delivery information, and the country/region where you intend to use the reward
- Advertising interaction data — ad watch counts, boost usage
2.4 — Data Collected by Third-Party SDKs
| Service | Purpose | Data Collected |
|---|---|---|
| Google AdMob | Advertising | Advertising IDs (GAID/IDFA), device info, IP, ad interactions |
| Google Sign-In | Authentication | Email and basic profile (only if you choose Google Sign-In) |
| Supabase | Backend / Database | All user data listed above, processed as our data processor |
| Google Play Billing | In-App Purchases | Order ID, product ID, purchase time only — no payment details |
| Firebase Cloud Messaging | Push Notifications | Anonymous device registration token (FCM token), delivery metadata, basic diagnostics |
| Firebase Crashlytics | Crash & Stability Reporting | Crash stack traces, exception type, device model / OS version, app version, crash timestamp (release builds only) |
| Unity Ads (Unity Technologies) | Advertising Mediation | Advertising IDs (GAID), device info, IP, ad interactions — served via Google AdMob mediation |
| Google Play Install Referrer | Referral Attribution | Install referrer string read once at first launch, used only to credit the user who invited you |
| Firebase Analytics (Google LLC) | Usage Analytics | App usage events (app opens, screen views, sessions) and a few custom events (e.g. rewarded-ad completion), app-instance ID, device model / OS version, app version, coarse location from IP (release builds only) |
2.5 — Two-Factor Authentication (2FA) Data
- 2FA enrollment status and chosen method — e.g. whether email-based 2FA is enabled
- Email one-time codes — stored only as a cryptographic hash, with a short expiry; challenge records are invalidated within minutes and not retained long-term
- Authenticator app (TOTP), where enabled — the secret needed to verify your codes and any recovery codes, stored only as cryptographic hashes
- Processed solely to verify your identity at sign-in and to secure your account (GDPR Art. 6(1)(b) and Art. 6(1)(f))
- Account management — create and manage your account, verify identity, provide access
- App features — operate the mining simulation, process in-game activities and purchases, fulfill reward redemptions
- Ad display — display advertisements via Google AdMob and its mediation partners (e.g. Unity Ads); in the EU/EEA, only after obtaining your explicit consent
- Security & fraud prevention — protect accounts, detect fraudulent activity, prevent abuse
- Analytics & improvement — analyze usage patterns via Firebase Analytics (aggregate, release builds only), maintain system statistics, improve the App
- Stability & crash diagnostics — detect, report, and fix application crashes via Firebase Crashlytics (release builds only)
- Account security — verify your identity at sign-in via optional two-factor authentication (email codes or authenticator app)
- Communication — send important service-related notifications and updates
- Legal compliance — comply with applicable laws, regulations, and legal processes
| Purpose | Legal Basis | GDPR Article |
|---|---|---|
| Account creation & authentication | Performance of a contract | Art. 6(1)(b) |
| App features (mining, shop, rewards) | Performance of a contract | Art. 6(1)(b) |
| Displaying personalized advertisements | Consent | Art. 6(1)(a) |
| Security & fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Analytics & service improvement | Legitimate interest | Art. 6(1)(f) |
| Stability & crash diagnostics | Legitimate interest | Art. 6(1)(f) |
| Account security & two-factor authentication | Contract / Legitimate interest | Art. 6(1)(b) / (f) |
| Legal compliance | Legal obligation | Art. 6(1)(c) |
We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. This applies to all users globally, including California residents under CCPA/CPRA.
Service Providers (Data Processors)
- Supabase Inc. — database hosting, authentication, and backend services
- Google LLC (AdMob) — advertising display and ad-related analytics
- Google LLC (Sign-In) — authentication services (only if you use Google Sign-In)
- Google LLC (Play Billing) — in-app purchase processing (only if you purchase coin packages)
- Google LLC (Firebase Cloud Messaging) — push notification delivery
- Google LLC (Firebase Crashlytics) — crash and stability diagnostics (release builds only)
- Google LLC (Firebase Analytics) — aggregate usage analytics for product improvement (release builds only)
- Unity Technologies (Unity Ads) — advertising mediation (serving and measuring ads)
- proxycheck.io — server-side VPN/proxy detection and risk scoring from your IP address, used solely for security and abuse prevention (not for advertising)
Legal Requirements
We may disclose your information if required by law, court order, or valid legal process — including government agency requests, or to protect our legal rights and defend against claims.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the successor entity. We will notify you of any such change through the App.
Your data is stored on servers operated by Supabase, Inc., located in Frankfurt, Germany (eu-central-1 region), European Union. As an EU-based infrastructure, Supabase maintains GDPR-compliant data processing practices.
Google LLC (for AdMob, Sign-In, Firebase Cloud Messaging, Firebase Crashlytics, and Firebase Analytics services) may process certain data in the United States. Google participates in the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses (SCCs) to ensure lawful transfers.
Unity Technologies (Unity Ads mediation) may process advertising identifiers, device, and ad-interaction data in the United States and other countries, relying on Standard Contractual Clauses (SCCs).
proxycheck.io may process the IP address you connect from to return a VPN/proxy risk assessment. proxycheck.io acts as our data processor for security purposes only and relies on appropriate safeguards (such as Standard Contractual Clauses or an adequacy decision) for any international transfer.
We ensure appropriate safeguards through:
- Supabase's GDPR-compliant Data Processing Agreement (DPA)
- Standard Contractual Clauses (SCCs) where applicable
- EU-U.S. Data Privacy Framework (for Google services)
- Adequacy decisions by applicable data protection authorities
By using the App, you acknowledge and consent to the transfer of your data to these jurisdictions.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information (email, username, avatar) | 30 days after account deletion | Account recovery window |
| Session data (IP, device info, user agent) | 90 days | Security and fraud detection |
| Mining and earning history | Anonymized upon account deletion | System analytics and integrity (GDPR Recital 26) |
| Advertising statistics | 12 months | Analytics and reporting |
| Reward redemption records | 3 years | Regulatory compliance and dispute resolution |
| Email change request logs | 90 days | Security audit trail |
When retention periods expire, data is either securely deleted or irreversibly anonymized. Anonymized data cannot be traced back to you and falls outside data protection regulations (GDPR Recital 26, KVKK, CCPA, LGPD).
Depending on your location, you have the following rights regarding your personal data:
- Access your personal data
- Correct inaccurate or incomplete data
- Delete your account (Profile → Delete Account)
- Withdraw consent for data processing at any time
- Receive information about how your data is processed
- Data portability (machine-readable format)
- Restrict processing of your data
- Object to processing based on legitimate interests
- Lodge a complaint with your local Data Protection Authority
- Not be subject to automated decision-making
- Learn whether personal data is being processed
- Request information about processing activities
- Know the purpose of processing and compliance
- Know domestic or foreign third parties data is transferred to
- Request correction of incomplete or inaccurate data
- Request deletion or destruction of personal data
- Claim compensation for damages due to unlawful processing
- Know what personal information is collected, used, and shared
- Delete personal information
- Opt-out of the sale or sharing of personal information
- Limit use of sensitive personal information
- Non-discrimination for exercising your privacy rights
Brazil (LGPD) residents also have rights to confirmation, access, correction, anonymization, blocking, deletion, portability, and revocation of consent. To exercise any right, contact us at metic.apps@gmail.com.
RESPONSE TIMELINES BY JURISDICTION
- European Economic Area (GDPR) — within 30 calendar days (extendable to 60 for complex requests)
- Turkey (KVKK) — within 30 calendar days
- California, USA (CCPA/CPRA) — within 45 calendar days
- Brazil (LGPD) — within 15 business days
- All other jurisdictions — within 30 calendar days
- Password hashing — passwords are cryptographically hashed using industry-standard algorithms (bcrypt via PostgreSQL pgcrypto); never stored in plain text
- TLS/SSL encryption — all data transmission is encrypted in transit
- Row Level Security (RLS) — enabled on all database tables; each user can only access their own data
- Leaked password protection — powered by HaveIBeenPwned, prevents use of compromised passwords
- Access restriction — access to personal data is restricted on a need-to-know basis
- Session management — authentication sessions have configurable timeouts
While we take reasonable precautions, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
The App is intended for users aged 16 and older. We do not knowingly collect personal information from anyone under the age of 16, and we do not direct the App or its content toward children.
If we discover that we have collected personal information from a child under 16, we will promptly delete such information and terminate the associated account.
For United States users: We comply with the Children's Online Privacy Protection Act (COPPA). Our App is not directed at children under 13. If you are a parent or guardian and believe your child under 16 has provided us with personal information, please contact us immediately at metic.apps@gmail.com.
We use Google AdMob to display advertisements within the App, including ads served through mediation partners such as Unity Ads (Unity Technologies). Google AdMob and its mediation partners may use device advertising identifiers and other technologies to serve relevant ads.
Opt-Out Options
- Android: Settings → Privacy → Ads → Opt out of Ads Personalization
- You can also reset your advertising identifier through your device settings
Your Choices
We do not sell or share your personal information for cross-context behavioral advertising. If you are in the EU/EEA, we will request your explicit consent before showing personalized ads. You may withdraw this consent at any time through your device settings.
For questions, concerns, or data rights requests regarding this Privacy Policy:
Regulatory Authorities