Privacy Policy for BitMatch

Effective and last updated: 24 August 2026

Privacy summary. BitMatch uses account, device, gameplay, rewards, subscription, advertising, analytics, and optional Crypto Coach data to provide and secure the app. Crypto Coach is an AI-powered educational feature. Before BitMatch sends a Coach request to OpenAI, it asks for explicit, versioned consent. If you consent, your message and minimized, relevant Coach context may be sent to OpenAI to generate a response. You may decline or later revoke this consent and continue using the rest of BitMatch and non-AI Coach features. Advertising and Firebase Analytics are enabled only as allowed by the privacy choices resolved through Google's User Messaging Platform. BitMatch does not sell your personal data.

1. Who We Are and Scope

BitMatch is operated by Xhavasoft, based in Albania ("Xhavasoft," "BitMatch," "we," "us," or "our"). Xhavasoft is responsible for the personal data described in this Privacy Policy.

This Policy applies to the BitMatch mobile application, its backend services, the Crypto Coach feature, the public account-deletion page, and related support interactions. It does not apply to websites, wallets, exchanges, app stores, or other services operated independently by third parties.

2. Information We Collect

2.1 Account and contact information

2.2 Gameplay, rewards, withdrawals, and subscriptions

BitMatch stores the wallet's point-reset timestamp and calculates the next scheduled reset date to operate the rewards program. All unredeemed point categories reset to zero after 24 weeks on the scheduled date shown in Wallet. Earning, spending, playing, signing in, or watching ads does not postpone this date. Complete eligibility and redemption conditions are described in the BitMatch Rewards Rules made available in the app.

2.3 Crypto Coach information

If you use Crypto Coach, we may collect and generate:

Never submit wallet secrets. Do not enter a seed or recovery phrase, private key, wallet password, API key, authentication code, government ID, or other highly sensitive information into Crypto Coach or the URL scanner. Safety filters are designed to block or redact certain secrets, but no filter can be guaranteed to detect every sensitive value.

2.4 Device, technical, advertising, and analytics information

2.5 Information from third parties and public sources

We may receive subscription and purchase status from Google Play; AI-generated output from OpenAI; delivery and device information from Firebase Cloud Messaging; advertising and analytics information from Google services and configured advertising partners such as Vungle/Liftoff Monetize; and public market, blockchain-network, fee, gas, or risk data from sources such as CoinGecko, Etherscan, and mempool.space. Server requests for general market or network signals are not intended to include your direct identity.

3. How We Use Information

We use personal data to:

4. How Crypto Coach and Third-Party AI Work

Crypto Coach uses generative AI to provide educational explanations and app-supported next steps. Opening Coach Home, using lessons, or using other non-AI Coach screens does not grant AI consent. Before the first provider-backed request, BitMatch presents an explicit disclosure for the current provider and policy version. You may choose "Not now" and continue using the rest of BitMatch. Revoking consent blocks future external AI requests but does not by itself erase data already processed; the deletion controls in Section 9 are separate.

If you grant consent and submit a Coach request, BitMatch may send OpenAI: the current message after safety filtering; your goal, experience level, risk tolerance, time budget, and relevant onboarding state; aggregate roadmap, lesson, quiz, nudge, and safety context; bounded recent conversation or memory summaries; approved educational sources and bounded read-only market, fee, or risk tool results; a scanned domain and BitMatch's local risk result; and saved-watchlist count, chain, and masked addresses. Model settings such as the selected model and output limits are also sent.

BitMatch does not intentionally send OpenAI your internal numeric user ID, raw Coach thread or database run ID, name, email address, Binance-linked phone number, purchase token, push token, password, authentication code, identity document, full public watchlist address, or the path, query, or fragment of a scanned URL. Full watchlist addresses remain available to the authenticated BitMatch app where required. The standalone URL scanner processes the submitted URL on BitMatch's server and stores only a one-way hash, normalized domain, and required result metadata; the AI tool receives the domain and local result rather than the full URL. Recognized secrets, contact details, wallet addresses, tokens, and raw URLs are redacted again at the provider boundary.

The current BitMatch backend is configured to use the OpenAI API as its third-party AI provider. OpenAI processes the submitted information to return AI output and to monitor for abuse and security. BitMatch sends chat-completions requests with application-state storage disabled. Under OpenAI's standard API data controls, API inputs and outputs are not used to train OpenAI models unless the API customer explicitly opts in, and abuse-monitoring logs for chat completions may be retained by OpenAI for up to 30 days unless an approved alternative retention control applies. See OpenAI's API data controls and Privacy Policy.

BitMatch may use redacted, minimized, aggregated, or de-identified Coach interactions to test and improve its own safety, quality, retrieval, evaluation, and future Coach models or datasets only when your current AI consent is valid and your Coach-improvement opt-out is not enabled. Export controls remove recognized emails, tokens, full wallet addresses, seed phrases, private keys, raw thread identifiers, and URLs. Access to non-public review or curation tools is restricted to authorized personnel. AI-response report comments, report excerpts, analytics free text, and administrator review notes are not sent to OpenAI. We do not intentionally provide BitMatch API content to OpenAI for training its general-purpose models without first updating our disclosures and obtaining any permission required by law or app-store rules.

AI output can be incomplete, outdated, inaccurate, or unsuitable. Crypto Coach is for education and safety awareness only. It is not financial, investment, legal, tax, or professional advice; it does not guarantee that a website is safe; and it must not be treated as a promise of profit or protection from loss. BitMatch does not use Coach output to make decisions that produce legal or similarly significant effects about you.

5. When We Share Information

We do not sell or rent personal data. We may disclose information as follows:

Recipient Information and purpose
OpenAI Consent-based, redacted Coach prompts, minimized relevant context and tool results, and generated responses, to provide, secure, and monitor the AI service. The minimized categories and exclusions are described in Section 4.
Google Firebase App-instance, device, consent-permitted structural usage and diagnostics, and push-delivery information for analytics, reliability, and Cloud Messaging. Firebase Analytics is enabled only when the resolved privacy choices permit it.
Google AdMob / Google Mobile Ads and mediation partners, including Vungle/Liftoff Monetize IP address, general location inferred from IP, device/account identifiers, ad and app interactions, consent signals, and diagnostics for eligible advertising, measurement, and fraud prevention.
Google Play Product, purchase token, subscription, trial, renewal, and entitlement information to process and verify in-app subscriptions and restore purchases.
Reward fulfillment providers, including Binance when used Your Binance-linked phone number, requested amount, voucher or fulfillment reference, and request status as needed to complete a withdrawal you request.
Transactional email provider Email address and a short-lived, one-time account-deletion or password-reset link where you request those services.
Infrastructure and operational providers Information necessary for hosting, database, security, communications, monitoring, and technical support, under contractual and confidentiality obligations.
Authorities, advisers, or transaction parties Information required by law or reasonably necessary to protect rights and safety, investigate abuse or fraud, handle claims, or complete a merger, financing, reorganization, or sale subject to appropriate safeguards.

Third-party services process information under their own terms and privacy notices. For Google services, see the Google Privacy Policy and How Google uses information for advertising.

6. Legal Bases for Processing

Where the laws of the European Economic Area, United Kingdom, Albania, or another jurisdiction require a legal basis, we rely on one or more of the following:

7. Retention

We retain data only for as long as reasonably necessary for the purposes described above, including security, dispute resolution, fraud prevention, and legal obligations. The current retention schedule is:

Data Typical retention
Coach chat turns and conversation content Approximately 90 days, after which expired turns are deleted and old thread content is scrubbed by scheduled cleanup.
Coach agent runs, traces, and tool-step data Approximately 90 days, after which detailed steps are deleted and conversation content in run records is scrubbed.
Reusable Coach experience summaries Approximately 180 days.
AI-response reports and review audit Approximately 180 days. Reports contain a category, redacted optional comment, bounded redacted assistant excerpt, references, status, and authorized review history rather than a copy of the full conversation.
URL-scan history Approximately 90 days. History stores a one-way input hash, normalized domain, and bounded result metadata rather than the full submitted URL.
Backend Coach analytics events Approximately 180 days. Event metadata is bounded and allowlisted; raw Coach messages and secret-like fields are rejected.
Daily AI usage quotas Approximately 400 days. These records contain aggregate usage and cost counts rather than prompts.
Push delivery records and inactive push devices Delivery-attempt records are retained for approximately 90 days. Inactive device registrations are retained for approximately 30 days. Active registrations remain while needed to deliver notifications you have enabled.
Fine-tune/evaluation reviews and snapshot manifests Approximately 180 days. The production application does not automatically upload a fine-tuning dataset to OpenAI. Any separately approved exported artifact requires its own controlled retention and deletion process.
Revoked or outdated AI consent records Approximately 365 days. A current valid consent remains while needed to provide and audit your choice.
OpenAI standard API abuse-monitoring logs Up to 30 days under OpenAI's standard controls, subject to OpenAI's stated legal and safety exceptions.
Coach profiles, roadmaps, lesson and quiz progress, nudges, and public watchlist addresses Generally while the account is active or until no longer needed for the stated purpose, unless you delete the item, disable the related feature, or request account/data deletion.
Account, reward, and subscription records The active point balance resets to zero under the 24-week reward policy. A scheduled point reset does not itself delete the account, gameplay history, reward history, withdrawal records, transaction records, or subscription records. Those records are retained while the account is active and afterward only as needed for accounting, security, fraud prevention, disputes, and legal or regulatory obligations. Account deletion removes the BitMatch subscription entitlement and purchase-token data but does not remove Google Play's own transaction records or cancel billing.
Pseudonymized withdrawal ledger after account deletion Up to 2,555 days (seven years) for accounting reconciliation, fraud prevention, and dispute handling. BitMatch removes the user ID and replaces the raw voucher code and Binance-linked phone number with purpose-separated keyed values; the amount, status, and timestamps remain until scheduled deletion. These retained records are pseudonymous, not anonymous.
Deletion-security records A consumed deletion-link receipt is retained for up to one day, keyed request-rate buckets for up to two days, and a keyed deleted-session marker for up to 31 days. They do not retain the raw email, IP address, user ID, or deletion token.

Deletion from active systems may not immediately remove limited data from encrypted backups. Backups are protected and overwritten or deleted through normal retention cycles. Aggregated or de-identified information that no longer identifies you may be retained longer.

8. Your Choices and Rights

Depending on where you live, you may have the right to request access, correction, deletion, restriction, objection, or portability of your personal data; withdraw consent; opt out of certain sharing or targeted advertising; and lodge a complaint with a competent data-protection authority.

You may also:

To exercise a privacy right, email bitmatch-support@xhavasoft.com. We may need to verify your identity and account ownership before completing a request.

9. Account and Data Deletion

You can permanently delete your BitMatch account in the Android app under Settings > Privacy & AI > Delete BitMatch account. The in-app flow requires your current BitMatch password and the exact confirmation phrase shown in the app. If you cannot use the app, open BitMatch's public Delete your BitMatch account page and request a short-lived, one-time verification link at the email address on the account. The public form gives the same response whether or not an account exists and never asks you to send a password, authentication code, identity document, seed phrase, or private key.

Deletion removes your profile and sign-in data, wallet points and transactions, rewards, BitMatch subscription entitlement and purchase-token data, password-reset data, push devices and deliveries, and account-linked Crypto Coach data. Coach deletion includes your profile and AI consent, conversations and assistant responses, agent traces and experience summaries, AI-response reports, roadmaps, lesson and quiz progress, nudges, saved public watchlist addresses, URL-scan history, analytics events, and AI usage quotas. BitMatch also clears user-specific local app data after successful in-app deletion. Deletion stops future Coach data from being sent to OpenAI.

BitMatch may retain the limited pseudonymized withdrawal ledger and short-lived deletion-security records for the periods and purposes described in Section 7. Pending withdrawal requests are cancelled. Data already processed by OpenAI, Google, advertising partners, email providers, or other service providers remains subject to their applicable retention, security, and legal requirements. Deletion from active BitMatch systems may not immediately remove protected backup copies, which are overwritten or deleted through normal backup cycles and are not restored for ordinary use.

Deleting BitMatch does not cancel a subscription billed by Google Play. Account deletion remains available while a subscription is active. You must separately manage or cancel billing through Google Play subscriptions.

10. Security

We use technical and organizational measures designed to protect personal data, including HTTPS/TLS in transit, hashed account passwords, authentication controls, role-based access for administrative Coach and report-review tools, provider allow-lists, data minimization and boundary redaction, retention controls, and safety checks intended to prevent secrets from being processed. No system or transmission method is completely secure, and we cannot guarantee absolute security.

11. International Data Transfers

Xhavasoft is based in Albania, and service providers may process data in the United States, the European Economic Area, and other countries where they or their subprocessors operate. These countries may have different data-protection laws. Where required, we use or require recognized safeguards such as adequacy decisions, standard contractual clauses, contractual confidentiality and security duties, or another lawful transfer mechanism.

12. Children and Teen Users

BitMatch is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Users under 18 should use BitMatch only with permission from a parent or legal guardian, and financial, reward, or subscription features may be restricted based on local law. If you believe a child provided personal data without the required permission, contact us so we can investigate and delete it where appropriate.

13. Changes to This Policy

We may update this Privacy Policy when our features, providers, or legal obligations change. We will update the date above and provide additional in-app or email notice when a change is material or consent is required.

14. Contact Us

Xhavasoft
Albania
Email: bitmatch-support@xhavasoft.com