← Back to rewado.io

Privacy Policy

Controller: Axess Intelligence GmbH, Pilgrimstraße 6, 50674 Cologne, Germany.
Data Protection Officer: privacy@rewado.io ([TBC] — DPO to be appointed).
Contact for privacy requests: privacy@rewado.io

1. Who we are and what Rewado does

Rewado is operated by Axess Intelligence GmbH. Rewado pays you rewards for taking part in market research: with your consent, we study the promotional emails brands send you and the promotional messages and screenshots you upload, and we sell pseudonymised, persona-level insights about brands' marketing to business customers. The companies that pay us are not necessarily the brands whose communications we study.

2. What data we collect

You provide / we collect from your use:

  • Account: email, hashed password, display name, optional phone.
  • Profile: country, language, preferences; demographic answers you give.
  • Connected email mailbox content — see §3.
  • Promotional messages and screenshots you submit — see §4.
  • Payout / verification data when you cash out.
  • Device & usage data: device type, OS, IP address, device identifiers, features used, timestamps, coarse (country-level) location, crash/performance data.
  • Consent records (what you agreed to, when, and the policy version).

From third parties: name/email from Google sign-in; confirmations from affiliate/attribution networks.

3. Connecting your email (Gmail)

  • You generate a Google app-specific password and enter it in the app. It is stored encrypted on your device and is not sent to our servers.
  • The app scans your mailbox on your device to find promotional messages. To identify them it examines incoming mail — which can include messages from senders you don't have a relationship with — but only the promotional content is processed and kept for the research purpose in §5; other messages are not retained. We never receive or store your main Google password.
  • An app password technically grants broader mailbox access; we use it solely to scan for and process promotional mail.

4. Promotional messages, SMS & push notifications you share

Beyond email, you can earn by uploading screenshots of promotional messages you receive from brands — including marketing SMS and push notifications. You choose what to upload; we process only the promotional content you submit for the research purpose described in §5. Rewado does not read, intercept, or automatically capture your SMS or push notifications in the background: you take a screenshot yourself and submit it, and we process only that image. You decide, each time, what to share.

5. How we use your data, and the AI and people involved

  • Reward & account operation (contract).
  • Market research + profiling (your consent): we remove direct identifiers, then assign you to a pseudonymised persona (e.g. "lapsed viewer") inferred from signals in the emails/messages themselves. This is profiling. Business customers can see that a communication reached a given persona — never your name or identity.
  • No automated decisions with legal or similarly significant effect: rewards follow a fixed, per-brand rule for the content you share — not a profile-based judgment about you — and screenshot uploads are checked by a person. Art. 22 GDPR (solely automated decision-making) therefore does not apply.
  • AI processing: uploaded content and email content are processed by Google's Gemini models (via Google Cloud Vertex AI) and Google Cloud Vision (optical character recognition) to read the promotional content and extract offer details.
  • Human review: our trained review team, bound by confidentiality, quality-checks our work and verifies de-identification, and may see content before de-identification is complete. (Interim wording; to be updated to "reviewers see identifiers masked" once masking is enforced — #533.)
  • Fraud prevention; affiliate task attribution.

On "anonymisation": identifiers are removed from what business customers receive, but our internal research records remain linkable to you (pseudonymous) and therefore remain personal data under GDPR until truly anonymised.

6. Lawful bases (Art. 6 / Art. 9 GDPR)

  • Reward processing & account: contract (Art. 6(1)(b)).
  • Market research + persona profiling: your consent (Art. 6(1)(a), Art. 7), collected granularly and separately in-app, withdrawable anytime.
  • Where the communications you share reveal — or our persona profiling infers — special-category data (for example, gambling-related interests indicated by marketing from betting or casino brands): we rely on your explicit consent (Art. 9(2)(a)). You give this as a separate, explicit consent in the app — a dedicated checkbox, shown apart from your general research consent, that expressly names gambling & betting brands. Because those brands are part of the marketing we study, this consent is required to use Rewado: if you do not give it, or later withdraw it in Settings, your research participation is paused until you provide it again. We do not attempt to infer, and do not derive, self-exclusion status, cooling-off periods, deposit limits, problem-gambling status, or your financial means/affordability from this content. (Consent architecture + final copy + German localisation pending legal sign-off — #524/#529.)

7. Who receives your data (sub-processors)

ProviderPurposeLocation
VercelApp & API hosting; request logsUS
NeonDatabase (all stored data)EU (Frankfurt)
Google Cloud StorageFile & image storageEU [TBC region]
Google Cloud Vertex AI (Gemini)AI recognition of uploaded content & emailEU region (pinned) [TBC]
Google Cloud VisionOptical character recognition (OCR) on images[TBC region]
Google (Gmail)Hosts your connected mailbox; the app reads it on your device via IMAPGoogle (US/EU)
Google FirebasePush notifications, crash & performance diagnostics, analytics[TBC]
Anthropic (Claude)AI chat over pseudonymised insights (business-customer platform)US
OpenAISearch / embeddings over pseudonymised insightsUS
IntercomSupport chatUS [TBC]
Affiliate / attribution networksTask confirmationEEA / US
Payment / reward partnersPayouts[TBC]
ResendTransactional email deliveryEU / US [TBC]
MixpanelProduct analyticsUS [TBC]
PusherRealtime notifications (contentless pokes)EU
Dagster+Data-pipeline orchestration[TBC]
Google Cloud RunCompute / content processingEU [TBC region]
Oxylabs / ScrapflyContent rendering / collection[TBC]

Our full, current sub-processor list is maintained at privacy@rewado.io on request [TBC — link the published sub-processor list (#528)]. Business customers receive only pseudonymised, persona-level insights (with your direct identifiers such as name and email removed) — never your raw uploads, mailbox, or account data. We do not sell personal information and do not share it for cross-context behavioural advertising.

8. International transfers

Wherever possible we keep processing inside the EU/EEA — for example, our database is hosted in Frankfurt — so that no international transfer takes place, and we prefer EU-region options for our other providers where they are offered. Where processing outside the EU/EEA is unavoidable (for example certain US-based hosting or support services), we rely on an appropriate safeguard under Chapter V GDPR — the EU–US Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses (2021/914, Module 2) otherwise — together with a case-by-case transfer impact assessment and additional technical and organisational safeguards. Our current sub-processor list identifies the mechanism relied on for each provider. (Per-provider EU-region pinning is being rolled out — #525.)

9. Retention

  • Account data: while active + 30 days after deletion.
  • Raw mailbox / uploaded content (original emails, images, OCR text, detected-PII records): kept for a maximum of 90 days after we extract the research insight, so extraction can be re-run if needed, then deleted. A shorter deadline overrides this: if you withdraw consent or ask us to erase your data, we delete the raw content promptly rather than waiting out the 90 days. Any special-category-derived attributes are kept for a shorter period than general profile data. (90-day period + its enforcement pending final product/legal confirmation — #526.)
  • Backups and logs: the above content ages out of our backups and operational logs within a further 30–35 days after live-system deletion.
  • Affiliate records: up to 2 years; accounting: up to 10 years (§147 AO); support: up to 2 years.
  • Consent & legal-acceptance records: life of account + 3 years.
  • Anonymised, aggregated insights: may be kept indefinitely.

10. Your rights

You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (Art. 15–21 GDPR). Withdrawing research consent ("Stop research" in the app's Privacy screen) opts you out of all brands and ends the earning relationship; you can opt back in per brand. Account deletion erases your data. To exercise any right, or to request a data export or object to processing, contact privacy@rewado.io. California residents (CCPA/CPRA): right to know, access, delete, correct, opt-out, and non-discrimination.

11. Your right to complain (supervisory authority)

You may lodge a complaint with a data-protection supervisory authority. Our competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany — www.ldi.nrw.de. You may also contact the authority in your EU country of residence.

12. People who appear in the content you share with us

The emails, messages, and screenshots you share can contain other people — brand senders, and occasionally a recipient, counterparty, or household member. We process that content to study brand marketing, not those individuals, and we minimise and redact third-party details in our pipeline. Because contacting each such person directly would involve disproportionate effort, we rely on the exemption in Art. 14(5)(b) GDPR, having weighed their interests and rights. If you appear in content shared with us and wish to exercise your rights, contact privacy@rewado.io.

13. Age requirement

Rewado is for adults only (18+). We do not knowingly enrol people under 18, and we take steps to keep minors' data out of what we process. If you believe someone under 18 has an account, contact privacy@rewado.io and we will remove it.

14. Cookies, device access & tracking (ePrivacy / TTDSG)

Non-essential cookies, trackers, and access to information on your device need your separate consent under the ePrivacy rules / TTDSG §25, in addition to a GDPR lawful basis.

  • Essential (no consent): the authentication / session cookie.
  • Non-essential (consent required): Mixpanel (product analytics), Intercom (support widget), Firebase (mobile analytics, crash & performance), Vercel Speed Insights (web-vitals).
  • Fonts are self-hosted — not trackers; no Google reCAPTCHA is used.

The full cookie/SDK inventory (names, durations, purposes) and the consent manager are delivered via the consent banner. [TBC — link the published cookie inventory once the cookie audit is complete (#528).]

15. How we notify you of changes

We may update this policy. For material changes we will notify you at least 14 days in advance, both in-app (a notice when you next open Rewado) and by email to your account address, with a short summary of what is changing and a link to the full text. Because a privacy policy is an information notice, there is nothing to "accept" — but where a change affects processing that relies on your consent, we will ask you to review and, where required, re-consent before that processing continues. Non-material updates are published here with a new version number and effective date.