Privacy policy
Last updated: 2026-08-04
This policy explains what personal data we process when you use Hustly, why we process it, what we base it on and how long we keep it. It is written to match what the system actually does.
Controller
company name, address, Germany.
Contact: support@gethustly.app
Data protection officer: name and contact, or state that none is required
What we process
Account. Your email address, the market you are in, your language and the status of your account. In markets where a mobile number is the identity anchor, we also store that number and the time it was verified.
Answers you give during sign-up. Gender, age band, how often you play mobile games, whether you buy inside games and roughly how much, your earning goal and how much time you have. Every one of these is optional and can be skipped. Each question states on screen what it is used for — mostly matching you with surveys you can actually qualify for, and sorting offers you are likely to finish.
What you do. Offers you open, rewards that are reported back for you, every movement of your balance and every payout you request. This is the record that answers “where is my money”, so it has to be complete.
Your payout target. Depending on the method you choose, a PayPal email address, or an IBAN together with the account holder’s name, or a mobile number.
Consents. Which terms you accepted and when, and whether you allowed marketing messages. Withdrawals are recorded the same way, as a new entry — we never overwrite the old one.
Device tokens. If you allow notifications, the push token of that device, so a message can reach it.
Support requests. What you write to us and what we answer.
IP addresses
We never store IP addresses in clear text. Where we need to recognise that several accounts came from the same connection — a fraud signal — we store a keyed hash instead. The key is held outside the database, so a database leak does not turn back into a list of addresses.
Why, and on what basis
- To run your account and pay out your rewards — Art. 6 (1) (b) GDPR, performance of a contract. Without this data there is no account and no payout.
- To send you marketing messages — Art. 6 (1) (a) GDPR, consent. You give it separately and can withdraw it at any time; messages about your own rewards and payouts are not marketing and continue either way.
- To prevent fraud and abuse — Art. 6 (1) (f) GDPR, legitimate interest. Rewards are paid from partner budgets; without these checks the offers would disappear for everyone.
- To meet legal obligations — Art. 6 (1) (c) GDPR, in particular records of payments we have made.
Automated checks
Payouts below a threshold are approved automatically; everything above it, and every first payout, is looked at by a person. Certain signals — a very new account, several accounts sharing a payout target, an unusually large amount — put a request into manual review rather than rejecting it. You can always ask us to explain a decision and to have it reviewed by a person.
Who else sees the data
We use service providers who process data on our behalf, under contract and on our instructions only:
- Supabase — database, sign-in and server functions.
- Vercel — hosting of this website.
- Expo — delivery of push notifications, if you allowed them.
- Payout providers — they receive what is needed to make the transfer, and nothing else.
- Offer and cashback partners — when you open an offer, the partner receives an identifier for that click so your reward can be assigned to you. They do not receive your email address.
Where a provider processes data outside the EU, that transfer is covered by the European Commission’s standard contractual clauses. confirm per provider
How long we keep it
- Account data: as long as your account exists.
- Balance movements and payouts: for as long as commercial and tax law require us to keep records, even after an account is closed. These entries are never edited or deleted — corrections are booked as counter-entries.
- Raw logs of partner callbacks: kept briefly for troubleshooting, then pruned automatically.
Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to receive it in a portable form (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you can withdraw it at any time with effect for the future.
To exercise any of these, write to support@gethustly.app. There is currently no delete button inside the app; a request by email has the same effect and we will confirm it. Where we have to keep individual records for legal reasons, we separate them from your identity instead of keeping them attached to you.
You also have the right to complain to a supervisory authority, for example the one responsible for federal state of the company’s seat.
Cookies
This website sets one kind of cookie: the one that keeps you signed in. It is technically necessary and needs no consent. We use no analytics, no advertising pixels and no third-party trackers. If that ever changes, this section changes with it and you will be asked first.
Changes
If we change how we process data, we update this page and the date at the top. Where the change affects you materially, we tell you directly rather than relying on you checking.
- Every entry marked in orange is a placeholder and has to be filled in before this page goes live.