Back to home

Privacy Policy

How Voraq collects, processes and protects your personal data — GDPR and CCPA compliant.

Last updated: 2026-06-23

1. Data controller

Voraq ("we", "us") is the data controller responsible for personal data processed via the voraq.app web app. For any question relating to this policy or to exercise your rights, contact us at contact@voraq.app. The legal entity operating Voraq is registered in Estonia.

2. Personal data we collect

We collect the minimum data needed to operate the service:
  • Wallet address — the lowercased EVM address you sign in with (it serves as your account identifier).
  • Sign-in & anti-fraud metadata — IP address, user-agent and timestamp of each SIWE sign-in attempt, a proxy/VPN/datacenter risk assessment of your IP, and a device fingerprint (a non-reversible identifier derived from your browser/device) used to limit multiple accounts per device. Purpose: keep bot traffic off our partners' offers. Legal basis: our legitimate interest in fraud prevention.
  • Earnings & claims — completion records (offerwall provider, transaction id, payout, type, timestamp), USDT/$ADS balances, on-chain claim transactions.
  • Postback logs — raw payloads received from offerwall providers, with the source IP and user-agent.
  • Cookies — strictly necessary session cookie (NextAuth), SIWE nonce cookie, and a locale preference cookie. No analytics or advertising cookies.

3. Why we process this data (legal basis)

  • Contract performance — to credit your rewards, process USDT claims, and operate the service.
  • Legitimate interests — anti-fraud (rate limiting, velocity checks, Sybil-cluster detection, IP allowlists), security audits and platform integrity.
  • Legal obligations — compliance with applicable AML/KYC regulations where required by local law.
  • Consent — recorded at sign-in (timestamp stored as acceptedTermsAt).

4. Third-party data processors

We share the minimum data necessary with these processors:
  • Cloudflare (United States) — captcha verification on sign-in (Turnstile).
  • IP reputation provider (e.g. proxycheck.io) — when enabled, your IP address is checked to detect VPN/proxy/datacenter connections for fraud prevention. No other personal data is sent.
  • Blockchain RPC providers (e.g. Alchemy) — used to broadcast your USDT claim transactions on Polygon.
  • Polygon network — your claim transactions are public on the Polygon blockchain and cannot be deleted.
  • Offerwall providers — survey and rewarded-video delivery. We send them only your internal user id (a random identifier, unlinked to any personal information) and receive completion callbacks. The list of currently-active offerwall partners will be published here as soon as integrations are signed; until then, no offerwall provider receives any data from Voraq users.
For transfers outside the EU/EEA, we rely on Standard Contractual Clauses or equivalent safeguards.

5. Data retention

Account, earnings and claim records are kept for as long as your account is active and for up to 5 years after closure for tax and accounting obligations. Postback logs are kept for 12 months for anti-fraud audit. Anonymised aggregates may be kept indefinitely. Blockchain transactions are immutable and cannot be removed.

6. Your rights under GDPR

If you are in the EU/EEA, you have the right to:
  • access the personal data we hold about you;
  • request rectification of inaccurate data;
  • request erasure ("right to be forgotten"), subject to legal retention obligations;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request data portability (machine-readable export);
  • withdraw consent at any time (this does not affect prior lawful processing);
  • lodge a complaint with your local supervisory authority.
To exercise any of these rights, email contact@voraq.app. We respond within one month.

7. California residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to opt out of any "sale" of personal information. We do not sell your personal information. To exercise these rights, email contact@voraq.app.

8. Cookies

We use only strictly necessary cookies — no analytics, no advertising, no tracking pixels. The cookies set by Voraq are:
  • next-auth.session-token — your authenticated session (JWT).
  • siwe-nonce — single-use nonce for the wallet sign-in challenge (10 min lifetime).
  • we-locale — your language preference.
Cloudflare Turnstile may set short-lived cookies in your browser solely for captcha verification.

9. Security

We use industry-standard protections: HTTPS, hashed/encrypted secrets, timing-safe signature comparisons, server-side rate limiting, IP allowlists for provider callbacks, captcha on sign-in, and a 14-day maturity window on USDT credits to absorb provider chargebacks. Your private wallet key never leaves your wallet — we never see it.

10. Children

Voraq is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the service evolves. The "Last updated" date at the top reflects the most recent change. Material changes are announced in the app, and we may ask you to re-accept the updated policy at your next sign-in.

12. Contact

All privacy questions and requests: contact@voraq.app. We aim to respond within 72 hours.