Privacy Policy
The shortest honest version: we keep an email address and a record of what your money did. We do not collect identity documents and we do not sell anything about you.
Last updated September 14, 2026
01
What we never collect
In shortNo ID, no selfie, no address, no tax number, no bank statements.
We do not run identity verification, so there is nothing to collect. We do not ask for or store government ID, biometric data, proof-of-address documents, national insurance or social security numbers, employment details or income information. We do not buy data about you from brokers and we do not track you across other websites.
02
What we do collect
In shortYour email, your transactions, and enough device data to keep the account safe.
- Email address and password hash, or the Google account you chose to sign in with
- Two-factor authentication secrets and hashed backup codes, if you enable them
- Balance, deposits, card loads, card transactions and payouts
- For a bank payout: the account holder name, postal address and bank details you enter, because the receiving bank requires them
- Card data as issued by the card partner; full card numbers are shown to you on request and are never stored in our own database
- Your IP address, browser and device type. Like every website, our servers and the third-party services we use see the IP address of whoever connects to them; that is how the internet works and no website can promise otherwise. We use it for security and to show you your active sessions.
- Messages you send to support
03
Why we use it
In shortTo run the service, keep it secure, and meet the obligations we cannot opt out of.
We use your data to operate your account, process deposits, cards and payouts, detect fraud and abuse, answer support requests and send service emails such as a login from a new device or a completed payout. We do not send marketing email unless you opt in, and we do not profile you for advertising.
Where a card partner or payment institution is legally required to keep transaction records, we share the minimum they need to do so.
06
How it is protected
In shortEncrypted in transit and at rest, with rate limits and monitoring.
All traffic is encrypted with TLS. Sensitive values such as two-factor secrets and backup codes are encrypted or hashed before storage. Full card numbers never touch our database. Access to production systems is limited to the people who operate the service, and abusive or automated traffic is rate-limited.
07
How long we keep it
In shortAccount data while you are with us, transaction records for seven years.
- Email, name and login data: for as long as your account is open, then removed on deletion
- Deposits, card transactions, payouts and the payout bank details: seven years, because our partners must keep them under financial record-keeping rules
- Support conversations and security logs: kept while the account is open and reviewed for deletion afterwards
08
Your rights
In shortSee it, fix it, take it, delete it.
You can ask for a copy of the data we hold about you, correct anything that is wrong, receive it in a portable format, or delete your account. Deletion removes your login, email and name straight away; the transaction records above are kept for the legal period under an internal account ID rather than your email. Terminate your cards and move any balance out before you delete, as the balance cannot be recovered afterwards.
Account deletion is in settings. For anything else, write to us and we answer within 30 days.
09
Changes to this policy
In shortWe tell you before anything material changes.
If we change what we collect or who we share it with, we announce it by email or in the dashboard before the change applies. Minor wording changes are published here with a new date.
10
Talk to a person
Privacy requests and questions go to this address or to support in the dashboard.