PLYPTO
ChronicleDoctrineCrypto & cashoutEconomyWhitepaperSign in

They trust us

Partners

  • clubmining.io

© 2026 Plypto. All rights reserved.

Affiliate ProgramFeedbackSupportStatusPrivacyTerms of SaleTerms of UseWhitepaper

Legal

Privacy Policy

Last updated: May 7, 2026

This Privacy Policy explains how Plypto Pte. Ltd. ("Plypto", "we", "us", "our") collects, uses, discloses, and protects personal data of visitors and players of the Plypto platform — including the website at plypto.space and the official Plypto Android application, which is a Trusted Web Activity wrapper around the same website (collectively, the "Platform").

By accessing or using the Platform you confirm that you have read and understood this Policy. If you do not agree with it, you must stop using the Platform. This Policy should be read together with our Terms of Use and Terms of Sale.

Table of Contents

  1. 01 Controller & Scope
  2. 02 Plain-Language Summary
  3. 03 Categories of Data We Collect
  4. 04 Sources of the Data
  5. 05 How and Why We Use Your Data
  6. 06 Legal Bases (GDPR)
  7. 07 Cookies & Similar Technologies
  8. 08 Analytics & Product Telemetry
  9. 09 Service Providers (Sub-Processors)
  10. 10 Payment Data
  11. 11 International Data Transfers
  12. 12 Retention Periods
  13. 13 Security
  14. 14 Children
  15. 15 Gameplay-Specific Disclosures
  16. 16 Android App-Specific Notes
  17. 17 Your Rights
  18. 18 Marketing Communications
  19. 19 Do Not Track & Global Privacy Controls
  20. 20 Changes to This Policy
  21. 21 Contact
01

Controller & Scope

The data controller for personal data processed through the Platform is Plypto Pte. Ltd., a private limited company incorporated and registered in the Republic of Singapore.

This Policy applies to personal data processed in connection with: (a) the Plypto website at plypto.space; (b) the official Plypto Android application; (c) any related emails, support channels, and partner-portal interactions.

The Android application does not run a separate backend: it loads the live website inside Chrome via a Trusted Web Activity. As a result, the same data flows, cookies, and security model described here apply identically whether you use Plypto in a browser or in the app.

02

Plain-Language Summary

  • We collect what we need to run the game safely: your account details, your gameplay state, technical telemetry, payment metadata (never the full card number), and a handful of attribution / analytics signals.
  • We never sell your personal data.
  • Plypto is not a bank, wallet, or exchange. We do not custody your private keys and we do not connect to your personal wallet beyond the address you supply for withdrawals.
  • In-game Bitcoin (BTC) production is simulated: nothing on Plypto mines cryptocurrency on your device, in your browser, or on your behalf. The Platform does not run any cryptominer, hash function, or proof-of-work workload on your device.
  • The Galactic Café uses protons only. Protons won at the café are non-withdrawable and have no cash value. There is no real-money gambling on the Platform.
  • You can ask us to access, correct, export, or delete your data at any time — see Section 17.
03

Categories of Data We Collect

We process the following categories of personal data:

a. Account & identity data

Email address, pseudonym (player handle), planet hex, public planet number, role (USER / ADMIN / PARTNER / BOT), banned status, password hash (bcrypt — we never see your plain password), optional WebAuthn / passkey credentials, and the Google ID returned by Google during Sign-In if you log in with Google.

b. Gameplay & ledger data

Infrastructure deployments and levels, proton balance, BTC in-game balance and append-only BTC ledger entries (every credit / debit with kind and metadata), strike / defense / monthly earning aggregates, raid history (initiator, defender, outcome, loot), Galactic Café play log (stake, fair draw, resolved value, win factor, café fee rate and amount), Battle Strike Pass purchases and consumption, daily rewards run records, login timestamps and per-day session log entries.

c. Payment metadata

For each purchase we store a payment record referencing the external invoice (Coinremitter invoice id, 0xProcessing invoice id, Stripe Checkout Session id), the price displayed, the resolved BTC reference price, the payer's declared Bitcoin address (for crypto payments), the wallet address used to receive funds, the success / cancel status, and the webhook payload (sanitised). We never see or store your full card number, CVV, or your private wallet keys — card data is handled directly by Stripe in their PCI-DSS scope.

d. Technical & security data

IP address (transient — used at request time for routing, rate-limiting, abuse detection, and Cloudflare Turnstile CAPTCHA validation), user-agent string, request timestamps, authentication session tokens (HMAC-signed JWT cookies, never stored server-side), error logs, and webhook signatures.

e. Attribution & marketing data

Signed signup-attribution cookie capturing: partner id, origin user id (when sent by a B2B partner), referral code, and ad-network parameters (gclid, gad_campaignid, gbraid, wbraid, fbclid, msclkid, ttclid, utm_*). On account creation, that cookie is decoded and the resulting ad-campaign payload may be persisted on the user record. Newsletter opt-in flag and timestamp.

f. Communications & support

Messages you send to support, the contact-guest cookie used to deduplicate guest tickets, transactional emails sent to you (welcome, password reset, purchase receipts, withdrawal notifications, admin signup alerts) and any feedback you submit via /feedback.

04

Sources of the Data

  • Directly from you: when you register, log in, play, send messages, or pay.
  • From Google:when you choose "Sign in with Google", Google returns your email, name, and a stable identifier; we do not receive your Google password.
  • From payment processors: Coinremitter, 0xProcessing, and Stripe send us webhook events about your invoices and Checkout Sessions.
  • From URL parameters: ad-network and partner referral parameters captured by our middleware when you land on the site.
  • Automatically: HTTP request metadata, cookies, and analytics events.
05

How and Why We Use Your Data

  • Run the game. Authenticate you, persist your planet state, run the daily BTC rewards cron, resolve raids, settle Galactic Café plays, and process Battle Strike Pass purchases.
  • Process payments. Issue invoices, verify webhooks, credit protons, audit transactions, and refund or charge-back when applicable.
  • Process withdrawals. Validate your wallet address, run anti-fraud and AML/KYC checks where required, and disburse BTC.
  • Secure the Platform. Detect and block fraud, abuse, multi-accounting, automation, and bot traffic; verify Cloudflare Turnstile CAPTCHA; validate webhook signatures.
  • Support & communicate. Respond to support tickets, send transactional emails (sign-up welcome, purchase receipts, password reset), and deliver legal or service notifications.
  • Analytics & improvement. Understand how the Platform is used so we can fix bugs and improve the game (PostHog, Vercel Analytics, optionally Google Analytics 4).
  • Marketing attribution. Measure how new players found us (partner program, referral, ad campaign) and remit partner commissions correctly.
  • Comply with the law. Tax, accounting, AML, and dispute-resolution obligations.
06

Legal Bases (GDPR)

Where the GDPR (or an equivalent regime) applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to operate the game, your account, and any paid features you choose to use.
  • Legitimate interest (Art. 6(1)(f)) — fraud prevention, security, network and information integrity, debugging, defending against abuse, and basic product analytics. We balance these interests against your rights and offer opt-outs where required.
  • Consent (Art. 6(1)(a)) — for marketing emails (when applicable), and for any non-essential cookies / advertising analytics where the jurisdiction requires opt-in consent.
  • Legal obligation (Art. 6(1)(c)) — tax and accounting record-keeping, AML / KYC, and responses to lawful requests.
07

Cookies & Similar Technologies

We use a small number of first-party cookies that are strictly necessary or directly related to operating the game:

  • authjs.session-token / __Secure-authjs.session-token — your authenticated session JWT (HTTP-only, secure).
  • plypto_signup_attribution — HMAC-signed payload that lets us correctly credit a partner / ad campaign / referrer when you sign up.
  • plypto_contact_guest — random UUID set on /support so guests can have a consistent ticket thread.
  • plypto_footer_variant — UI preference flag for the in-app footer style.
  • Third-party cookies / SDK identifiers may also be set by the analytics and CAPTCHA providers listed in Sections 8 and 9.

You can clear or block cookies in your browser settings. Please note that blocking the session cookie will sign you out and prevent you from using authenticated features.

08

Analytics & Product Telemetry

Where enabled, we use the following analytics tools to understand usage patterns and improve the Platform:

  • PostHog (product analytics, optional session replay) — events about page views, in-game actions, and errors. Configured via NEXT_PUBLIC_POSTHOG_KEY; can be disabled per-environment via NEXT_PUBLIC_POSTHOG_DISABLED.
  • Vercel Analytics — privacy-focused traffic measurement that does not use cross-site cookies.
  • Google Analytics 4 — only loaded in production when NEXT_PUBLIC_GA_ID is set. IP addresses are truncated by Google and we do not enable ad personalisation.

If you do not want to be measured by these tools, you can use your browser's built-in tracking protection, an extension that blocks third-party scripts, or a privacy-focused browser such as Brave or Firefox with strict tracking protection.

09

Service Providers (Sub-Processors)

We rely on the following data processors. Each of them only processes the data needed for its function and is bound by a data-processing agreement and / or its own enterprise terms.

ProviderPurposeRegion
VercelWeb & serverless hosting, CDN, basic analytics, deployment platformGlobal edge, EU/US
MongoDB AtlasPrimary database (accounts, gameplay, ledger)EU
Google LLCSign-In with Google (OAuth identity), Google Analytics (when enabled)US / Global
Stripe, Inc.Card payments for proton packs (Checkout Sessions + webhooks)US / EU
CoinremitterBitcoin invoices and webhook processingGlobal
0xProcessingEthereum invoices and webhook processingGlobal
Brevo (Sendinblue)Transactional email delivery (welcome, receipts, etc.)EU
CloudinaryHosting of game assets and partner / infrastructure imageryUS / Global
Cloudflare TurnstileCAPTCHA / bot mitigation on sign-up and sensitive formsGlobal
PostHogProduct analytics (when enabled)EU/US (per project setting)
UptimeRobotExternal uptime monitoring of public endpointsGlobal

We may add or replace processors over time; this list will be kept current and material additions will be highlighted in the changelog at the top of this page.

10

Payment Data

Plypto does not store card numbers, card CVVs, or wallet private keys. When you pay with a card, you are redirected to a Stripe-hosted Checkout Session and Stripe handles the card data inside its PCI-DSS scope. Plypto only receives the Checkout Session identifier, the amount, the currency, the success / cancel status, and a sanitised webhook payload.

For Bitcoin and Ethereum payments, the invoice is created and hosted by Coinremitter or 0xProcessing respectively. We receive the invoice identifier, the resolved transaction hash (when available), the amount, the wallet address used, and the webhook signature for verification.

Withdrawals are paid out to the Bitcoin address you provide. That address, along with the amount, status, and transaction identifier, is recorded for audit, accounting, and AML purposes.

11

International Data Transfers

Some of our processors are located outside the European Economic Area or the United Kingdom. Where personal data is transferred outside these jurisdictions, we rely on legally recognised transfer mechanisms such as the European Commission Standard Contractual Clauses, equivalent UK addenda, adequacy decisions where available, and the transfer-impact assessments published by the relevant providers. You may contact us for more information on any specific transfer.

12

Retention Periods

  • Account data: kept while your account is active and for a reasonable period thereafter to handle disputes, fraud investigations, and legal obligations.
  • Append-only ledger & payment records: retained for at least the duration required by Singaporean accounting and tax law (currently 5 years) and longer if required for an open dispute or investigation.
  • Authentication session JWT: 30 days from issuance, after which you must sign in again.
  • Signup-attribution cookie: up to ~13 months from set time, then automatically discarded by the browser.
  • Server logs: short-term, typically 30–90 days unless preserved for an active investigation.
  • Marketing attribution data on user records: kept for the lifetime of the account because it is needed to credit partner commissions retroactively.

When data is no longer needed we delete it or anonymise it (for example, by stripping personal identifiers from long-term aggregate ledger records).

13

Security

We apply industry-standard security practices including TLS in transit, at-rest encryption on managed databases, bcrypt password hashing, HMAC-signed session tokens, HMAC-signed attribution cookies, webhook signature verification (Stripe, Coinremitter, 0xProcessing), and least-privilege access controls on operational tooling. No system can be guaranteed to be 100% secure; we encourage you to use a strong unique password and enable a passkey when available.

If we ever experience a personal-data breach affecting you, we will notify the relevant supervisory authority and / or you, as required by applicable law.

14

Children

The Platform is strictly reserved for adults aged 18 and over (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to Plypto, please contact us and we will delete it.

15

Gameplay-Specific Disclosures

Galactic Café — protons only, non-withdrawable

The Galactic Café (roulette, roll-under, roll-identical, scratch cards) is an in-game entertainment annex. Stakes and prizes are denominated exclusively in protons, the in-game resource. Protons won at the Galactic Café are non-withdrawable: they cannot be exchanged for Bitcoin, fiat currency, or any other crypto-asset, and they cannot be redeemed against Plypto for cash. Their only use is to be reinvested into the in-game economy (building / upgrading infrastructure, buying optional in-game items priced in protons such as Battle Strike Passes). The Galactic Café is not a casino, not a betting service, and not a payment product.

Bitcoin production — simulated, not on-device mining

Plypto is a strategic simulation game. In-game BTC production accrues at server-side, deterministic rates determined by the infrastructure you have built, upgraded, and defended in the game. Plypto does not mine cryptocurrency on your device, in your browser, or on your behalf. The Platform never executes proof-of-work hashing loops, never uses your CPU / GPU for mining, and never requires you to install any kind of miner.

Withdrawable BTC balances correspond to settled in-game production credited by our server-side rewards pipeline, subject to the eligibility rules set out in our Terms of Use and Terms of Sale.

Plypto is not a wallet, exchange, or financial institution

Plypto does not custody your private keys, does not let you send arbitrary crypto-assets between users, does not provide brokerage or exchange services, and does not provide financial, investment, or tax advice. The only purpose for which we accept a Bitcoin address from you is to pay out your in-game earned BTC during a withdrawal request.

16

Android App-Specific Notes

The Plypto Android app is a Trusted Web Activity wrapper: under the hood it is the Chrome browser rendering plypto.space. As a result:

  • No additional personal data is collected by the app itself beyond what the website would already collect in your browser.
  • The app does not access your phone book, SMS, microphone, camera, precise location, files outside its sandbox, or installed apps list.
  • Sign-in with Google in the app uses the same Google flow as in your browser and is processed by Google directly.
  • Push notifications are off by default. If we add them, you will be asked for explicit consent the first time the feature is used.
  • We do not run any mining, hashing, or compute-intensive background workload on your device.
17

Your Rights

Subject to applicable law, you have the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): ask us to delete your account and personal data, subject to legal retention obligations and to settled ledger records that must remain auditable for tax / accounting purposes.
  • Portability: receive a structured machine-readable export of the personal data you have provided.
  • Restriction & objection: ask us to pause certain processing activities or object to processing based on our legitimate interest.
  • Withdraw consent: where we rely on consent (for example, marketing emails), you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
  • Lodge a complaint: you may lodge a complaint with the data-protection supervisory authority of your country of residence (Singapore: PDPC; EU: your local DPA; UK: ICO).

To exercise any of these rights, please contact us as described in Section 21. To prevent unauthorised disclosure, we may need to verify your identity before acting on your request. We aim to respond within 30 days.

18

Marketing Communications

Transactional emails (welcome, password reset, purchase receipts, withdrawal updates) are sent on the basis of our contract with you and cannot be opted out of without closing your account.

Marketing or product-update emails (when applicable) are only sent to users who have explicitly opted in. Each such email contains an unsubscribe link, and the corresponding newsletterOptIn flag on your account is updated accordingly.

19

Do Not Track & Global Privacy Controls

We do not currently respond to legacy Do Not Track signals (which lack a unified industry standard). We do, however, disable Google Ads personalisation features in our Google Analytics 4 configuration when GA4 is loaded, and we honour explicit opt-outs you make through the providers listed in Section 8.

20

Changes to This Policy

We may update this Policy from time to time. The date at the top of the page reflects the latest revision. Material changes will be communicated through in-game notifications or email. Your continued use of the Platform after the posting of a revised Policy constitutes acceptance of the changes.

21

Contact

For privacy-related questions, requests, or complaints, please reach out to our team:

Plypto Pte. Ltd.
Republic of Singapore

General privacy: privacy@plypto.space
Data protection: dpo@plypto.space
Support: plypto.space/support

By continuing to use Plypto, you confirm that you have read, understood, and agree to this Privacy Policy.