Privacy Policy
Last Updated: September 2026 • Effective Date: September 2026
1. Our Core Privacy Invariant
At
Traditional ad-tech networks force developers to inject tracking SDKs directly into utility applications—harvesting location data, device identifiers, and background telemetry.
2. The Three-Tier Architecture
To understand our privacy posture, it is important to distinguish the three layers of the
A. Client Host Applications (e.g. AutoSpot, Offline Utilities)
Applications integrating the Adxiety Client SDK never request network permissions (android.permission.INTERNET is strictly absent). Host apps do not collect, process, transmit, or share any personal data, identifiers, or analytics. Pass validation happens 100% offline via local IPC in under 1 millisecond.
B. The Adxiety Companion Application
The companion app acts as a quarantined sandbox. When a user explicitly chooses to watch a sponsored break, the companion app requests a rewarded video ad via real-time mediation demand partners (e.g., AppLovin MAX, Unity Ads, Liftoff). The companion app does not collect user names, phone numbers, contact lists, or location data. Upon completion of an ad, it mints a cryptographic ECDSA P-256 attention proof locally on the user's device.
C. The Developer Portal (adxiety.com)
The web portal provides developers with an interface to register apps, configure lease durations, and manage payout settings. It is governed specifically by the developer data terms below.
3. Information Collected via the Developer Portal
When you interact with the developer portal at adxiety.com, we may collect:
- Account Identification: When signing in via Google OAuth, we receive your email address, display name, and unique Google OAuth identifier to authenticate you and associate your registered applications.
- Application Configuration: Android package names (e.g.,
com.autospotapp), application labels, pass lease durations, stacking caps, and developer payout preferences. - API Telemetry: Edge servers record anonymized request counts and response status codes to ensure API availability and enforce rate limits. No personal browsing histories are tracked or sold.
4. Cookies, Local Storage & Do Not Track Signals
The
CalOPPA & GPC Signals: Because our website does not engage in cross-site tracking or third-party behavioral profiling, our web services do not alter their operation upon receipt of browser "Do Not Track" (DNT) or Global Privacy Control (GPC) signals.
5. Third-Party Processors & Infrastructure
We rely on reputable infrastructure providers that comply with global data protection standards:
- Cloudflare, Inc.: Hosts our edge functions, global CDN, and edge database (Cloudflare Pages & D1) with industry-standard TLS encryption.
- Google Identity Services: Provides secure authentication for developer sign-in without Adxiety ever storing your raw account passwords.
- Third-Party Demand & Mediation Networks: Certified demand partners (including AppLovin MAX, Unity Ads, and Liftoff) are integrated strictly within the optional companion hub for rewarded video delivery. Demand partner data processing is governed by their respective privacy policies and SDK disclosures.
6. European Data Protection Rights (GDPR & UK GDPR)
For developers and users located in the European Economic Area (EEA) and the United Kingdom, we process personal data in accordance with the following framework:
- Lawful Basis for Processing: We process developer account credentials under Contractual Necessity (Art. 6(1)(b) GDPR) to deliver portal services and manage dynamic edge rules. Server request metrics and IP logs are processed under Legitimate Interests (Art. 6(1)(f) GDPR) to maintain system availability and prevent malicious abuse. In the optional companion app, rewarded ad delivery by certified demand partners (AppLovin, Unity, Liftoff) is governed by User Consent (Art. 6(1)(a) GDPR) managed via standard Android Consent Management Platforms (CMP).
- Data Retention Schedule: Developer account records and configuration metadata are retained for the active duration of your account. Upon receiving an account closure or data deletion request, all associated identifiers and configuration endpoints are permanently purged within 30 days. Proof-of-attention tokens generated in the companion app exist strictly on the user's device and are never sent to or stored on our servers.
- Your Statutory Rights: You have the right to access, rectify, port, or request erasure of your developer data, or object to specific processing activities.
- Right to Lodge a Complaint: If you believe our data processing violates statutory regulations, you have the right under Art. 77 GDPR to lodge a complaint with your local Data Protection Supervisory Authority (such as the CNIL in France, the BfDI in Germany, or the Information Commissioner's Office in the United Kingdom).
Because client applications embedding our offline SDK collect zero consumer data, there are no consumer logs or personal identifiers stored on our servers to query, export, or delete.
7. California Privacy Rights (CCPA & CPRA)
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- No Sale or Sharing of Portal Data: We do not sell, rent, or share personal information collected through this website with third parties for monetary or other valuable consideration, nor do we disclose it for cross-context behavioral advertising.
- No Sensitive Personal Information: We do not collect or process sensitive personal information (such as precise geolocation, financial credentials, racial or ethnic origin, or health data).
- Companion App Ad Controls: In the optional companion application, rewarded video ads are served by third-party ad networks (e.g., AppLovin MAX, Unity Ads, Liftoff), which may use device advertising identifiers (GAID) according to their own privacy disclosures. Users can opt out of personalized ad targeting or reset their device advertising identifier at any time through their Android system settings (
Settings > Google > Ads).
8. Children's Privacy (COPPA)
The
We do not knowingly solicit, collect, or process personal information from children under the age of 13 (or under 16 in applicable European jurisdictions). If we become aware that personal information of a child has been inadvertently submitted to our portal, we will take immediate steps to delete such data from our databases.
9. Contact Information
For questions about this Privacy Policy or to submit a data deletion request, please reach out to us at:
Adxiety Privacy Inquiries
Email: privacy@adxiety.com