Legal
Privacy Policy
Last updated: May 7, 2026
This Privacy Policy explains how Plypto Pte. Ltd. ("Plypto", "we", "us", "our") collects, uses, discloses, and protects personal data of visitors and players of the Plypto platform — including the website at plypto.space and the official Plypto Android application, which is a Trusted Web Activity wrapper around the same website (collectively, the "Platform").
By accessing or using the Platform you confirm that you have read and understood this Policy. If you do not agree with it, you must stop using the Platform. This Policy should be read together with our Terms of Use and Terms of Sale.
Controller & Scope
The data controller for personal data processed through the Platform is Plypto Pte. Ltd., a private limited company incorporated and registered in the Republic of Singapore.
This Policy applies to personal data processed in connection with: (a) the Plypto website at plypto.space; (b) the official Plypto Android application; (c) any related emails, support channels, and partner-portal interactions.
The Android application does not run a separate backend: it loads the live website inside Chrome via a Trusted Web Activity. As a result, the same data flows, cookies, and security model described here apply identically whether you use Plypto in a browser or in the app.
Plain-Language Summary
- We collect what we need to run the game safely: your account details, your gameplay state, technical telemetry, payment metadata (never the full card number), and a handful of attribution / analytics signals.
- We never sell your personal data.
- Plypto is not a bank, wallet, or exchange. We do not custody your private keys and we do not connect to your personal wallet beyond the address you supply for withdrawals.
- In-game Bitcoin (BTC) production is simulated: nothing on Plypto mines cryptocurrency on your device, in your browser, or on your behalf. The Platform does not run any cryptominer, hash function, or proof-of-work workload on your device.
- The Galactic Café uses protons only. Protons won at the café are non-withdrawable and have no cash value. There is no real-money gambling on the Platform.
- You can ask us to access, correct, export, or delete your data at any time — see Section 17.
Categories of Data We Collect
We process the following categories of personal data:
a. Account & identity data
Email address, pseudonym (player handle), planet hex, public planet number, role (USER / ADMIN / PARTNER / BOT), banned status, password hash (bcrypt — we never see your plain password), optional WebAuthn / passkey credentials, and the Google ID returned by Google during Sign-In if you log in with Google.
b. Gameplay & ledger data
Infrastructure deployments and levels, proton balance, BTC in-game balance and append-only BTC ledger entries (every credit / debit with kind and metadata), strike / defense / monthly earning aggregates, raid history (initiator, defender, outcome, loot), Galactic Café play log (stake, fair draw, resolved value, win factor, café fee rate and amount), Battle Strike Pass purchases and consumption, daily rewards run records, login timestamps and per-day session log entries.
c. Payment metadata
For each purchase we store a payment record referencing the external invoice (Coinremitter invoice id, 0xProcessing invoice id, Stripe Checkout Session id), the price displayed, the resolved BTC reference price, the payer's declared Bitcoin address (for crypto payments), the wallet address used to receive funds, the success / cancel status, and the webhook payload (sanitised). We never see or store your full card number, CVV, or your private wallet keys — card data is handled directly by Stripe in their PCI-DSS scope.
d. Technical & security data
IP address (transient — used at request time for routing, rate-limiting, abuse detection, and Cloudflare Turnstile CAPTCHA validation), user-agent string, request timestamps, authentication session tokens (HMAC-signed JWT cookies, never stored server-side), error logs, and webhook signatures.
e. Attribution & marketing data
Signed signup-attribution cookie capturing: partner id, origin user id (when sent by a B2B partner), referral code, and ad-network parameters (gclid, gad_campaignid, gbraid, wbraid, fbclid, msclkid, ttclid, utm_*). On account creation, that cookie is decoded and the resulting ad-campaign payload may be persisted on the user record. Newsletter opt-in flag and timestamp.
f. Communications & support
Messages you send to support, the contact-guest cookie used to deduplicate guest tickets, transactional emails sent to you (welcome, password reset, purchase receipts, withdrawal notifications, admin signup alerts) and any feedback you submit via /feedback.
Sources of the Data
- Directly from you: when you register, log in, play, send messages, or pay.
- From Google:when you choose "Sign in with Google", Google returns your email, name, and a stable identifier; we do not receive your Google password.
- From payment processors: Coinremitter, 0xProcessing, and Stripe send us webhook events about your invoices and Checkout Sessions.
- From URL parameters: ad-network and partner referral parameters captured by our middleware when you land on the site.
- Automatically: HTTP request metadata, cookies, and analytics events.
How and Why We Use Your Data
- Run the game. Authenticate you, persist your planet state, run the daily BTC rewards cron, resolve raids, settle Galactic Café plays, and process Battle Strike Pass purchases.
- Process payments. Issue invoices, verify webhooks, credit protons, audit transactions, and refund or charge-back when applicable.
- Process withdrawals. Validate your wallet address, run anti-fraud and AML/KYC checks where required, and disburse BTC.
- Secure the Platform. Detect and block fraud, abuse, multi-accounting, automation, and bot traffic; verify Cloudflare Turnstile CAPTCHA; validate webhook signatures.
- Support & communicate. Respond to support tickets, send transactional emails (sign-up welcome, purchase receipts, password reset), and deliver legal or service notifications.
- Analytics & improvement. Understand how the Platform is used so we can fix bugs and improve the game (PostHog, Vercel Analytics, optionally Google Analytics 4).
- Marketing attribution. Measure how new players found us (partner program, referral, ad campaign) and remit partner commissions correctly.
- Comply with the law. Tax, accounting, AML, and dispute-resolution obligations.
Legal Bases (GDPR)
Where the GDPR (or an equivalent regime) applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to operate the game, your account, and any paid features you choose to use.
- Legitimate interest (Art. 6(1)(f)) — fraud prevention, security, network and information integrity, debugging, defending against abuse, and basic product analytics. We balance these interests against your rights and offer opt-outs where required.
- Consent (Art. 6(1)(a)) — for marketing emails (when applicable), and for any non-essential cookies / advertising analytics where the jurisdiction requires opt-in consent.
- Legal obligation (Art. 6(1)(c)) — tax and accounting record-keeping, AML / KYC, and responses to lawful requests.
Analytics & Product Telemetry
Where enabled, we use the following analytics tools to understand usage patterns and improve the Platform:
- PostHog (product analytics, optional session replay) — events about page views, in-game actions, and errors. Configured via NEXT_PUBLIC_POSTHOG_KEY; can be disabled per-environment via NEXT_PUBLIC_POSTHOG_DISABLED.
- Vercel Analytics — privacy-focused traffic measurement that does not use cross-site cookies.
- Google Analytics 4 — only loaded in production when NEXT_PUBLIC_GA_ID is set. IP addresses are truncated by Google and we do not enable ad personalisation.
If you do not want to be measured by these tools, you can use your browser's built-in tracking protection, an extension that blocks third-party scripts, or a privacy-focused browser such as Brave or Firefox with strict tracking protection.
Service Providers (Sub-Processors)
We rely on the following data processors. Each of them only processes the data needed for its function and is bound by a data-processing agreement and / or its own enterprise terms.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Web & serverless hosting, CDN, basic analytics, deployment platform | Global edge, EU/US |
| MongoDB Atlas | Primary database (accounts, gameplay, ledger) | EU |
| Google LLC | Sign-In with Google (OAuth identity), Google Analytics (when enabled) | US / Global |
| Stripe, Inc. | Card payments for proton packs (Checkout Sessions + webhooks) | US / EU |
| Coinremitter | Bitcoin invoices and webhook processing | Global |
| 0xProcessing | Ethereum invoices and webhook processing | Global |
| Brevo (Sendinblue) | Transactional email delivery (welcome, receipts, etc.) | EU |
| Cloudinary | Hosting of game assets and partner / infrastructure imagery | US / Global |
| Cloudflare Turnstile | CAPTCHA / bot mitigation on sign-up and sensitive forms | Global |
| PostHog | Product analytics (when enabled) | EU/US (per project setting) |
| UptimeRobot | External uptime monitoring of public endpoints | Global |
We may add or replace processors over time; this list will be kept current and material additions will be highlighted in the changelog at the top of this page.
Payment Data
Plypto does not store card numbers, card CVVs, or wallet private keys. When you pay with a card, you are redirected to a Stripe-hosted Checkout Session and Stripe handles the card data inside its PCI-DSS scope. Plypto only receives the Checkout Session identifier, the amount, the currency, the success / cancel status, and a sanitised webhook payload.
For Bitcoin and Ethereum payments, the invoice is created and hosted by Coinremitter or 0xProcessing respectively. We receive the invoice identifier, the resolved transaction hash (when available), the amount, the wallet address used, and the webhook signature for verification.
Withdrawals are paid out to the Bitcoin address you provide. That address, along with the amount, status, and transaction identifier, is recorded for audit, accounting, and AML purposes.
International Data Transfers
Some of our processors are located outside the European Economic Area or the United Kingdom. Where personal data is transferred outside these jurisdictions, we rely on legally recognised transfer mechanisms such as the European Commission Standard Contractual Clauses, equivalent UK addenda, adequacy decisions where available, and the transfer-impact assessments published by the relevant providers. You may contact us for more information on any specific transfer.
Retention Periods
- Account data: kept while your account is active and for a reasonable period thereafter to handle disputes, fraud investigations, and legal obligations.
- Append-only ledger & payment records: retained for at least the duration required by Singaporean accounting and tax law (currently 5 years) and longer if required for an open dispute or investigation.
- Authentication session JWT: 30 days from issuance, after which you must sign in again.
- Signup-attribution cookie: up to ~13 months from set time, then automatically discarded by the browser.
- Server logs: short-term, typically 30–90 days unless preserved for an active investigation.
- Marketing attribution data on user records: kept for the lifetime of the account because it is needed to credit partner commissions retroactively.
When data is no longer needed we delete it or anonymise it (for example, by stripping personal identifiers from long-term aggregate ledger records).
Security
We apply industry-standard security practices including TLS in transit, at-rest encryption on managed databases, bcrypt password hashing, HMAC-signed session tokens, HMAC-signed attribution cookies, webhook signature verification (Stripe, Coinremitter, 0xProcessing), and least-privilege access controls on operational tooling. No system can be guaranteed to be 100% secure; we encourage you to use a strong unique password and enable a passkey when available.
If we ever experience a personal-data breach affecting you, we will notify the relevant supervisory authority and / or you, as required by applicable law.
Children
The Platform is strictly reserved for adults aged 18 and over (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to Plypto, please contact us and we will delete it.
Gameplay-Specific Disclosures
Galactic Café — protons only, non-withdrawable
The Galactic Café (roulette, roll-under, roll-identical, scratch cards) is an in-game entertainment annex. Stakes and prizes are denominated exclusively in protons, the in-game resource. Protons won at the Galactic Café are non-withdrawable: they cannot be exchanged for Bitcoin, fiat currency, or any other crypto-asset, and they cannot be redeemed against Plypto for cash. Their only use is to be reinvested into the in-game economy (building / upgrading infrastructure, buying optional in-game items priced in protons such as Battle Strike Passes). The Galactic Café is not a casino, not a betting service, and not a payment product.
Bitcoin production — simulated, not on-device mining
Plypto is a strategic simulation game. In-game BTC production accrues at server-side, deterministic rates determined by the infrastructure you have built, upgraded, and defended in the game. Plypto does not mine cryptocurrency on your device, in your browser, or on your behalf. The Platform never executes proof-of-work hashing loops, never uses your CPU / GPU for mining, and never requires you to install any kind of miner.
Withdrawable BTC balances correspond to settled in-game production credited by our server-side rewards pipeline, subject to the eligibility rules set out in our Terms of Use and Terms of Sale.
Plypto is not a wallet, exchange, or financial institution
Plypto does not custody your private keys, does not let you send arbitrary crypto-assets between users, does not provide brokerage or exchange services, and does not provide financial, investment, or tax advice. The only purpose for which we accept a Bitcoin address from you is to pay out your in-game earned BTC during a withdrawal request.
Android App-Specific Notes
The Plypto Android app is a Trusted Web Activity wrapper: under the hood it is the Chrome browser rendering plypto.space. As a result:
- No additional personal data is collected by the app itself beyond what the website would already collect in your browser.
- The app does not access your phone book, SMS, microphone, camera, precise location, files outside its sandbox, or installed apps list.
- Sign-in with Google in the app uses the same Google flow as in your browser and is processed by Google directly.
- Push notifications are off by default. If we add them, you will be asked for explicit consent the first time the feature is used.
- We do not run any mining, hashing, or compute-intensive background workload on your device.
Your Rights
Subject to applicable law, you have the following rights over your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): ask us to delete your account and personal data, subject to legal retention obligations and to settled ledger records that must remain auditable for tax / accounting purposes.
- Portability: receive a structured machine-readable export of the personal data you have provided.
- Restriction & objection: ask us to pause certain processing activities or object to processing based on our legitimate interest.
- Withdraw consent: where we rely on consent (for example, marketing emails), you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
- Lodge a complaint: you may lodge a complaint with the data-protection supervisory authority of your country of residence (Singapore: PDPC; EU: your local DPA; UK: ICO).
To exercise any of these rights, please contact us as described in Section 21. To prevent unauthorised disclosure, we may need to verify your identity before acting on your request. We aim to respond within 30 days.
Marketing Communications
Transactional emails (welcome, password reset, purchase receipts, withdrawal updates) are sent on the basis of our contract with you and cannot be opted out of without closing your account.
Marketing or product-update emails (when applicable) are only sent to users who have explicitly opted in. Each such email contains an unsubscribe link, and the corresponding newsletterOptIn flag on your account is updated accordingly.
Do Not Track & Global Privacy Controls
We do not currently respond to legacy Do Not Track signals (which lack a unified industry standard). We do, however, disable Google Ads personalisation features in our Google Analytics 4 configuration when GA4 is loaded, and we honour explicit opt-outs you make through the providers listed in Section 8.
Changes to This Policy
We may update this Policy from time to time. The date at the top of the page reflects the latest revision. Material changes will be communicated through in-game notifications or email. Your continued use of the Platform after the posting of a revised Policy constitutes acceptance of the changes.
Contact
For privacy-related questions, requests, or complaints, please reach out to our team:
Plypto Pte. Ltd.
Republic of Singapore
General privacy: privacy@plypto.space
Data protection: dpo@plypto.space
Support: plypto.space/support
By continuing to use Plypto, you confirm that you have read, understood, and agree to this Privacy Policy.