Security
How we protect your account, your documents and your money.
Every page, sign-in and upload travels over HTTPS with modern TLS. Identity documents, payment proofs and QR images live in private storage that is never publicly listable — files are served through short-lived signed links only.
The database enforces row-level access: you can only read and change your own profile, missions, wallet, documents and conversations. Staff access is limited to the customers assigned to them, and administrator actions run through audited, permission-checked functions.
Sign in with email and password, Apple or Google. Passwords are stored only as salted hashes, sessions are short-lived and refreshed automatically, password changes require your current password, and password resets are delivered by one-time email links.
Mission timers are set and enforced on our servers, so they cannot be altered from a browser. Every submission, payment and withdrawal is reviewed by a person before money moves, and duplicate accounts, automated submissions or fabricated evidence lead to suspension.
Administrative actions — balance adjustments, approvals, rejections, verification decisions — are written to an immutable audit log that cannot be edited or deleted. Errors and unusual activity are monitored continuously.
Our data practices
- • We collect only what the service needs: name, email, phone (optional), profile photo and — where payouts require it — an identity document.
- • Identity documents are visible to reviewers only, are never shared with other members, and can be deleted on request once verification is complete.
- • Payment details you receive are generated per request, for you alone, and are not shared between members.
- • We never ask for your password, one-time codes or wallet recovery phrases. No member of our team will ever request them in chat.
- • Third-party access is limited to our hosting, database and email providers, each bound by their own data-protection terms.
Keeping your own account safe
- • Use a password you do not use anywhere else, or sign in with Apple or Google.
- • Never share your sign-in details, even with someone claiming to be support.
- • Check that payment details came through your in-app payment request before sending anything.
- • Sign out on shared devices.
Reporting a problem
If you believe your account has been accessed by someone else, or you have found a weakness in the platform, tell us immediately through the in-app support chat. Reports are treated confidentially and acted on as a priority.