PRIVACY POLICY
REWORTH GAMES PROTOCOL
Last Updated: May 30, 2026
This Privacy Policy ("Policy") describes how the Reworth Games Protocol, operated by its designated Protocol Team ("Protocol Team," "we," "us," or "our"), collects, uses, stores, and protects information of users ("User," "you," or "your") who access and use the Platform and related services (collectively, the "Service").
This Policy is an integral part of and must be read in conjunction with our Terms of Use. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the data practices described herein.
Applicable Law: This Policy is governed by the laws of the Federative Republic of Brazil, including the General Data Protection Law (LGPD — Law No. 13.709/2018), the Brazilian Internet Civil Rights Framework (Marco Civil da Internet — Law No. 12.965/2014), and other applicable data protection regulations.
1. DATA CONTROLLER
The Protocol Team of the Reworth Games Protocol acts as data controller for all personal data collected through the Service and is responsible for determining the purposes and means of processing in accordance with the LGPD.
2. AGE RESTRICTIONS
Use of the Service is strictly prohibited for individuals under eighteen (18) years of age. We do not knowingly collect personal data from minors. If we become aware that a minor's data has been inadvertently collected, we will immediately delete it and terminate the associated Account.
Parents or guardians who believe a minor has provided personal data to the Service should contact us at [email protected].
3. INFORMATION WE COLLECT
3.1 Information You Provide
Google Account Data (Essential): Account creation and authentication are performed exclusively through Google Sign-In (OAuth 2.0). When you authenticate, we collect and store your Google account ID, full name, email address, and profile picture URL as provided by Google. This data is mandatory for Account creation, authentication, and delivery of personalized service features. By signing in with Google, you also authorize Google's own data practices, as described in Google's Privacy Policy.
Communication and Support Data: When you contact us, we collect your communication identifier (e.g., email address), the content of your messages, and any additional information you voluntarily provide.
KYC and Verification Data: The Protocol Team reserves the right to request identity verification data, which may include your full legal name, date of birth, government-issued identification (e.g., CPF, RG, CNH, passport), proof of address, and photographs. KYC may be required in the following circumstances: withdrawal requests exceeding specified thresholds; detection of suspicious transaction patterns, fraud, or multi-accounting; AML compliance obligations; or requests from law enforcement or regulatory authorities. Failure to provide requested KYC documentation may result in suspension of withdrawal privileges or Account termination.
3.2 Information Collected Automatically
Usage and Interaction Data: We automatically collect data about your use of the Service, including dates and times of access, session duration, games played, scores, features used, navigation patterns, and Referral Program activity. This data is essential for Platform operation, Prize distribution, fraud detection, and service improvement.
Technical and Device Data: We collect technical information including your IP address (which may be pseudonymized), browser type and version, operating system, device type, and user agent strings. This data is used for security monitoring, fraud detection, technical support, and service optimization.
Transaction and Economic Data: We maintain comprehensive records of all Platform economic activities, including Balance transactions, Coin acquisitions and expenditures, Prizes received, Referral Commissions, Service Fees, Vault interactions, withdrawal and deposit requests and status, marketplace transactions, and purchase history. This data is essential for executing the Terms of Use, processing manual withdrawals, fraud prevention, tax compliance, legal defense, and audit purposes. Financial and transaction records may be retained for extended periods as specified in Section 7.
3.3 Blockchain Data
All on-chain transactions — including USDC withdrawals, deposits, Smart Contract interactions, and gas fee payments — are public, permanent, and immutable by the inherent nature of blockchain technology. Once recorded on-chain, this data is publicly visible to anyone with access to blockchain explorers, cannot be modified or deleted by the Protocol Team or any other party, and may be indexed by third-party services outside our control. The Protocol Team has no control over privacy or visibility of data recorded on the blockchain.
The Protocol Team maintains off-chain records associating your Account with on-chain transaction data — including wallet addresses used for deposits and withdrawals, and transaction hashes — enabling operation of the Platform's economic model, Prize distribution, and audit purposes. While wallet addresses are public blockchain identifiers, when associated with your Account and usage patterns, they may constitute personal data subject to LGPD.
4. LEGAL BASIS FOR PROCESSING (LGPD)
We process personal data under the following legal bases established by LGPD (Article 7):
Contractual Execution (Art. 7, I): Processing necessary to provide the Service, including Account management, game functionality, Balance and Coins management, Prize distribution, Referral Program administration, and deposit and withdrawal processing.
Legitimate Interest (Art. 7, IX): Processing necessary for our legitimate interests, including fraud detection and prevention, security of Vault and Prizes Reserve funds held in custody, Platform security, Terms enforcement, service improvement, and business operations. Users' fundamental rights are respected through appropriate safeguards and transparency measures.
Legal Obligation (Art. 7, II): Processing necessary for compliance with Brazilian legal obligations, including tax record-keeping and reporting (Carnê-Leão, Receita Federal), AML/KYC requirements, law enforcement cooperation, and preservation of evidence for legal proceedings.
Consent (Art. 7, I — when applicable): For non-essential processing activities, we may rely on your explicit consent, which may be withdrawn at any time without affecting the lawfulness of prior processing.
5. HOW WE USE YOUR INFORMATION
Service Provision: Account creation and management, game functionality, Balance and Coins tracking, Prize allocation and daily distribution, Referral Commission calculation, withdrawal processing, and customer support.
Security and Compliance: Fraud and bot detection, security monitoring, manual review of withdrawal requests and high-value transactions, Terms enforcement, KYC/AML compliance, and fulfillment of Brazilian legal obligations including tax, consumer protection, and data protection regulations.
Communication: Transactional notifications, withdrawal and deposit status updates, security alerts, and support responses. We do not send marketing communications without explicit consent.
Service Improvement: Usage trend analysis, A/B testing, bug resolution, feature development, and generation of anonymized or aggregated statistics.
Financial and Tax Purposes: Maintaining financial records for tax compliance; generating reports for Brazilian tax authorities; documenting and separating Protocol Team compensation (20% of net Vault yield) from third-party funds held in custody (User funds, Vault capital, Prizes Reserve, Referral Commissions); and preserving evidence for audits or legal proceedings.
6. SHARING AND DISCLOSURE
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We may share information only in the following limited circumstances:
Service Providers: Trusted third-party providers who perform services on our behalf, including blockchain infrastructure and RPC providers, cloud hosting, analytics tools (with data minimization and anonymization where possible), and email service providers. These providers are contractually bound to protect your data, use it only for specified purposes, and comply with applicable data protection laws.
Legal and Regulatory Compliance: We may disclose information when required by law, including in response to valid court orders, requests from Brazilian law enforcement, tax authorities (Receita Federal), or regulatory agencies, and for cooperation with official investigations. We disclose only the minimum information necessary, unless broader disclosure is legally required.
Protection of Rights and Safety: We may disclose information to protect the rights, property, and safety of the Protocol Team, the Platform, its Users, and the integrity of Vault and Prizes Reserve funds held in custody — including in connection with investigating prohibited conduct under our Terms of Use.
Business Transfers: In the event of a restructuring, merger, acquisition, or sale of assets, your information may be transferred to the succeeding entity. We will notify affected Users before such transfer occurs and before their data becomes subject to a different privacy policy.
With Your Consent: We may share information with third parties when you provide explicit consent.
7. DATA RETENTION
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer period is required by applicable law.
Account Data: Active Account data is retained for the duration of the Account's activity. Inactive accounts (over 365 days without activity) may be deactivated and their data subjected to deletion, except for data subject to longer legal retention requirements. Data from terminated Accounts is retained for the duration required by legal obligations.
Transaction and Financial Data: Records of Balance history, Coin transactions, Prize distributions, Referral Commissions, Service Fees, deposits, and withdrawals may be retained for extended periods, potentially indefinitely, based on the following: Brazilian tax law requires financial record retention for a minimum of 5 years from the end of the reporting period (Lei nº 8.218/1991); accounting records may require retention of up to 10 years in certain circumstances; and records are preserved for the duration of applicable statutes of limitations for potential legal claims (generally 5–10 years under Brazilian law).
KYC and Verification Data: Retained for a minimum of 5 years after Account closure for AML compliance, or longer if required by ongoing legal obligations.
Communication and Support Data: Retained for up to 3 years for quality assurance, or longer if related to disputes or legal claims.
Technical and Usage Data: IP addresses and technical logs are generally retained for up to 12 months for security purposes, unless longer retention is required for fraud investigation or legal proceedings. Anonymized usage analytics may be retained indefinitely.
Blockchain Data: Data recorded on the blockchain is permanent and immutable. The Protocol Team has no ability to delete, modify, or anonymize on-chain data. Users acknowledge that blockchain records persist independently of this retention policy.
Upon expiration of applicable retention periods, personal data will be securely deleted or anonymized. Users may request earlier deletion of certain data by exercising their LGPD rights under Section 9, subject to mandatory retention requirements.
8. SECURITY MEASURES
The Protocol Team implements reasonable technical and organizational measures to protect personal data, including: HTTPS/TLS encryption for data in transit and encryption of sensitive data at rest; role-based access controls limiting data access to authorized personnel; multi-signature custody for User funds; manual security review of withdrawal requests; continuous monitoring for suspicious activity and unauthorized access; data minimization practices; and staff training on data protection obligations.
No internet-based service can guarantee absolute security. Users acknowledge that data transmission carries inherent risks and that the Protocol Team is not liable for security breaches resulting from circumstances beyond its reasonable control. Users are responsible for maintaining the security of their Google Account credentials and Platform Account.
In the event of a security breach that poses a risk to User rights, the Protocol Team will: assess and contain the breach; notify the ANPD if required by LGPD Article 48; and notify affected Users without undue delay, providing information on the nature of the breach, potential consequences, and measures taken.
9. YOUR RIGHTS UNDER LGPD
As a data subject under Brazilian law, you have the following rights in accordance with LGPD Articles 17–18:
Confirmation and Access (Art. 18, I–II): Confirm whether we process your personal data and access the data held about you, including processing purposes and retention periods.
Correction (Art. 18, III): Request correction of incomplete, inaccurate, or outdated data.
Anonymization, Blocking, or Deletion (Art. 18, IV): Request anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed without legal basis — subject to mandatory legal retention requirements, particularly for financial and transaction data.
Portability (Art. 18, V): Receive your personal data in a structured, commonly used, machine-readable format for transmission to another controller, where technically feasible. This right does not apply to anonymized data or to data recorded on the blockchain.
Information About Sharing (Art. 18, VI–VII): Receive information about entities with which your data has been shared and about the possibility of denying consent.
Objection and Revocation of Consent (Art. 18, VIII–IX): Object to processing based on legitimate interest, subject to demonstration of compelling grounds; or revoke consent previously given. Withdrawal of consent does not affect the lawfulness of prior processing and may affect the availability of certain Service features.
Review of Automated Decisions (Art. 20): Request review of decisions made solely through automated processing that affect your interests.
To exercise any of these rights, contact us at [email protected], clearly identifying yourself and the right(s) you wish to exercise. We will respond within the timeframe required by LGPD (generally 15 days per ANPD regulations), free of charge except for manifestly excessive or repetitive requests.
If you believe your data is not being processed in accordance with LGPD or this Policy, you may lodge a complaint with the Brazilian National Data Protection Authority (ANPD) at https://www.gov.br/anpd/.
10. INTERNATIONAL DATA TRANSFERS
While the Service operates primarily within Brazil, certain infrastructure components or service providers may be located outside Brazil. In such cases, the Protocol Team will ensure that adequate safeguards are in place as required by LGPD Article 33, relying on standard contractual clauses, adequacy decisions, or ANPD authorization as appropriate. Users acknowledge and consent to such transfers as necessary for the provision of the Service.
11. COOKIES AND TRACKING TECHNOLOGIES
The Platform may use cookies and similar technologies for essential Service functionality, user preference storage, usage pattern analysis, and fraud detection. Cookie types used include essential cookies (necessary for Service operation; cannot be disabled), functional cookies (enhanced functionality and personalization), and analytics cookies (usage understanding, with anonymization where possible). The Platform does not use third-party advertising or tracking cookies.
You may manage cookie preferences through your browser settings; however, disabling certain cookies may affect Service functionality.
12. THIRD-PARTY LINKS AND SERVICES
The Service may link to or integrate with third-party websites, applications, or DeFi protocols (including those used for Vault yield strategies). This Policy does not apply to third-party services. The Protocol Team does not endorse or assume responsibility for the privacy practices or performance of third-party services. We encourage Users to review the privacy policies of any third-party services accessed through the Platform.
13. CHANGES TO THIS POLICY
The Protocol Team may update this Policy at any time to reflect changes in data processing practices, applicable law, or Service operation. Changes become effective on the "Last Updated" date displayed at the top of this document. For material changes that substantially affect how we collect, use, or protect your data, we will provide notice through the Platform interface and, where possible, via email or in-Platform notification. Your continued use of the Service after such notice constitutes acceptance of the updated Policy.
14. LEGAL BASIS SUMMARY
For ease of reference, the following summarizes the primary legal bases for our key processing activities under LGPD (Article 7):
- Account management, Balance, and Transactions: Contractual Execution (Art. 7, I)
- Prize distribution and Referral Commissions: Contractual Execution (Art. 7, I)
- Fraud detection and security audits: Legitimate Interest (Art. 7, IX)
- KYC, AML, and financial record retention: Legal Obligation (Art. 7, II)
- Tax compliance and reporting: Legal Obligation (Art. 7, II)
- Usage analytics and service improvement: Legitimate Interest (Art. 7, IX)
- User communication: Contractual Execution (Art. 7, I)
15. CONTACT AND DATA PROTECTION INQUIRIES
For questions, requests, or complaints regarding this Policy or our data processing practices:
- General & Legal: [email protected]
- Player Support: [email protected]
While not currently required to appoint a formal Data Protection Officer under LGPD, the Protocol Team has designated responsible personnel for data protection matters, reachable through the contact above.
16. ACKNOWLEDGMENT
BY ACCESSING OR USING THE REWORTH GAMES PROTOCOL, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY IN ITS ENTIRETY, INCLUDING:
- The collection and processing of personal data as described in this Policy;
- The legal bases for processing specified in Section 4;
- The sharing of information in the limited circumstances described in Section 6;
- The retention periods specified in Section 7, including extended retention for tax and legal compliance;
- The public, permanent, and immutable nature of blockchain-recorded transactions;
- The manual processing model for withdrawals and security reviews;
- The Protocol Team's right to implement KYC/AML procedures as described in Section 3.1;
- International data transfers as described in Section 10; and
- Your rights under LGPD as described in Section 9.
Document Version: 3.1 Effective Date: May 30, 2026 Jurisdiction: Federative Republic of Brazil Governing Law: LGPD (Law No. 13.709/2018) and Marco Civil da Internet (Law No. 12.965/2014)