Skip to main content
Monster Network

Monster Network

Privacy Policy

Last updated: 28 September 2026

This policy describes how Monster Network handles information for the Android app io.monsternetwork.app and the website https://monsternetwork.io. It matches the current app and API.

1. Who operates Monster Network

Monster Network operates the Android app and this website. A company registration number is not stated on this page. Privacy questions go to support@monsternetwork.io.

2. Scope

This policy covers member accounts, Node participation, reward records, and the public website. It does not describe a product that is not in the current app.

3. Information we process

  • Email address, used to create and sign in to a member account.
  • When a member chooses Sign in with Google: the Google subject identifier (sub), the verified email address, and the name Google returns with that sign-in.
  • A member identifier assigned by Monster Network.
  • Profile fields such as display name, language, locale, and time zone.
  • Email one-time codes, stored only as a hash, and session records.
  • Node identifier, device model, operating-system version, and app version.
  • Node credential identifiers. Private signing seeds stay on the device.
  • Play Integrity tokens sent to Monster Network for server-side checks.
  • Network type and country or region when needed to operate the service.
  • Approximate location, only in the case described below.
  • Wi-Fi network name, only in the case described below.
  • Journey and participation state.
  • Reward, wallet, and ledger records, including pending and available amounts.
  • Security, abuse-prevention, and diagnostic records needed to run the service.

4. How we use it

We use this information to create and authenticate accounts, operate Nodes, verify eligible participation, keep reward and ledger records, send service email, and protect the service. We do not sell personal information. We do not build an advertising profile.

5. Service providers

Sign-in and deletion codes are sent through the email delivery provider configured for the API. That mail path can use the Resend HTTPS API or SMTP. The public website is served over HTTPS. Google Play Integrity is used when the app asks Google to attest a device. Sign in with Google uses Google only to authenticate the member. Monster Network does not access Gmail, Drive, Contacts, or Calendar. The Android app does not include an advertising SDK or a third-party analytics SDK.

6. Device and Node information

When a device is enrolled as a Node, Monster Network processes the Node id, device and app details, and credential state. Credentials can be revoked. Detaching a Node removes the member binding. The private key material used to sign Node traffic is not uploaded.

7. Location and network information

The app does not ask for Location permission at launch, before sign-in, or merely because the Dashboard is opened. Location is requested only in context, for supported network-verification features, and only as a when-in-use permission. There is no background-location permission and no continuous location stream.

If Location permission is already granted, a Node work cycle may send coordinates that have been reduced to about one kilometer. The app rounds latitude and longitude to two decimal degrees and labels that payload APPROX_1KM. It does not send the unreduced GPS reading in that payload.

The signed Node heartbeat does not include the raw Wi-Fi network name. If the app needs an ISP name, it may send the Wi-Fi name to the Monster Network ISP-resolve API. A name that is only an unresolved Wi-Fi label is not copied into the network hint.

8. Authentication

Members can sign in with an email one-time code or with Google. The email code expires in about five minutes, can be tried a limited number of times, and is stored as a hash. Sign in with Google is used to authenticate the member, create a member account, link Google to an existing member after a separate email-code check, and protect the session. Monster Network stores the Google subject identifier as the Google identity. The email address is not used as that permanent identifier. Passkey controls in the app do not complete a real sign-in.

9. Rewards and ledger records

The app can show pending and available amounts and Journey state. Those are service records. Payouts are not enabled. This policy does not offer withdrawal, token exchange, or an investment.

10. Security

Member traffic to the production API uses HTTPS. One-time codes are not written into public pages.

11. Retention and deletion

You can ask us to close the member account. When deletion runs, access ends, profile fields are removed or replaced, Node bindings are detached, and Node credentials are revoked. Pending rewards may be forfeited to the network reward pool. Security, audit, and ledger records are kept so the network can prevent abuse and preserve reward integrity. We do not promise that every record is erased.

Start a request on the web at monsternetwork.io/account-deletion without installing the app. The Android app also has Settings → Delete account. Both paths use the same deletion process.

12. Choices

You can refuse Location and notification permission. Email sign-in and Google sign-in do not require Location permission. You can email support@monsternetwork.io about your information.

13. Children

Monster Network is not a child-directed service. We do not knowingly collect personal information from children.

14. Changes

If this policy changes, we will update this page and the date above.

15. Contact

Monster Network, https://monsternetwork.io, Android application id io.monsternetwork.app. Email support@monsternetwork.io.