Version 1.1 – Last updated: 14 July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Timothy Kardel, operating under "Claimo"
Rilkestr. 8
41541 Dormagen Zons
Germany
Email: support@claimo-app.com
A data protection officer has not currently been appointed. For data protection inquiries, you can reach us at support@claimo-app.com.
2. Scope
This privacy policy applies to the mobile application Claimo (hereinafter the "App") and the related services, in particular the user account, rewards system, offerwalls, advertising, payouts, push notifications, support, and the admin dashboard.
If you use offers, surveys, games, advertisements, or payout methods from third-party providers through the App, the privacy notices of those third-party providers may also apply. We have only limited influence over this.
3. Overview
Claimo processes in particular:
- account data such as email address, login method, display name, and referral code,
- reward and usage data such as gems, tickets, XP, level, streaks, transactions, daily tasks, offerwall credits, and payouts,
- technical security data such as an installation-related device identifier and hashed IP signals for fraud prevention,
- settings such as the chosen app language, push notifications, email updates, and personalized offers,
- push tokens and push delivery logs, when notifications are enabled,
- advertising and consent data in connection with Google AdMob,
- data generated by BitLabs offers and their callbacks,
- support and payout emails.
Under its current structure, the App does not collect GPS location data, contacts, camera or microphone content, or user payment data for in-app purchases. No genuine external analytics service is currently connected; the existing analytics interface is a local no-op.
4. Legal bases
We process personal data on the following legal bases:
- Art. 6(1)(b) GDPR, where processing is necessary to provide the App, the user account, the rewards system, offerwall credits, payouts, and support.
- Art. 6(1)(c) GDPR, where we process data to fulfil legal obligations, for example commercial, tax, or record-keeping retention requirements.
- Art. 6(1)(f) GDPR, where we have a legitimate interest, in particular in security, fraud prevention, abuse detection, operations, troubleshooting, support, defense of legal claims, and aggregated evaluation of app operations.
- Art. 6(1)(a) GDPR, where you have given consent, for example for certain push notifications, personalized advertising/offers, or tracking, insofar as consent is required.
You can withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.
5. Registration, login, and user account
A user account is required to use the App. You can register or log in using an email address and password, or via supported third-party logins such as Google or Facebook.
In doing so, we process in particular:
- email address,
- password or password hash via the authentication service,
- user ID,
- display name and avatar letter,
- login provider, for example email, Google, or Facebook,
- technical authentication data such as session and refresh tokens,
- time of registration and last login,
- accepted version of the terms of use and time of acceptance,
- optionally entered referral code.
Authentication and database functions are currently provided via Supabase. Supabase processes the data on our behalf, insofar as we store and retrieve app data via Supabase.
With Google or Facebook login, you are redirected to the respective provider. We receive from that provider the data required for login, typically a provider ID and email address, as well as, where applicable, basic profile information, depending on your settings with the third-party provider.
6. Profile, wallet, rewards, and app progress
For the rewards app to function, we store account-related game data and reward data. This includes in particular:
- gems and ticket balances,
- wallet transactions with amount, currency, type, description, metadata, and timestamp,
- welcome bonus, daily rewards, daily streak, streak protection, and daily tasks,
- active usage time for daily tasks, currently measured in seconds per day,
- level, XP, and level bonuses,
- ticket boosters, boost type, and expiry time,
- referral code, referred user, referring user, and referral bonuses,
- in-app notifications about rewards, payouts, and status changes.
This data is necessary to correctly calculate your balance, grant rewards, display your progress, prevent abuse, and be able to trace support requests.
7. Offerwalls and BitLabs
Claimo currently integrates BitLabs as an offerwall and offer provider. Additional providers may be added later.
When you open the BitLabs offerwall or a BitLabs offer, the following data may be transmitted to BitLabs:
- your Claimo user ID as a unique user ID,
- your display name, insofar as it is passed to the offerwall as a username,
- technical parameters such as app token, in-app mode, theme, currency, and offer placement,
- where applicable, data that your device or browser automatically transmits when opening the BitLabs website, for example IP address, device/browser data, and usage data.
BitLabs decides, according to its own offer terms, whether an offer has been successfully completed. BitLabs sends server callbacks to us for this purpose. We store in particular:
- user ID,
- BitLabs transaction ID,
- gems to be credited,
- USD amount or partner value, insofar as provided by BitLabs,
- callback URL,
- callback payload including technical parameters and hash,
- credit status, for example "credited" or "ignored",
- time of the callback.
This processing is necessary to correctly display offerwall rewards, avoid duplicate credits, process chargebacks, and make revenue/rewards traceable.
For processing within the BitLabs offerwall, BitLabs or BitBurst GmbH is responsible under its own privacy notices, insofar as BitLabs pursues its own purposes. BitLabs may process in particular offer, survey, device, usage, and fraud-prevention data.
8. Advertising and Google AdMob
The App may display voluntary rewarded ads. After fully watching an advertisement, gems and XP may be credited.
We use Google AdMob and the Google Mobile Ads SDK for this purpose. In doing so, Google and its partners may process in particular the following data:
- advertising ID or mobile advertising ID, where available and permitted,
- IP address, device information, operating system, app information,
- ad impressions, interactions, load errors, and technical delivery data,
- approximate location information, insofar as this is derived from an IP address or device signals,
- consent status and privacy choices.
The App initializes AdMob with a delayed app-measurement start and invokes a Google consent prompt before requesting ads. If ads may not be loaded due to missing privacy consent, the App shows a corresponding error message.
Personalized advertising and personalized offers can be disabled in the App settings. In addition, you can reset the advertising ID at the system level or restrict personalized advertising/tracking. On iOS, an App Tracking Transparency prompt may also appear.
Crediting for rewarded ads takes place server-side within Claimo. We do not store the content of the advertisement itself, but in particular the reward claim, timestamps, limits, and wallet transactions.
9. Payouts and rewards
When you redeem gems for rewards, we process the data required for verification and delivery. This includes in particular:
- user ID, account email, and display name,
- selected reward, provider, reward key, and value,
- recipient email address, for example a PayPal or voucher email,
- gem cost, status, request time, review time, and payout time,
- fraud review status, fraud flags, risk score, and risk details,
- reason for rejection, if a request is declined,
- admin notes, review events, and the responsible admin,
- payout reference, email ID, and for vouchers only a masked reference such as the last digits of the code, not the full voucher code.
Payout requests are currently reviewed manually. For this purpose, admins can view payout data, account data, wallet data, fraud flags, risk signals, and prior transactions in the admin dashboard.
Resend is currently used to send voucher and payout emails. Resend receives the recipient email address, subject, email content, and technical delivery data. For PayPal payouts or external voucher suppliers, the respective providers may also receive data, insofar as this is required for the payout or redemption.
Please make sure to provide a correct recipient email address for payouts. Incorrect information may result in a reward not being delivered.
10. Fraud prevention and security
Claimo is a free rewards app. To prevent multiple accounts, manipulation, fake activity, chargebacks, and abusive payouts, we process technical and account-related security signals.
The App generates a random installation-related device identifier and stores it locally via Expo SecureStore. This identifier is transmitted to our backend and stored there in pseudonymized form using a hashing procedure.
On the server side, the IP address may additionally be read from request headers and stored as a hashed IP value. Under the current implementation, we do not store the raw IP address in the fraud table, only the hash value.
Fraud review may take into account in particular:
- account age,
- prior earning history and type of credits,
- unusually fast collection rates,
- referral patterns,
- shared recipient email addresses,
- offerwall chargebacks,
- repeated or rejected payout requests,
- shared device or IP signals,
- manual risk notes and blocking flags set by admins.
This data is used to review payouts, detect fraud, prevent abuse, and protect the rights of the provider as well as honest users.
The App may automatically generate fraud flags and risk scores. Payouts are generally approved or rejected as part of a manual review. An account that has already been manually blocked can be technically excluded from further payout requests.
11. Push notifications and in-app messages
When push notifications are enabled, the App requests the required device permission and generates an Expo Push Token via Expo Notifications.
We store:
- Expo Push Token,
- platform, for example iOS or Android,
- user ID,
- time of creation, update, and last seen,
- your setting on whether push notifications are enabled.
Push messages may relate, for example, to daily rewards, inactivity reminders, offerwall credits, or completed payouts.
For traceability and error diagnosis, we store push delivery logs, in particular reason, title, text, platform, a truncated token preview, delivery status, Expo request ID, error messages, metadata, and timestamp.
Delivery takes place via the Expo Push Service and, depending on the platform, via Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM)/Google services.
You can disable push notifications in the App. In addition, you can block notifications at any time in your device settings.
Independent of push, Claimo stores an in-app message list ("notification bell") for important reward and payout events. Under the current implementation, these entries are limited to a maximum of 100 entries per user and a maximum of 90 days.
12. Settings, consents, and local storage
The App stores settings for:
- the chosen app language,
- push notifications,
- email updates,
- personalized offers or personalized tracking.
Before login, the App reads only locally the language and region provided by the operating system, in order to suggest one of the supported app languages. We use neither the IP address, GPS location data, nor an external geolocation service for this. The device language and region read this way are not transmitted to us or to third parties.
The following may be stored locally on your device in particular:
- the selected app language in AsyncStorage,
- Supabase session data and auth tokens in AsyncStorage,
- Expo Push Token in AsyncStorage,
- a random installation-related device identifier in Expo SecureStore,
- local flags, for example whether a rating prompt has already been shown,
- on web platforms, local flags, for example whether an OAuth referral prompt has already been completed.
After registration, the selected app language is additionally stored as an account setting with Supabase. On later logins, the language stored there can be loaded. The locally read device language and region are not applied in that case.
Expo SecureStore stores data encrypted within the respective platform storage. On iOS, SecureStore data may, depending on system behavior, persist even after uninstallation if the App is later reinstalled with the same bundle ID.
13. Support, emails, clipboard, sharing, and store reviews
If you contact support by email, we process the data you submit, in particular your email address, the content of your message, attachments, timestamps, and support topic. If you use the App's mailto function, your email program is opened; your email provider processes the data independently.
If you copy the referral code, the App only writes the code to your device's clipboard. Other apps or your operating system may have access to the clipboard.
If you share the referral code, the App uses your device's native share dialog. The selected target app processes the shared data according to its own privacy rules.
If you leave a rating or use the store review dialog, the review process is handled via the Apple App Store or Google Play. We do not receive complete personal rating data from Apple or Google, unless it is made available to us in the respective store consoles.
14. Admin dashboard and aggregated evaluations
Authorized admins can use an admin dashboard to review payouts, view user overviews, document risk decisions, review push delivery logs, and evaluate aggregated performance/growth data.
Admin functions are access-protected and role-based. Admin actions may be logged with admin user ID, note, previous status, new status, and timestamp.
Aggregated evaluations include, for example, user numbers, activity, offerwall revenue, payouts, retention proxies, fraud metrics, and manually entered advertising costs. Under the current structure, these evaluations are internal to admins and serve operations, management, fraud prevention, and improvement of the App.
No external product analytics or tracking service such as Firebase Analytics, PostHog, or Mixpanel is currently actively connected. Under the current implementation, the analytics function prepared in the code does not send any data to third parties.
15. Recipients and service providers
Personal data may be disclosed in particular to the following categories of recipients:
- hosting, backend, and database providers,
- authentication providers,
- offerwall, survey, and advertising partners,
- push and platform services,
- email delivery services,
- payout and voucher providers,
- support and communication providers,
- app store and operating system providers,
- legal advisors, authorities, or courts, where necessary.
Currently relevant in particular are:
- Supabase for authentication, database, edge functions, and API access,
- Expo/EAS and the Expo Push Service for Expo project functions and push delivery,
- Google, in particular Google AdMob, Google Mobile Ads, Google login, and, on Android, possibly Firebase Cloud Messaging/Google Play Services,
- Apple, in particular APNs, iOS system services, and App Store reviews,
- Meta/Facebook, insofar as Facebook login is enabled,
- BitLabs / BitBurst GmbH for offerwall offers and reward callbacks,
- Resend for sending payout and status emails,
- PayPal and voucher/reward providers, insofar as data is required for payout or redemption.
Where necessary, we enter into data processing agreements under Art. 28 GDPR with our processors.
16. Transfers to third countries
Some service providers are based, or maintain technical infrastructure, outside the European Union or the European Economic Area, in particular in the USA.
Insofar as personal data is transferred to third countries, this takes place on the basis of appropriate safeguards, for example EU standard contractual clauses, adequacy decisions, the EU-US Data Privacy Framework where applicable, or explicit consent.
Which transfer mechanisms specifically apply depends on the respective service provider, its certifications, the regions used, and the contractual arrangements in place. We review these bases regularly and update this privacy policy in the event of material changes.
17. Storage period and deletion
We store personal data only for as long as necessary for the purposes stated, or for as long as legal obligations or legitimate interests justify longer storage.
As a general rule:
- We store account and profile data for the duration of your user account.
- We store wallet, reward, referral, offerwall, and payout data for the duration of your user account and beyond, insofar as this is necessary for evidentiary purposes, fraud prevention, accounting, defense of legal claims, or statutory retention obligations.
- Under the current implementation, in-app notifications are limited to 90 days or 100 entries per user.
- Push tokens are deleted when you disable push notifications or when they are no longer needed.
- We store support and payout emails for as long as necessary for processing and record-keeping.
- We store fraud signals for as long as necessary for fraud prevention, defense of legal claims, or payout security.
If you have your account deleted, we delete or anonymize your personal data, insofar as no statutory retention obligations, open payout reviews, fraud reviews, or legitimate interests in defending legal claims stand in the way. Data that we may not delete immediately is blocked from use for other purposes.
18. Provision of data
Providing certain data is necessary to be able to use the App. Without an email address or login credentials, no account can be created. Without wallet and transaction data, rewards cannot be managed. Without a recipient email address, rewards cannot be delivered.
Other data is voluntary, for example a referral code, push permission, support messages, or personalized offers. If you do not provide voluntary data, the respective feature may be limited.
19. Automated decisions and profiling
The App uses automated rules for fraud prevention and to detect suspicious payout requests. In doing so, risk scores and fraud flags may be generated.
As a rule, a payout is not rejected solely by automated means; instead, it is submitted for manual review. Accounts that have already been manually blocked can be technically excluded from payouts.
You can contact support with any questions about a decision or a block.
20. Security
We take technical and organizational measures to protect your data. These include in particular role-based admin access, row-level security in the database, server-side crediting, hashed fraud signals, protected edge functions, and limited disclosure of sensitive data in the admin dashboard.
Nevertheless, no system can guarantee absolute security. Please protect your login credentials and inform us if you suspect unauthorized access.
21. Your rights
Under the GDPR, you have in particular the following rights:
- right of access under Art. 15 GDPR,
- right to rectification under Art. 16 GDPR,
- right to erasure under Art. 17 GDPR,
- right to restriction of processing under Art. 18 GDPR,
- right to data portability under Art. 20 GDPR,
- right to object under Art. 21 GDPR,
- right to withdraw consent under Art. 7(3) GDPR,
- right to lodge a complaint with a data protection supervisory authority.
To exercise your rights, you can contact us at support@claimo-app.com. For processing purposes, we may need to verify your identity beyond doubt.
If your request concerns data that a third-party provider processes independently, for example BitLabs, Google, Meta, Apple, PayPal, or a voucher provider, it may be necessary for you to additionally contact that third-party provider directly. We will support you in doing so where possible.
22. Right to object under Art. 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data where such processing is based on Art. 6(1)(e) or (f) GDPR.
We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
You may object to direct marketing at any time. In that case, your data will no longer be processed for direct marketing purposes.
23. Children and minors
The App is not directed at children or minors. Use is permitted only from the age of 18 and only in accordance with the terms of use.
If we learn that an account has been created in violation of the age requirements or that required consents are missing, we may suspend or delete the account.
24. Changes to this privacy policy
We may update this privacy policy if the App, the data processing, the legal situation, or the service providers used change.
The current version is available in the App and at the following URL: https://claimo-app.com/datenschutz-app.html.
In the event of material changes, we will inform you in an appropriate manner, for example within the App or by email.