Legal
Privacy Policy
Last updated: 13 September 2026
On this page
1. Scope · 2. Partner data · 3. End-user device data · 4. What we never collect · 5. How we use data · 6. Legal bases · 7. Sharing · 8. Retention · 9. Your rights · 10. Security · 11. ContactThis Privacy Policy explains how ipsterr ("we", "us") processes information in connection with the ipsterr SDK monetization program (the "Program"): both for the developers and companies who join it ("Partners") and for the users of Partner apps whose devices participate ("Participants").
1. Scope
The Program lets a Partner embed our SDK in their app. When a Participant gives explicit consent, their device shares a portion of its idle internet bandwidth, acting as a residential exit point for traffic from our customers. This policy covers data we process to operate that network. It does not cover a Partner's own app beyond the SDK, or how our customers use the network — Partners remain responsible for their own privacy notices to their users.
2. Information we collect from Partners
When you apply to and use the Program, we collect:
- Application details — app or company name, contact email, app store link or website, estimated monthly active users, primary user regions, and anything you add to your message.
- Account & payout details — the partner key we issue, and the payment details you provide to receive payouts (e.g. a wallet address or bank/e-wallet identifier).
- Usage & earnings — aggregate figures we measure for your integration: active devices, bytes relayed, countries and computed earnings.
3. Information processed from Participant devices
Only after a Participant opts in, and only what is technically necessary to relay traffic and pay fairly:
- IP address of the device's internet connection — this is inherent to routing network traffic.
- Approximate location and network derived from that IP: country, and the network operator / ASN. These are read from the connection by our servers, never claimed by the app.
- Connection metadata — device type category (e.g. mobile vs. TV), and coarse connection state used to decide when it is appropriate to run.
- Traffic volume — the number of bytes relayed, which is how earnings are metered.
- A device identifier assigned by us (via a signed token) to distinguish one participating device from another. It is specific to the Program.
4. What we never collect
The SDK relays network bandwidth. It is not a data-collection tool. We do not access, read, store or sell: your browsing history or the contents of your traffic; personal files, photos, messages or contacts; precise GPS location; microphone or camera; app usage analytics; or account credentials on the device.
5. How we use information
- To operate the network: route customer traffic through consenting devices.
- To meter usage and calculate and make payouts to Partners.
- To assess IP quality and quarantine datacenter, VPN or flagged addresses so they are never used or paid — protecting the network's integrity and Partners' honest earnings.
- To prevent fraud and abuse, and to comply with legal obligations.
6. Legal bases (GDPR)
Where the GDPR or similar laws apply, we rely on: consent (the Participant's explicit opt-in, which can be withdrawn at any time); performance of a contract (our agreement with Partners); and legitimate interests (operating and securing the network, and preventing fraud), balanced against individuals' rights.
7. How information is shared
- With network customers — a consenting device serves as an exit point for a customer's traffic, so the device's IP is visible to the destinations that traffic reaches, as with any proxy. We do not disclose a Participant's identity, and customers are bound by acceptable-use terms.
- With service providers — infrastructure and payment providers who process data on our behalf under contract.
- For legal reasons — where required by law or to protect rights, safety and the integrity of the network.
We do not sell personal information in the ordinary meaning of that term.
8. Retention
We keep usage and earnings records for as long as needed to run the Program, make and evidence payments, and meet legal and tax obligations, then delete or aggregate them. When a Participant withdraws consent, their device stops participating and associated operational identifiers are retired.
9. Your rights & choices
Participants can withdraw consent at any time from within the host app, which immediately stops participation. Depending on your location, you may have rights to access, correct, delete or object to the processing of your personal data, and to lodge a complaint with a supervisory authority. Because we hold very little that identifies an individual, we may ask for information to locate the relevant records. Partners can request access to or deletion of their account data by contacting us.
Children. The Program is not directed to children, and Partners must not enable it on apps directed to children or knowingly for users below the age of digital consent in their jurisdiction.
10. Security & international transfers
We use technical and organizational measures appropriate to the limited data we hold, including encrypted transport and server-side authorization. Data may be processed in countries other than yours; where required, we use appropriate safeguards for such transfers.
11. Changes & contact
We may update this policy; material changes will be reflected by the "last updated" date and, where appropriate, notice to Partners. Questions or requests: privacy@ipsterr.com.