← Back to rewado.io

Privacy Policy

Controller: Axess Intelligence GmbH, Pilgrimstraße 6, 50674 Cologne, Germany.
Data protection contact: dpo@axessintelligence.com.
Contact for privacy requests: support@rewado.io or dpo@axessintelligence.com

1. Who we are and what Rewado does

Rewado is operated by Axess Intelligence GmbH. Rewado pays you rewards for taking part in market research: with your consent, we study the promotional emails brands send you and the promotional messages and screenshots you upload, and we sell pseudonymised, persona-level insights about brands' marketing to business customers. The companies that pay us are not necessarily the brands whose communications we study.

2. What data we collect

You provide / we collect from your use:

  • Account: email, hashed password, display name, optional phone.
  • Profile: country, language, preferences; demographic answers you give.
  • Connected email mailbox content — see §3.
  • Promotional messages and screenshots you submit — see §4.
  • Payout / verification data when you cash out.
  • Device & usage data: device type, OS, IP address, device identifiers, features used, timestamps, coarse (country-level) location.
  • Crash & error diagnostics: crash and non-fatal error reports (stack trace, device model, OS and app version, and a crash-reporter installation identifier stored on your device), plus technical records of failed app-to-server requests (method, host, path, status code, timing — no message content) so we can find and fix faults. See §7 and §14.
  • Consent records (what you agreed to, when, and the policy version).

From third parties: name/email from Google sign-in.

3. Connecting your email (Gmail)

  • You generate a Google app-specific password and enter it in the app. It is stored encrypted on your device and is not sent to our servers.
  • The app scans your mailbox on your device to find promotional messages. Senders are first classified as a company or a person — an on-device read of the message is part of that check, and it can include senders you have no relationship with. Only mail from allowlisted company senders goes on to be processed and kept for the research purpose in §5; mail from people is discarded, and other messages are not retained. We never receive or store your main Google password.
  • An app password technically grants broader mailbox access; we use it solely to scan for and process promotional mail.

4. Promotional messages, SMS & push notifications you share

Beyond email, you can earn by uploading screenshots of promotional messages you receive from brands — including marketing SMS and push notifications. You choose what to upload; we process only the promotional content you submit for the research purpose described in §5. Rewado does not read, intercept, or automatically capture your SMS or push notifications in the background: you take a screenshot yourself and submit it, and we process only that image. You decide, each time, what to share.

5. How we use your data, and the AI and people involved

  • Reward & account operation (contract).
  • Market research + profiling (your consent): we remove direct identifiers, then assign you to a pseudonymised persona (e.g. "lapsed viewer") inferred from signals in the emails/messages themselves. This is profiling. Business customers can see that a communication reached a given persona — never your name or identity.
  • No automated decisions with legal or similarly significant effect: rewards follow a fixed, per-brand rule for the content you share — not a profile-based judgment about you — and screenshot uploads are checked by a person. Art. 22 GDPR (solely automated decision-making) therefore does not apply.
  • AI processing: uploaded content and email content are processed by Google's Gemini models (via Google Cloud Vertex AI) and Google Cloud Vision (optical character recognition) to read the promotional content and extract offer details.
  • Human review: our trained review team, bound by confidentiality, quality-checks our work and verifies de-identification, and may see content before de-identification is complete.
  • Fraud prevention.

On "anonymisation": identifiers are removed from what business customers receive, but our internal research records remain linkable to you (pseudonymous) and therefore remain personal data under GDPR until truly anonymised.

6. Lawful bases (Art. 6 / Art. 9 GDPR)

  • Reward processing & account: contract (Art. 6(1)(b)).
  • Market research + persona profiling: your consent (Art. 6(1)(a), Art. 7), collected granularly and separately in-app, withdrawable anytime.
  • Where the communications you share reveal — or our persona profiling infers — special-category data (for example, gambling-related interests indicated by marketing from betting or casino brands): we rely on your explicit consent (Art. 9(2)(a)). You give this as a separate, explicit consent in the app — a dedicated checkbox, shown apart from your general research consent, that expressly names gambling & betting brands. This consent is optional. We ask for it just before your first email scan, and only if the brands active in your country actually include gambling or betting companies — otherwise you are never asked. Declining is a valid answer and does not limit your use of Rewado or your earning: if you decline, or have not answered yet, gambling and betting brands are simply excluded from the scan, so no special-category processing takes place. You can change the decision at any time in the app's Privacy screen. We do not attempt to infer, and do not derive, self-exclusion status, cooling-off periods, deposit limits, problem-gambling status, or your financial means/affordability from this content.

Why this consent is freely given. Taking part is voluntary and no service is gated behind it — Rewado is a paid research panel, not access-in-exchange-for-tracking. You may decline, or withdraw later, without losing anything you already have: withdrawal ends the ongoing arrangement for the future, and we do not claw back rewards you have already earned.

  • Sender triage and allowlist maintenance, fraud prevention, security, and crash & error diagnostics: our legitimate interests (Art. 6(1)(f)) in operating a working, secure service, documented in a balancing test. You may object at any time (§10). Separately, the crash reporter's storage on your device is addressed in §14.

7. Who receives your data (sub-processors)

We use vetted providers (sub-processors) under Art. 28 GDPR data processing agreements. Our full, current list — every provider, what it does, where it is located, and the transfer safeguard relied on — is maintained at rewado.io/subprocessors and updated whenever a provider changes, so it stays accurate without this policy being re-issued.

By category:

CategoryProviders
Content processing & AIGoogle Cloud Vertex AI (Gemini) & Cloud Vision; Anthropic (Claude); OpenAI
Email collection & renderingGoogle (Gmail); Oxylabs; Scrapfly
Storage, hosting & infrastructureNeon; Google Cloud Storage; Vercel; Dagster+; Pusher
Communication, support & diagnosticsResend; Intercom; Mixpanel; Google Firebase; Firebase Crashlytics; Sentry
Rewards & payoutsPayPal (payouts — acts as its own controller)

Business customers receive only pseudonymised, persona-level insights (with your direct identifiers such as name and email removed) — never your raw uploads, mailbox, or account data. We do not sell personal information and do not share it for cross-context behavioural advertising.

What the error monitors do and do not receive. The diagnostics sent from the app carry no message content: request bodies, cookies and query strings are stripped, sensitive headers are redacted, and anything that looks like an email address is masked before the report leaves your device. Where a fault happens on our servers while we are serving your request, the report can include your account identifier (an internal ID — not your name or email address); that is the only direct identifier either error-monitoring provider receives.

8. International transfers

Wherever possible we keep processing inside the EU/EEA — for example, our database is hosted in Frankfurt — so that no international transfer takes place, and we prefer EU-region options for our other providers where they are offered. Where processing outside the EU/EEA is unavoidable (for example certain US-based hosting or support services), we rely on an appropriate safeguard under Chapter V GDPR — the EU–US Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses (2021/914, Module 2) otherwise — together with additional technical and organisational safeguards; case-by-case transfer impact assessments for the providers concerned are being completed. Our current sub-processor list identifies the mechanism relied on for each provider.

9. Retention

  • Account data: while active + 30 days after deletion.
  • The pseudonymised research dataset: kept while your participation is live. When the relationship ends, we delete it after a 30-day grace window. (We may instead convert it into a genuinely anonymised set — but only once that anonymisation has been independently validated; until then, deletion is what happens.)
  • Raw mailbox / uploaded content (original emails, images, OCR text, detected-PII records): kept until the research insight has been extracted and verified, then for a further three months as a clarification window — questions about a specific item often surface weeks later — and then deleted. A shorter deadline overrides this: if you withdraw consent or ask us to erase your data, we delete the raw content promptly rather than waiting out the 90 days. Any special-category-derived attributes are kept for a shorter period than general profile data.
  • Backups and logs: the above content ages out of our backups and operational logs within a further 30–35 days after live-system deletion.
  • Sender-classification (triage) metadata: up to 30 days, then auto-purged — only a confirmed allowlist entry survives. The content of non-promotional messages is not retained at all (§3).
  • Crash & error diagnostics: up to 90 days — the standard retention window of both diagnostic providers — then automatically deleted.
  • Accounting records: up to 10 years (§257 HGB / §147 AO); support: up to 2 years.
  • Consent & legal-acceptance records: life of account + 3 years.
  • Anonymised, aggregated insights: may be kept indefinitely.

10. Your rights

You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (Art. 15–21 GDPR). Withdrawing research consent ("Stop research" in the app's Privacy screen) opts you out of all brands and ends the earning relationship; you can opt back in per brand. Account deletion erases your data. To exercise any right, or to request a data export or object to processing, contact support@rewado.io. We respond within one month (Art. 12(3) GDPR); if a request is complex we may extend that by up to two further months and will tell you why. California residents (CCPA/CPRA): right to know, access, delete, correct, opt-out, and non-discrimination.

11. Your right to complain (supervisory authority)

You may lodge a complaint with a data-protection supervisory authority. Our competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany — www.ldi.nrw.de. You may also contact the authority in your EU country of residence.

12. People who appear in the content you share with us

We aim to process company senders only, using an allowlist — a sender is classified as a company or a person, and mail from people is discarded rather than processed. Company senders are not personal data. Even so, the emails, messages, and screenshots you share can incidentally contain individuals — an individual sender address, or a person named or pictured in the content. We process that content to study brand marketing, not those individuals; such data is minimised and short-lived, and we redact third-party details in our pipeline. Because contacting each such person directly would involve disproportionate effort, we rely on the exemption in Art. 14(5)(b) GDPR, having weighed their interests and rights. If you appear in content shared with us and wish to exercise your rights, contact support@rewado.io.

13. Age requirement

Rewado is for adults only (18+). We do not knowingly enrol people under 18, and we take steps to keep minors' data out of what we process. If you believe someone under 18 has an account, contact support@rewado.io and we will remove it.

14. Cookies, device access & tracking (ePrivacy / TTDSG)

Non-essential cookies, trackers, and access to information on your device need your separate consent under the ePrivacy rules / TTDSG §25, in addition to a GDPR lawful basis.

This website (rewado.io) sets no cookies at all and makes no third-party requests — no analytics, no tag manager, no embedded widgets, and its fonts are served by us. The items below concern the Rewado app and our business-customer platform.

  • Essential (no consent): the authentication / session cookie.
  • Non-essential (consent required): Mixpanel (product analytics), Intercom (support widget), Firebase Analytics and Performance (mobile), Vercel Speed Insights (web-vitals).
  • Crash reporting (Firebase Crashlytics) has its own category, separate from product analytics, so declining optional analytics no longer switches off diagnostics. It writes to your device (an installation identifier and a local crash cache), so TTDSG §25 applies to it in its own right. In the app it is presented as a necessary-to-operate notice you acknowledge rather than a refusable consent — it cannot currently be declined or switched off in the app. Your acknowledgement is recorded, and nothing is collected before that record exists.
  • Sentry is not a tracker. It shares the crash-reporting category but stores nothing on your device, so §25 is not triggered; it appears in the sub-processor list in §7 instead.
  • Fonts are self-hosted — our sites and app serve their own font files, so no request for them reaches a third party and no IP address is disclosed that way. No Google reCAPTCHA is used.

In the app, the Privacy screen shows each of these categories and lets you change your choice at any time; the providers behind them are listed at rewado.io/subprocessors. On our business-customer platform the same choices are offered through its consent banner.

15. How we keep your data secure

We apply appropriate technical and organisational measures (Art. 32 GDPR): access controls on a least-privilege basis; separation of raw personal data from the customer-facing dataset; a two-stage de-identification process (automated, then human review) including pixel-level redaction of images; encryption in transit and at rest; audit logging of internal access; and processors selected under Art. 28 data processing agreements. Your Gmail app password stays encrypted on your device and never reaches our servers (§3).

16. How we notify you of changes

We update this policy as our processing changes. Material changes are communicated to you — in-app (a notice when you next open Rewado) and by email to your account address, with a short summary of what is changing and a link to the full text. Because a privacy policy is an information notice, there is nothing to "accept" — but where we rely on your consent, re-consent is sought on version changes before the affected processing continues. Non-material updates are published here with a new version number and effective date.