EarnHub Privacy Policy
This Policy will be published at https://earnhub.space/legal/privacy and referenced from the EarnHub Android app and its Google Play listing. It is one document for all three audiences of the Platform: Clients, Agents, and website visitors.
Amended 2026-08-25 on two points where the text had gone out of date or was silent. (a) The mail processor changed. Until 2026-08-24 all Platform email left through a single Google account; since that date it is sent through Resend (Plus Five Five, Inc., United States) over its HTTP API, with one sender address per audience. Sections 10, 11 and 12 are corrected accordingly; the superseded Gmail line is kept, struck through, in the Section 10 table because it explains the historical mail archive. (b) The company-verification (KYB) correspondence with third parties is now stated as its own disclosure, in a new Section 9.8 — we write to a person at an outside company, name our Client to them, and keep their reply. The former Section 9.8 ("What we do not do") is renumbered 9.9.
1. Who we are
1.1. The EarnHub platform is operated by [ENTITY LEGAL NAME], a company incorporated in the RAK Digital Assets Oasis free zone, Ras Al Khaimah, United Arab Emirates ("EarnHub", "we", "us", "our").
1.2. For the purposes of United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), we are the controller of the personal data described in this Policy, except where Section 4.3 says otherwise (data uploaded by Clients, for which the Client is the controller and we act as processor).
1.3. We are a small company. All privacy requests are handled by our team through a single support mailbox: [SUPPORT EMAIL] (Section 18). We do not currently have a dedicated Data Protection Officer.
2. Definitions
- "Agent" — a natural person who uses the EarnHub Android app to perform paid Tasks.
- "Client" — a company (and the natural persons acting for it) that uses the web Portal at
earnhub.spaceto create Tasks and receive results. - "Task" — a paid micro-job on the Platform: either an SMS Test or a generic task (for example, collecting photos or data, or processing data supplied by a Client).
- "SMS Test" — a Task in which an Agent receives a real SMS message (typically a one-time code) on their own SIM card so that a Client can measure SMS deliverability.
- "ERN" — the Platform's internal credit unit, with a displayed exchange rate to USDT.
- "Platform" — the EarnHub services collectively: the Client Portal (
earnhub.space), the Android app for Agents, the public websites onearnhub.appandearnhub.io, and the supporting backend services. - "PDPL" — UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
- "Sensitive Personal Data" — data given special protection by the PDPL, including biometric data, health data, and data revealing religious beliefs or political views.
- "Verification" — the identity (KYC) and company (KYB) checks described in Sections 3.2 and 4.2.
3. Personal data we process about Agents
We collect the following categories of personal data from and about Agents. We collect what is listed here and nothing beyond it; where a category is optional, we say so.
3.1. Account and profile data
- Account identity: email address, username, password (stored only as a salted hash), interface language, app version, account settings; if you sign in with Google, the Google account identifier Google provides to us.
- Profile and targeting attributes you choose to provide in the verification questionnaire, used to match you with Tasks: gender, age, region, education, employment, marital status, height, weight, clothing size, spoken languages, timezone, device model, and — entirely optional — religion and political views. You may leave any optional field blank. The Platform also derives some attributes itself: your country, your mobile operator, and your activity and earnings statistics. See Section 7 on sensitive data and Section 9.3 on how Clients see these attributes.
- Two-factor authentication data: if you enable 2FA, the TOTP seed for your authenticator app.
3.2. Identity verification (KYC) data — including biometric data
If you apply for a Verification level, we process, depending on the checks that level requires:
- Identity documents: photographs of the front and back of your ID document, and a proof of address document; the text we extract from them (name, document number, address), which we store encrypted.
- Liveness video: a short video of your face recorded during the guided liveness check.
- Face embeddings: a numerical template derived from your face image, which we use to verify that your ID matches you and to detect duplicate accounts (your template is compared against other Agents' templates for this purpose). Face embeddings and liveness video are biometric data and are Sensitive Personal Data under the PDPL. See Section 7.
- Phone verification data: your phone number, and — depending on the method — an automated verification call, or your Telegram account identifier if you verify by sharing your contact through Telegram.
3.3. Phone, SIM and device data
To run SMS Tests we need to know which SIM cards and operators you use. The app sends us, for each SIM you register: phone number, operator and carrier name, carrier identifiers (MCC/MNC), SIM and network country, SIM slot and subscription identifiers, and roaming status. We also process your device model, app version and language.
3.4. SMS messages read during SMS Tests
When you take an SMS Test, the app — using the Android SMS permission you grant — reads the most recent messages received on your phone after the moment the test started (up to about ten messages), and shows them to you on your device so you can pick out the test message. That on-device list is filtered by time and — on most phones — by the SIM you connected, not by sender: on some phones the list can also include messages arriving on your other SIM, and a personal message that happens to arrive during a test can appear in it; the list itself is never sent to us. Only the message you select — its text, sender identifier and timestamp — is transmitted to us and stored as part of the SMS Test record, and made available to the Client that commissioned the test (Section 9.4). Test messages are typically one-time codes sent by the service under test.
3.5. Task submissions, location and media metadata (GPS/EXIF)
Some Tasks require photos, videos, audio or answers collected or produced by you. We process the content you submit for a Task, and for media files we extract and store their technical metadata (EXIF), including GPS coordinates and capture time, which we use to verify the submission is genuine. Media you submit may also incidentally show other people or places; Section 9.5 covers that. Accepted submissions are delivered to the Client that commissioned the Task and become part of that Client's Task records (Section 13.2 explains what this means for deletion).
3.6. Wallet, balance and payout data
We process your ERN balance and earnings history, and, when you withdraw earnings: your withdrawal amounts, your recipient cryptocurrency wallet address (and address tag/memo where applicable), transaction identifiers, and your withdrawal history. Withdrawals are paid in USDT. On-chain transactions are public: your wallet address and the transferred amount become part of a public blockchain record that we can neither edit nor delete (Section 9.6).
3.7. Chat
Messages you exchange with Clients through Platform chat: message text, machine translations, attachments, and moderation status. Every chat message with text is automatically checked by a moderation system, and translated messages are processed together with up to 30 prior messages of the conversation for context (Section 8).
3.8. Technical and security data
IP address and an approximate location (country, city and approximate coordinates) derived from it — the derivation happens on our own servers using a local database; your IP address is not sent to any geolocation provider. We also record security-relevant events (sign-ins, withdrawals, verification actions) with timestamps, operational logs (Section 12), and any correspondence you send to our support mailbox.
3.9. App permissions
The Android app declares the permissions listed in its Play data-safety form. As of the date of this draft, the app actively uses: read SMS (only for SMS Tests, Section 3.4), read phone state (SIM registration, Section 3.3), and notifications. Camera, microphone, precise location and media-library permissions are declared for upcoming Task types but are not requested by any current app feature; when Tasks that need them exist, the app will ask at the moment you take such a Task, not at install or launch.
4. Personal data we process about Clients
4.1. Account, company and billing data
- Account identity: name, email address, phone number, password (stored only as a salted hash), TOTP seed if you enable 2FA, account recovery codes; if you sign in with Google, the Google account identifier; if you verify your phone via Telegram, your Telegram account identifier.
- Company data: company name, billing address, country, phone, website; team invitations and member roles.
- Billing data: your ERN balance and transaction ledger; top-up records including USDT transaction hashes and the originating wallet address, where applicable.
4.2. Company verification (KYB) data
If your company applies for verification, we process: company registration documents and company proof-of-address documents; the extracted registration data (stored encrypted); your company website; a residential address declared by the account owner (entered through an address autocomplete service, Section 10); and, where the verification level requires identification of the company's owner, the owner's KYC data as described in Section 3.2 — including ID documents and face comparison, which involve biometric data.
At the higher (Pro+) company-verification levels we may also write to your company directly to confirm that the person applying is authorised to act for it. That letter goes to an address at your company, not to you; it names you (your name and email address) as the person making the claim; and the reply is read by our system from the verification mailbox named in Section 10, stored with your company's verification record, and assessed automatically (Sections 8.1, 9.8, 10, 12). The letter is always sent by a member of our staff, never automatically.
4.3. Content you upload — you are the controller
Files and datasets you upload to the Platform (for example, data for Agents to process) may contain personal data of third parties. For that data, you are the controller and we act as your processor: we store it, distribute it to Agents per your Task settings, and run automated content-safety checks on it (Section 8). You are responsible for having a lawful basis to upload it and to have it processed as your Task instructs. We process it only to operate your Task and the Platform's safety checks.
4.4. Chat and technical data
The same chat processing (Section 3.7) and technical/log/support-correspondence data (Section 3.8) apply to Client users.
5. Personal data about website visitors
Our public web pages are the Portal at earnhub.space and the domains earnhub.app and earnhub.io. For a visitor who only browses, we process exactly one category of data: the standard web-server access log of each request — your IP address, the requested URL, your browser's user-agent string and connection details — kept for the period stated in Section 12, plus an approximate location derived from the IP address on our own servers. Our pages set no advertising or third-party analytics cookies or trackers; our analytics are first-party and run on our own servers. A public statistics endpoint on earnhub.app publishes only aggregate counters and an anonymous event feed (a country code, an amount, a service name) — it contains no names, account identifiers or IP addresses.
6. Why we process personal data (legal bases)
6.1. We process personal data on the following bases, matched to the purposes in this Policy:
- To perform our contract with you: operating your account, matching and running Tasks, paying Agents, billing Clients, providing chat and support (Sections 3, 4).
- With your consent: Sensitive Personal Data (Section 7), the optional profile fields you choose to fill in, and the app permissions you grant.
- To comply with legal obligations that apply to us: keeping financial and transaction records, responding to lawful requests (Sections 9.7, 12).
- For the Platform's legitimate operational needs, where the PDPL permits processing without consent: security monitoring, fraud and duplicate-account prevention, moderation and content safety, and establishing or defending legal claims.
7. Sensitive Personal Data, and the consents we ask for
7.1. We process the following Sensitive Personal Data:
| Data | Whose | Why |
|---|---|---|
| Face embeddings and liveness video | Agents; Client company owners in KYB | Identity verification; duplicate-account detection |
| ID document images (which show your face) | Agents; Client company owners | Identity verification |
| Religion; political views | Agents (optional questionnaire fields, offered only at the Pro+ verification level — Section 7.3) | Survey-panel Task targeting, only if you choose to provide them |
7.2. Biometric data and precise location are processed only with your explicit consent, asked for at the moment they are first needed: before a verification capture session opens your camera, and before a Task that requires location/camera data first requests the corresponding permission. You can decline; declining means you cannot complete that verification level or that Task, but the rest of the Platform remains available. You can withdraw consent at any time by deleting your account or by asking us through the support mailbox (Section 13.2); withdrawing biometric consent deletes your face embeddings.
7.3. Sensitive profile questions are gated to high verification levels — as a standing rule. Any profile question that touches a sensitive category — today that is religion and political views; the rule equally covers categories the questionnaire may add later, such as membership of a political party — is offered only to Agents at the Pro+ verification level, where survey-panel targeting genuinely needs it. Such questions are always optional, with an explicit "prefer not to say" path, and leaving them unanswered never affects the rest of the Platform. We review new questionnaire fields against this rule as they are added. Stated honestly: the profile questionnaire narrows by verification level today, but this specific Pro+ restriction is a committed product rule whose enforcement in code has not yet been verified — until it is, these fields may be offered more widely than this Section says.
8. Automated processing, moderation and AI services
8.1. The Platform uses automated systems, including third-party large-language-model (LLM) services, for the following. The named providers and their jurisdictions are in Section 10.
- Chat moderation and translation: every chat message containing text is checked by an automated moderation model before delivery; translation processes the message plus up to 30 prior messages of the conversation.
- Content safety: every file uploaded by a Client (images, text, video frames, audio) is scanned by an automated moderation model.
- Submission checking: Agent Task submissions — photos, video frames, audio, together with GPS coordinates and capture time extracted from the files — are checked by an automated model for compliance with the Task.
- Document and face verification: ID document images, proof-of-address and company documents are read by an automated model (OCR/extraction), and pairs of face images are compared by an automated model. Liveness scoring runs entirely on our own servers; the liveness video itself is stored with our storage provider (Section 10).
- Company (KYB) research: your company name, website and the registration details you claim are used as search queries against a web-search service.
- Company-verification replies: where we write to a Client's company to confirm an applicant's authority (Sections 4.2 and 9.8), the reply we receive — its full text, together with the name and email address of the person who made the claim — is scored by an automated model to decide whether it confirms or denies the claim. The reply of an employee of an outside company is therefore processed by an LLM provider (Section 10).
8.2. Automated decisions with real effects. Whether an Agent's submission is accepted — and therefore paid — is decided by these automated checks at the moment of submission, without a human in the loop. A rejected submission is not paid and uses up an attempt; repeated rejections or timeouts can close that Task unit to you permanently. Verification checks are likewise automated in the first instance. If you believe an automated decision about you was wrong, you may contest it through our support mailbox (Section 18) and a human will review what the record supports.
8.3. We keep records of AI-service usage (token counts, cost, request identifiers) linked to the Client or Agent concerned. These records do not contain the content that was processed.
9. Who receives personal data
Our de-identification commitment (Agents). Agents appear to Clients under an anonymized platform label, never under their name, and we do not give Clients an Agent's email address, phone number, face photo, or any other data that identifies the Agent as a person — we enforce this on our side. There are exactly two exceptions: (1) data an Agent consents to share as part of performing a specific Task — for SMS Tests the receiving phone number is inherently part of the result (Section 9.4), and collected media carries the location and capture-time metadata the location consent covers; and (2) anything an Agent chooses to hand to a Client themselves, for example by sending personal documents in chat — that is the Agent's own decision and responsibility. Clients are contractually prohibited from attempting to re-identify Agents or contact them outside the Platform (Client Terms, Section 9.2).
9.1. Our staff
Our team of three, on a need-to-know basis, under the access controls in Section 14.
9.2. Service providers (processors)
The named providers in Section 10, strictly for the purposes listed there.
9.3. Clients receive Agent data — this is a feature, not an accident
When Agents make themselves available for Tasks, Clients can search and filter Agents by their profile attributes through the Portal — including, where the Agent has chosen to provide them: age, gender, region, education, employment, marital status, height, weight, spoken languages, timezone, device model, country, mobile operator, and religion. Two further optional attributes — political views and clothing size — are visible on an Agent's profile to Clients of the corresponding tier but cannot back a search filter today. Religion and political views reach Clients only where the Agent — at the Pro+ verification level, Section 7.3 — has chosen to provide them. Clients also see a masked version of your phone number (never the full number in search), and your platform statistics: completed units, likes and dislikes, reliability, total earned ERN, joining date and last-active date. Clients additionally receive the results Agents submit for their Tasks — including, for SMS Tests, the receiving phone number (Section 9.4) — and chat messages Agents send them. None of this identifies the Agent as a person (see the de-identification commitment above); Clients must use Agent data only to run their Tasks on the Platform and must not attempt to identify the person behind an Agent label.
9.4. SMS Test results and the services being tested
SMS Tests involve a third-party service sending a message to the Agent's SIM; that service necessarily learns the Agent's phone number in the course of the test flow. The Client that commissioned the test receives the individual result of each test — including the phone number that received the message, the sender identifier, the message text and the timing — as well as aggregate deliverability statistics. An Agent who takes an SMS Test is therefore disclosing their phone number to the commissioning Client and to the service under test. This is the task-consent exception to our de-identification commitment (Section 9, opening): the test cannot exist without the number, and the SMS-test consent states this before the Agent takes the test.
9.5. People who appear in submitted media
Photos and videos Agents submit may incidentally include bystanders. We instruct Agents to avoid capturing identifiable people where the Task does not require it. Such media is processed as Task-result content (stored, checked, delivered to the Client that commissioned it).
9.6. Public blockchains
USDT payouts and top-ups are executed on public blockchains (Section 10): wallet addresses, amounts and transaction identifiers become permanently public. This is inherent to how blockchains work and is not reversible by us or anyone.
9.7. Authorities
We disclose personal data where a law that applies to us requires it, or to establish, exercise or defend legal claims. We have no standing arrangements with any authority.
9.8. Third-party companies we contact to verify a Client's authority (KYB)
This is the one case where we process the personal data of someone who is not a user of the Platform and has given us nothing. Stated plainly, because it is unusual:
- What we send. When a company applies for a higher (Pro+) verification level, a member of our staff may send a letter to an address at that company — one or more recipients, sometimes with others in copy. The addresses are taken from openly available sources (the company's own website and public registers), collected by the automated research described in Section 8.1 and chosen by a human. Sending is never automatic.
- What the letter says. It identifies EarnHub, names the company, and names the person making the claim — our Client's contact, by full name and email address — and asks the recipient to confirm or deny that this person is authorised to act for the company. It carries a one-time reference code in the subject line, which is how we recognise the reply; that code is valid for the reply deadline (72 hours by default).
- What we do with the reply. The reply is read from the verification mailbox named in Section 10 — which must be a mailbox dedicated to this purpose before this policy is published; see the flag on that entry — and we keep the sender address, subject, date and the full text of the reply with the company's verification record. A copy — the reply text, together with the claimant's name and email address and the letter we sent — is stored in our file storage and assessed by an automated model (Sections 8.1, 10).
- The recipient's data. For the person who receives the letter, the personal data we process is: their work email address, whatever they write back, and the fact that they answered.
9.9. What we do not do
We do not sell personal data. We do not share it with advertisers or data brokers. Our web pages set no advertising or third-party analytics cookies or trackers (Section 5).
10. Named recipients and their jurisdictions
The table below lists every third party that personal data actually reaches as of the date of this draft, what reaches it, and where it is subject to jurisdiction. All of them act as our processors or infrastructure providers except where noted.
| Provider | Jurisdiction | What reaches it |
|---|---|---|
| [HOSTING PROVIDER] (server hosting) | To be confirmed before publication | All Platform data resides on rented servers operated by our hosting provider, which runs the physical infrastructure and does not access data in the ordinary course |
| Cloudflare, Inc. (R2 object storage) | United States (we use its EU-jurisdiction storage endpoint) | All stored files: Task-result media (including EXIF/GPS), Client uploads, chat attachments, and verification evidence — liveness videos, ID document images, proof-of-address and company documents |
| OpenRouter, Inc. (LLM gateway) | United States | Content submitted to the automated checks in Section 8: chat messages (with up to 30 prior messages), Client-uploaded file content, Agent submissions with GPS/capture-time context, ID document images and face-image pairs for verification. OpenRouter routes requests to downstream model providers (currently including Google-published, Xiaomi-published and Alibaba-published (Qwen) models, and hosting providers such as DeepInfra); the routed content transits those providers' infrastructure |
| Google LLC — Firebase Authentication | United States | Google sign-in tokens and account identifiers (Agents and Clients who choose Google sign-in) |
| Resend — operated by Plus Five Five, Inc. (email delivery) | United States. Resend stores all customer data — message content, delivery logs and account records — in the United States; the sending region we choose changes only where a message is routed from, not where it is stored | All outbound Platform email, in full, for all three audiences (from noreply@mail.earnhub.app to Agents, noreply@mail.earnhub.space to Clients, noreply@mail.earnhub.io to staff): recipient address, subject and the complete rendered message body. In practice this includes sign-up, reset and invitation links; one-time codes; the sign-in notification that states your IP address, derived city/country and device; and the company-verification letter of Section 9.8 with its reference code and the claimant's name and email address. We send no attachments. |
| Google LLC — the mailbox that receives company-verification replies (Section 9.8) | United States | The reply sent by the third-party company: sender address, subject, date and full text, read from the mailbox over IMAP. This is a receiving mailbox only — the three mail.* sending domains cannot receive mail, which is why the letter's reply address is this mailbox and not its sender. This entry must be replaced before publication, not merely re-worded: the mailbox in use on 2026-08-25 is a personal Google account, and moving it to an organisational mailbox at Spacemail (operated by Spaceship, Inc.; United States, reported and unconfirmed) — the provider that already hosts our corporate earnhub.io mail — was ruled on 2026-08-25 but has not been carried out. Publishing this table while the personal account is still in place would disclose a processor we have named wrongly |
| Google LLC — Places API | United States | The residential address a Client account owner declares during Pro verification (address autocomplete) |
| Brave Software, Inc. (Search API) | United States | KYB research queries: company name, website, claimed registration details |
| New-Tel (phone verification calls) | Jurisdiction to be confirmed before publication | Agent phone numbers, for automated verification calls |
| Telegram (messenger) | Dubai-headquartered; controlling entities to be confirmed before publication | Phone verification via contact share (phone number, Telegram user ID); delivery of Telegram-channel notifications |
| Binance (crypto exchange) | Global; multiple jurisdictions | Agent payout details for Binance-rail withdrawals: recipient address, address tag, amounts, order identifiers |
| Public blockchain networks — BNB Smart Chain, Arbitrum One, Polygon, Base — via public RPC endpoints | Decentralized, worldwide | On-chain USDT transfers: wallet addresses, amounts, transaction identifiers (permanently public) |
Notes, stated for accuracy:
- IP geolocation is local. We resolve IP addresses to approximate locations using a database on our own servers (MaxMind database files); IP addresses are not sent to MaxMind or any other geolocation provider.
- No push-notification provider. The app does not use Google Firebase Cloud Messaging or any push service; no push device tokens are collected. Notifications reach you in-app, by email, or by Telegram.
- Email is delivered by a processor that stores what it sends. Resend keeps message content and delivery logs for a period we state in Section 12; it is certified under the EU-U.S. Data Privacy Framework, publishes a data-processing addendum that takes effect automatically for every account, and publishes its own list of sub-processors — which includes hosting, database, analytics and AI providers of its own. We do not control that chain beyond choosing the provider.
11. International transfers
11.1. We are a UAE company. Our servers are operated by the hosting provider named in Section 10, and the other providers in Section 10 process data in the United States and other jurisdictions outside the UAE. In particular, verification evidence including biometric-source material (liveness videos, ID images) is stored with Cloudflare (a US company, on its EU storage endpoint), and ID images and face pairs transit OpenRouter (US) and its downstream model hosts during verification. Every email we send you is also transferred to, and stored in, the United States by our email provider (Section 10), and there is no storage-location setting that would change that — the provider's regional options govern only where a message is sent from. The same is true of the mailbox that receives company-verification replies (Section 9.8).
11.2. The PDPL permits transfers of personal data outside the UAE to jurisdictions with adequate protection, or otherwise subject to safeguards including appropriate contractual arrangements or the data subject's express consent. The PDPL's executive regulations — which are expected to define the adequacy list and detailed transfer mechanisms — have not been issued. Until they are, we rest our transfers on the contractual data-protection commitments in our providers' terms and, for Sensitive Personal Data, on the express consent described in Section 7.
12. Retention — how long we keep personal data
We keep personal data no longer than needed for the purposes above, subject to the specific periods below. This table states our actual current practice, including where automatic deletion does not yet exist; we would rather tell you the true state than a flattering one.
| Data | Retention |
|---|---|
| Sign-up and password-reset links | 15 minutes |
| Verification capture sessions and upload links | 15–30 minutes |
| Telegram phone-verification codes | 30 minutes |
| Sign-in sessions and tokens | Until they expire or are revoked |
| Quarantined (rejected) uploads | 1 day |
| Verification processing and technical working copies | 7 days |
| SMS sender registrations | 30 days |
| Operational logs (queryable log store), including web-server access logs with visitor IP addresses | 30 days — see 12.2 for the raw-copy caveats |
| Infrastructure metrics (aggregate, no personal identifiers known) | 30 days |
| Notifications (in-app/email/Telegram delivery records) | 1 month |
| Email content and delivery logs held by our email provider (Section 10) | 30 days on the provider's standard plans, after which message content and logs are deleted; the provider states that its backups persist separately — it publishes both a 7-day and a 30-day figure for them, which we have asked it to reconcile (see the flag below). For most Platform mail we keep no copy of the rendered message — we hold the underlying data (your address, the notification, the token) and re-render from it. Two exceptions, both kept on our own systems: the notification records in the row above hold the title and body text a notification email carried, and the company-verification correspondence in the row below is stored in full, both the letter we sent and the reply we received |
| Company-verification correspondence with third parties (Section 9.8): the letter we sent, its reference code, and the reply we received | Kept 12 months from the date we receive the reply, then deleted — the mailbox copy and both of ours (the company's verification record and the copy in our file storage). What survives is the verification decision itself and its audit record, never the correspondence. Automatic enforcement does not exist yet: until the deletion sweep is built, this period is honoured by a manually approved pass on the same schedule — see Section 9.8 |
| Platform email sent before 2026-08-24 | Held in the Google account through which all Platform mail was previously sent. Whether that account's sent history still holds those messages, and on what schedule it will be cleared, is not settled — see the flag below |
| Account, profile, phone/SIM and chat data | Life of the account; deleted when the account is deleted |
| Biometric templates (face embeddings) | Until you withdraw consent or delete your account, whichever is first — deleted automatically on account deletion |
| Identity documents (ID images, proof-of-address and company documents) and the encrypted identity data extracted from them | Kept 5 years after account deletion (or the end of the company relationship) as identity-verification records, then deleted. This period is our self-set operating default pending professional confirmation (see the flag below). Automatic enforcement does not exist yet: until the deletion sweep that applies this period is built, deletion happens through a manually approved purge on the same schedule |
| Liveness videos | Deleted 90 days after the verification decision; deleted at once on account deletion if still present. Automatic enforcement does not exist yet — same manually approved purge until the sweep is built |
| SMS Test records, including message content | Life of the account in our primary store (deleted with the account); see 12.2 for the analytics copy |
| Task submissions delivered to Clients | Part of the commissioning Client's Task records; they follow the Client's Task and storage deletion, not the Agent's account |
| Task media EXIF/GPS metadata | Media follows Task/asset deletion; extracted EXIF records currently have no automatic expiry |
| Financial ledger, withdrawal and payment records | Retained indefinitely as accounting/audit records, including after account deletion |
| Analytics event records | No automatic expiry currently applies — see 12.2 |
12.2. Honest gaps we are fixing. Parts of our infrastructure do not yet enforce the retention discipline this Policy intends, and we say so plainly:
- Our analytics event store (which includes email addresses, IP addresses and derived locations, phone/SIM details, SMS Test message content, and withdrawal wallet addresses) currently has no automatic expiry, and its records are not removed by account deletion. Until automatic limits are in place, we delete a person's analytics records manually on request (Section 13).
- Our raw system journal (a low-level copy of operational logs) is limited by size rather than by time, so individual entries can persist longer than the 30-day queryable store. A fixed time bound is being introduced.
- A frozen archive of old web-server access logs (visitor IP addresses, October 2025 – February 2026) predates our current logging pipeline and sits outside every automatic deletion mechanism. It is being deleted, not retained.
- Operational log lines can include personal data that appears in the operations they record (for example, an email address in a failed sign-in). A redaction layer that strips personal data and secrets from log output is being introduced; until it lands, log access is restricted to our three-person team and the 30-day expiry of the queryable store applies.
13. Your rights under the PDPL
13.1. Subject to the conditions and exceptions in the PDPL, you have the right to:
- request access to the personal data we process about you, and information about how it is processed and shared;
- request a copy / transfer of your personal data in a structured, machine-readable form;
- request correction of inaccurate or incomplete personal data;
- request erasure of your personal data;
- request restriction of, or object to, processing in the circumstances the PDPL provides;
- object to decisions based solely on automated processing as described in Section 8.2;
- withdraw consent at any time where processing rests on consent (Section 7.2) — this does not affect processing already carried out;
- complain to the UAE Data Office if you consider that our processing violates the PDPL.
We have listed only the rights the PDPL provides; where you may have heard of rights under other laws (such as the GDPR), they apply only if that law applies to you independently of this Policy.
13.2. How to exercise your rights.
- Agents can delete their account directly in the app; deletion is confirmed with your second factor. Deletion removes your account, profile, phones, SMS Test history and chat threads from our primary systems, revokes and deletes your biometric templates, and removes you from Client search. It does not remove: your identity-verification records — ID document images and the encrypted identity data extracted from them — which we keep for 5 years after deletion as identity-verification records and then delete (Section 12); your liveness video, which follows its own 90-day clock (Section 12); Task results you have already delivered to Clients (they remain part of the commissioning Client's Task records); financial records (Section 12); and — until the fix described in 12.2 lands — analytics copies, unless you ask us to remove them.
- Clients can request account closure and any other right through the support mailbox; there is no self-service closure in the Portal today.
- Everyone can send any rights request to [SUPPORT EMAIL]. We will need enough information to verify you control the account concerned. We answer every request ourselves — we are a three-person team — and aim to respond within 30 days; if a request is complex we will tell you within that time what is taking longer and why.
14. Security
We protect personal data with measures that include:
- encryption in transit (TLS) on all public endpoints;
- password hashing (passwords are never stored in readable form);
- encryption at rest for extracted identity data (the text extracted from ID and company documents is stored encrypted with a dedicated key); verification evidence is held in a private storage bucket separate from general content;
- two-factor authentication available to all accounts, and required for sensitive Agent actions (account deletion, withdrawals);
- segregated verification processing: the workers that handle biometric and document checks run network-isolated except for the specific services they need; liveness analysis runs entirely on our own servers;
- operational controls: withdrawals above limits require staff approval; manual balance changes require two staff members; staff actions on verification data are logged in an audit trail;
- access limitation: production access is limited to our three-person team.
No system is perfectly secure, and we do not claim ours is. We describe here what we actually run, and we improve it continuously; material weaknesses we identify are tracked and fixed before launch-critical milestones.
15. Data breach notification
If a breach of personal data security occurs that is likely to prejudice your privacy or the confidentiality of your data, we will notify the competent UAE supervisory authority (the UAE Data Office) as the PDPL requires, and we will notify you directly — through the Platform or the email on your account — without undue delay when the breach is likely to put you at real risk, telling you in plain language what happened, what data is affected, and what we and you can do about it. Reports of suspected security issues: [SECURITY CONTACT EMAIL — to be created before launch]. Because we are a three-person team, our incident process is simple by design: contain, assess, notify, remediate — with the same people doing all four.
16. Children
The Platform is for adults. You must be 18 or older to use EarnHub as an Agent or to act for a Client. We do not knowingly process children's data; identity verification at higher Agent levels involves ID-document checks that confirm age, though basic accounts are created on self-declaration alone. If we learn an account belongs to someone under 18, we will close it and delete its data as described in Section 13.2.
17. Changes to this Policy
We will update this Policy when the Platform or the law changes. The version and date at the top identify the current text. For material changes we will notify registered users through the Platform or by email before the change takes effect, and — where a change concerns processing that rests on your consent — we will ask for that consent again rather than assume it.
18. Contact
[ENTITY LEGAL NAME], a company incorporated in the RAK Digital Assets Oasis free zone, Ras Al Khaimah, United Arab Emirates.
All privacy matters: [SUPPORT EMAIL].
This Policy is provided in English only.