BL APPS MANAGEMENT AB, a Swedish company with company registration number (org.nr) 559275-3932 (“BL Apps”, “Earnly”, “we”, “our” or “us”), is the controller responsible for the processing of your personal data described in this policy. Our registered address is Bagartorpsringen 78, 170 65 Solna, Sweden. This privacy policy concerns you who register an account and become an Earnly user.
We care about and value your privacy. Through this privacy policy we want to give you clear information about how we process your personal data, who we share it with, and what rights you have. If you have any questions, or wish to exercise any of your rights, you can contact us at any time at support@blmapp.se.
1. The personal data we process and why
We process your personal data for the following general purposes:
- To create and administer your Earnly account;
- To build a basic profile so we can show offers that are relevant to you;
- To provide offerwall game offers and rewarded tasks;
- To provide third-party surveys;
- To run features such as the daily check-in, goal progress and the leaderboard;
- To administer your withdrawals of virtual coins via PayPal or, in Sweden, via Swish;
- To send you notifications and important service messages;
- To send you, if you have linked an email address, occasional emails about Earnly and about our other apps, for example new offers, features or app launches; you can opt out of these marketing emails at any time via the unsubscribe link in every such email;
- To reward you for referring friends to Earnly;
- To detect and prevent fraud, abuse and misuse of our service;
- To provide customer support; and
- To comply with our legal obligations and handle possible legal claims.
A detailed, purpose-by-purpose description (including exactly which data we use, our lawful basis and how long we keep it) is set out in the tables in Section 6.
2. The personal data we collect
Information you give us
- Account information. When you first open Earnly we create a guest account for you automatically, using only a device identifier and, where you have consented, your advertising ID. You do not need to provide your name, email address or any other personal data to start using the app; your guest account is given an automatically generated display name (for example “Player1234”). If you later choose to link a Google account, which is required only if you want to withdraw rewards, we use Google Sign-In only and receive your name, email address and your Google profile picture (as a link to the image) from Google. We never see or store a password.
- Profile information (optional). If you choose to complete the optional “Complete profile” task, you provide your gender and your year of birth. We store the year only, not your full date of birth and not a calculated age.
- Payment information. Your PayPal email address, collected when you link PayPal or request a withdrawal, so we can send your payment. When you link PayPal we also receive from PayPal your name, your PayPal account verification status and, where PayPal provides it, your postal address. We use these to confirm your identity for payouts and to help prevent fraud. If you are in Sweden and choose a Swish payout, we collect the Swedish mobile number you have connected to Swish and your Swedish personal identity number (personnummer); Swish requires both so that the payment reaches the right person. We store them encrypted and use them only to send your payouts and to prevent fraud.
- Support messages. If you contact our in-app support, we keep the messages you send us and our replies, so we can help you and keep a record of the conversation. Support conversations that have been closed for more than 180 days are deleted automatically. If our support team enables photo attachments for your conversation, you can also choose to send screenshots; they are stored as part of the conversation and are deleted together with it.
- Identity verification (KYC). If your account is selected for identity verification, either due to suspected fraud or as a random spot-check, you may be asked to provide a photo of a government-issued identity document and a selfie with a handwritten note. See Section 6.11 for full details, including what you may cover on the document and how long we keep these photos.
Information we collect automatically
- Device & technical data: a device identifier, your advertising ID (GAID), IP address, approximate country, device model and operating system, the app version, your time zone and mobile carrier.
- Anti-fraud device signals. To protect the rewards system for everyone, when you sign in we also collect a persistent device identifier derived from your device's built-in content-protection (DRM) module. This identifier can persist across app reinstalls and a factory reset, and we use it only to recognise the same physical device so we can prevent repeat abuse, such as creating many accounts from a single device. We also collect your SIM and mobile-network country, your device region, and basic device-security state, namely whether developer mode or USB debugging is switched on and whether the app is running as a duplicated or cloned instance. These signals are used only to detect and prevent fraud.
- App usage data: to operate our game based reward offers, our offerwall partner uses Android Usage Access to collect the list of apps installed on your device and how long and how often you use them. This is used to confirm that you completed a rewarded game offer and to recommend offers that are relevant to you. We also read that list ourselves, to detect and prevent fraud. We look only at apps that are not part of your device's system software, and we use the list to recognise device farms (many accounts whose devices carry an identical set of apps) and apps used to automate or duplicate Earnly. We do not use this list for advertising or to build an interest profile, and we do not read it at all if you declined our offerwall partner in the consent screen.
- Activity: the offers, surveys and tasks you complete, the coins you earn and spend, your daily check-ins, your leaderboard standing, and your withdrawal history.
- Notification token: a push token issued by your device, used to deliver notifications (only if you allow notifications).
- Sign-in restore: the app keeps a copy of your session token (the code that keeps you signed in; it is not your password) in Google Play services Block Store on your device, so you stay signed in when you move to a new phone or restore your phone from a backup. If your device has a screen lock, this copy is included in your Google account backup with end-to-end encryption, so Google cannot read it. Only the Earnly app can read it back. The copy is deleted when you sign out or delete your account.
- Diagnostics data: technical information about how the app runs on your device, such as device model, operating system and app version, session timestamps, time zone, mobile carrier and similar stability information. We collect this to keep the app working, reliable and secure, and our notification provider collects it to deliver notifications (see Section 4). Optional crash reporting and analytics are separate and run only if you consent (see Section 7).
- Advertising & analytics data (only if you consent): the ads you are shown and interact with (including rewarded ads you choose to watch for extra coins), and basic app usage and crash-diagnostic events. These are described in Section 7 and are switched off unless you allow them.
Are you required to provide your data?
Some data is necessary to provide the service. A guest account only needs a device identifier, so you can start using Earnly without providing any personal details. However, you cannot withdraw rewards without linking a Google account, you cannot receive a PayPal payout without a PayPal email, and you cannot receive a Swish payout without the Swedish mobile number connected to your Swish account and your personnummer. The optional profile task is entirely your choice; you can use Earnly without completing it. Where data is required to perform our contract with you or to meet a legal obligation, this is indicated in the tables in Section 6.
3. Age requirement
Earnly is a real-money rewards service and is intended only for users who are at least 18 years old. By creating an account you confirm that you are 18 or older. The optional profile task additionally checks that the birth year you provide corresponds to an age of 18 or above.
We do not knowingly collect personal data from anyone under 18, and never from children under 13. If we become aware that we have collected personal data from someone under 18, we will take steps to delete that information and close the account.
4. Who we share your data with
We do not sell or rent your personal data. We share limited personal data with categories of service providers and partners so that the app can function. We share only what is necessary for each purpose.
Categories of recipients
| Category of recipient | Data shared | Purpose |
|---|---|---|
| Hosting & IT infrastructure providers (processors acting on our instructions) | Account and activity data, as needed for secure operation | To host the app, database and reward images and keep the service running securely |
| Sign-in / identity provider | The sign-in identifier needed to authenticate you | To let you sign in securely with Google |
| Offerwall & rewarded-offer partners |
| To show and verify rewarded game offers and to recommend offers that better match you |
| Game-offer partner (AffiliateOS) |
| To attribute the game you installed and the milestones you reach to your account, so your coins can be credited, and to prevent fraudulent rewards |
| Survey providers | A user identifier and limited profile attributes used for matching | To match you with surveys and to credit your reward once a survey is completed |
| Advertising provider (Google AdMob) |
| To show ads (rewarded, native and banner) and to verify the extra coins you earn for watching a rewarded ad. Shown only if you consent (see Section 7) |
| Analytics & diagnostics provider (Google Firebase) | App and device usage events, a pseudonymous installation identifier, device and diagnostic data, and crash reports | To measure how the app is used and to detect and diagnose crashes and errors. Active only if you consent (see Section 7) |
| Payment provider | For PayPal payouts: your PayPal email address and the payout amount. For Swish payouts (Sweden): your Swish mobile number, your Swedish personal identity number (personnummer) and the payout amount, sent to the Swish payment system (operated by Getswish AB) | To deliver your withdrawal |
| Notification provider | Your push notification token, a user identifier used to target notifications to your account, notification interaction events such as opens and clicks, app session data, and device and app diagnostics collected by the notification SDK (device model, operating system and app version, time zone, mobile carrier, an SDK or app identifier and session timestamps) | To deliver notifications to your device |
| Device-integrity / anti-fraud provider | A device-integrity attestation and related technical signals | To verify the app and device are genuine and to prevent fraud |
| Authorities, advisors or acquirers | Only where legally required, to defend legal claims, or in a business transfer (see Section 15) | To meet legal obligations and protect our rights |
We share your data with these recipients only when it is necessary for the purpose described, and our processors are bound by contracts that require them to protect your data and use it only on our instructions.
5. Where your data is processed and international transfers
We and our processors process your personal data primarily within the EU/EEA. However, some of our partners (in particular offerwall partners, survey providers and certain hosting/infrastructure providers) may process data outside the EU/EEA, including in the United States.
When we transfer your personal data outside the EU/EEA, we do so on the basis of an adequacy decision from the European Commission, the European Commission’s Standard Contractual Clauses, or other appropriate safeguards required by applicable data protection law. You can contact us at support@blmapp.se for more information about these safeguards.
6. Detailed description of our processing
The tables below describe, for each purpose, why we process your personal data, which data we process, our lawful basis under the GDPR, and how long we keep the data.
6.1 To create and administer your account
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To create your account, let you sign in securely, keep track of the coins you earn and spend, and communicate with you about your account. |
| Performance of our contract with you (your Earnly membership). | Until you delete your account (see Section 9). |
6.2 To build your profile and show relevant offers
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To recommend offers and surveys that better match you, including via the optional profile task. |
| Our legitimate interest in showing you relevant offers. Where your gender and year of birth are shared with offerwall partners, that sharing is covered by your acceptance of this policy at sign-up; you can avoid it by not completing the optional profile task. | Until you delete your account. |
6.3 To provide offerwall offers, surveys and in-app reward features
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To show offerwall game offers and surveys, verify that you completed an offer or survey, credit your coins, and run features such as the daily check-in, goal progress and the leaderboard. |
| Performance of our contract with you, and our legitimate interest in operating and securing these reward features. | Until you delete your account. |
6.4 To administer your withdrawals via PayPal or Swish
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To convert your coin balance into a PayPal or Swish payment, send the payment, and keep track of your withdrawal status. |
| Performance of our contract with you. We process your Swedish personal identity number only because Swish requires it to deliver the payment securely to the right person, which is clearly justified by the purpose of the payment. Records of payments made are also kept to comply with bookkeeping law (see 6.7). | Until you delete your account; payment records are kept for up to 7 years for accounting purposes. |
6.5 To send you notifications
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To send you occasional marketing emails about Earnly and about our other apps, for example new offers, features or app launches. |
| Our legitimate interest in marketing our own services to our existing users (so-called soft opt-in). Every marketing email contains an unsubscribe link; if you opt out, we stop these emails immediately. Essential service emails about your account are not affected. | Until you opt out of marketing emails or delete your account. |
| To send push notifications about rewards, new offers and service updates, and to send essential account-related messages. |
| Your consent for promotional notifications (granted via your device permission, withdrawable at any time in your device or app settings); our legitimate interest / contract for essential service messages. | Until you delete your account or disable notifications. |
6.6 To detect and prevent fraud
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To verify your identity and device, prevent duplicate or fraudulent accounts, recognise device farms operating many accounts, check for VPN/proxy use, enforce country eligibility, and protect the integrity of the rewards system for all users. |
| Our legitimate interest in protecting our service, our users and ourselves against fraud and abuse. | Until you delete your account. Security logs may be kept for a limited period for security purposes. |
6.7 To handle legal claims and meet accounting obligations
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To establish, exercise or defend legal claims, and to keep accounting records of the payments we make. |
| Compliance with a legal obligation (Swedish bookkeeping legislation); and our legitimate interest in defending against and bringing legal claims. | Payment/accounting records: until the end of the seventh year after the financial year they relate to. Claim-related data: for the duration of the dispute. |
6.8 To show ads and reward you for watching rewarded ads
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To display ads (rewarded, native and banner), to verify and credit the extra coins you earn for choosing to watch a rewarded ad, and to control how often ads are shown. |
| Your consent, given through our consent management platform (see Section 7). You can withdraw it at any time. | Until you delete your account or withdraw your consent. |
6.9 To measure app usage and stability (analytics and crash reporting)
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To understand how the app is used so we can improve it, and to detect, diagnose and fix crashes and errors. |
| Your consent, given through our consent management platform (see Section 7). You can withdraw it at any time. | Kept for a limited period, in aggregated or pseudonymised form; until you withdraw your consent. |
6.10 To operate the community feed
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To show a community feed inside the app in which your approved cashouts and your milestones (such as reaching a new tier or a check-in streak) are shown to other users as social proof, and to let users like these posts. A post shows only a masked version of your display name (only the first part of the name is shown and the rest is hidden), your chosen cartoon avatar, your tier and basic activity stats (level, streak and games played). We never show your real full name, your email address or your Google profile picture. Only approved cashouts appear; pending or failed withdrawals are never shown. The feed never contains any free text written by users. |
| Our legitimate interest in operating engaging social-proof features that show the service genuinely pays its users. You can avoid appearing in the feed by not requesting withdrawals, and deleting your account removes your posts and likes. | Until you delete your account, which removes your feed posts and likes. |
6.11 To verify your identity (KYC)
| Purpose | Personal data | Lawful basis | Retention |
|---|---|---|---|
| To verify your identity before processing withdrawals or rewards, either when we detect signs of fraud or abuse, or as a routine randomly selected spot-check. This protects the rewards system and ensures payouts reach their rightful owner. |
| Performance of our contract with you (processing your withdrawal) and our legitimate interest in preventing fraud and abuse of the rewards system. | Verification photos are deleted within 30 days after the verification is completed. We keep only a record of the verification outcome (approved/rejected and the date) until you delete your account, and where needed to defend legal claims. |
7. Advertising ID, tracking and automated decisions
Advertising identifier and third-party SDKs
We use third-party SDKs and services for specific features. These include an offerwall / rewarded-offer provider (which serves the in-app game offers), third-party survey providers, a push-notification provider, Google services for sign-in and security, and Google services for advertising and measurement. We show ads through Google AdMob (rewarded ads that you can choose to watch for extra coins, native ads and banner ads), and we use Google Firebase for analytics and crash reporting. When you choose to watch a rewarded ad, we send Google a user identifier and a reward reference so the extra coins can be verified and credited server-side. Our offerwall partner uses Android Usage Access to measure which apps you install and play and for how long, so it can credit your playtime rewards and recommend offers that are relevant to you. The main advertising-related identifier we use is your device advertising ID (GAID). You can reset your advertising ID, or limit ad personalisation, at any time in your device settings.
Your advertising and analytics choices (consent)
Advertising, analytics and other non-essential SDKs stay switched off until you allow them. The first time you open Earnly we show a consent management platform (provided by Usercentrics, a Google-certified consent solution) where you can accept or decline each purpose, such as ads, analytics and crash reporting. You can change your choices at any time from Settings → My Consents. You can use Earnly even if you decline: ads and analytics simply stay off, and where applicable law allows, ads may be shown without personalisation. In the EU/EEA, whether ads are personalised follows the choices you make in this consent platform.
Referral attribution
When you install Earnly from a referral link, we use your device’s install-referrer information to credit the friend who invited you. This involves a referral code, click timestamp and basic device information.
Automated decision-making
We use automated processing to match offers and surveys to your profile; this only affects which offers you are shown and does not have legal or similarly significant effects on you. We also use automated checks for fraud prevention (for example checking your IP address against known VPN/proxy sources and verifying device integrity), which in some cases may restrict your account. Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. If you believe such a decision has affected you, you may contact us at support@blmapp.se to obtain human review, express your view and contest the decision.
8. Your rights
Under applicable data protection law you have a number of rights in relation to our processing of your personal data. To exercise any of them, contact us at support@blmapp.se.
- Access and information: to obtain confirmation of whether we process your data and to receive a copy of it.
- Rectification: to have inaccurate data corrected and incomplete data completed.
- Erasure (“right to be forgotten”): to have your data deleted in certain cases.
- Restriction: to ask us to restrict our processing in certain cases.
- Data portability: to receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transferred to another controller where technically feasible.
- Object: to object to processing based on our legitimate interest, and to object at any time to processing for direct marketing.
- Withdraw consent: where processing is based on your consent, you may withdraw it at any time, without affecting processing carried out before the withdrawal.
- Complaint: to lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
9. Account deletion and data retention
You can delete your account at any time from within the app (Settings → Delete account). When you delete your account, your identifying account data is retired so that you can no longer sign in with the same email, and your data cannot be restored.
Please note that certain records are retained even after account deletion: records of the payments we have made to you are kept for up to 7 years to comply with Swedish bookkeeping and accounting legislation, and limited security records may be retained to prevent fraud. Where possible, retained records are kept in a form that cannot be linked back to you as an identifiable person.
10. Data security and breach notification
We use industry-standard measures, including encrypted connections, access controls and secured databases, to protect your personal data. No method of transmission or storage is completely secure, but we take reasonable steps to protect your information.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to you, we will also inform you directly, in accordance with GDPR Article 34.
11. Your right to know about the personal information we share
In addition to the rights described in Section 8, you have the right to know about the personal information we disclose or share with third parties. Depending on where you live, this right is provided under laws such as the California Consumer Privacy Act and the California Privacy Rights Act in the United States, the Personal Information Protection Act in South Korea, and the Protection of Personal Information Act in South Africa, as well as the GDPR right of access in the EU/EEA.
This means you may ask us to confirm, and to tell you in a clear and understandable form:
- the categories of personal information we have collected about you;
- the categories of personal information we have disclosed or shared with third parties for a business purpose;
- the categories of third parties and recipients to whom that personal information was disclosed or shared, and the business purpose for each disclosure; and
- the categories of sources from which the personal information was collected.
The categories of personal information we share, the categories of recipients we share it with, and the business purpose of each disclosure are set out in the table in Section 4 of this policy. We disclose or share each category of personal information described in that table for the business purpose stated alongside it. We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising in the sense of a sale.
How to exercise this right
To request this information, contact us at support@blmapp.se. You may make a request free of charge. We will verify your request, normally by confirming control of the email address linked to your account, before we respond. We will respond within the period required by the law that applies to you, and we will not discriminate against you for making a request.
12. California residents (CCPA/CPRA)
This section applies to you if you are a California resident and supplements the rest of this policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). Terms such as “personal information”, “sell”, “share” and “sensitive personal information” have the meanings given to them in the CCPA. The data controller responsible for your personal information is BL APPS MANAGEMENT AB (org.nr 559275-3932), Bagartorpsringen 78, 170 65 Solna, Sweden.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA. We have not sold or shared the personal information of California consumers in the preceding 12 months, including the personal information of consumers we know to be under 16 years of age (Earnly is restricted to users who are at least 18).
Categories of personal information we collect
In the preceding 12 months we have collected the following CCPA categories of personal information. For the specific data points within each category, see Section 2.
| CCPA category | Examples we collect | Collected |
|---|---|---|
| Identifiers | Name, email address, device identifier, a persistent device (DRM) identifier, advertising ID (GAID), IP address, a user/account identifier, PayPal email address, push notification token | Yes |
| Commercial information | Coins earned and spent, offers, surveys and tasks completed, withdrawal and payout history | Yes |
| Internet or other electronic network activity information | App usage and interaction events, offer and ad interaction events, and the list of installed apps and usage duration collected via Android Usage Access, both by our offerwall partner to verify rewarded game offers and by us to detect fraud | Yes |
| Geolocation data | Approximate location (country/region) derived from your IP address. We do not collect precise GPS location | Yes |
| Audio, electronic, visual or similar information | Your Google profile picture, received as a link from Google Sign-In | Yes |
| Professional, employment, education, biometric or genetic information | Not collected | No |
| Protected classification characteristics | If you complete the optional profile task, your gender and year of birth. We do not use these to discriminate | Yes, if you choose |
| Sensitive personal information | Account log-in identifiers used to access your account. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA, so the right to limit does not change how we handle it (see below) | Limited |
| Inferences | Inferences drawn to recommend offers and surveys that are more relevant to you | Yes |
Categories of sources
- Directly from you, such as when you sign in, complete the optional profile task, or link PayPal;
- Automatically from your device and your use of the app, such as device and technical data, usage data and activity;
- From third parties acting on our behalf or that you interact with through the app, such as Google (sign-in), PayPal (payout and verification details), our offerwall and survey partners, our advertising and analytics providers, and our notification provider.
Business or commercial purposes for collecting
We collect personal information for the business and commercial purposes described in Sections 1 and 6, which include: creating and administering your account; building a basic profile and recommending relevant offers and surveys; providing offerwall offers, rewarded tasks and surveys and crediting your coins; running in-app reward features such as the daily check-in, goal progress and the leaderboard; administering PayPal withdrawals; sending notifications and service messages; rewarding referrals; detecting and preventing fraud, abuse and misuse; providing customer support; and complying with our legal obligations. We use your personal information only for the purposes for which it was collected, or for a compatible purpose.
Categories of personal information disclosed for a business purpose, and to whom
The table below shows, for each CCPA category, the categories of third parties to which it was disclosed for a business purpose in the preceding 12 months, if any. This disclosure is not a “sale” or “share” under the CCPA. The categories of third parties are described in full in Section 4.
| CCPA category disclosed | Categories of third parties |
|---|---|
| Identifiers | Hosting and IT infrastructure providers, sign-in/identity provider, offerwall and rewarded-offer partners, survey providers, advertising provider, analytics and diagnostics provider, payment provider, notification provider, device-integrity/anti-fraud provider |
| Commercial information | Hosting and IT infrastructure providers, offerwall and survey partners, payment provider |
| Internet or other electronic network activity information | Offerwall and rewarded-offer partners, advertising provider, analytics and diagnostics provider, notification provider |
| Geolocation data (approximate, region-level) | None as a geolocation category. We derive your approximate country from your IP address on our own servers; providers your device connects to receive your IP address itself, which is covered under Identifiers above |
| Protected classification characteristics (gender, year of birth, if you provide them) | Offerwall and rewarded-offer partners, survey providers |
| Sensitive personal information (account log-in) | Sign-in/identity provider, hosting and IT infrastructure providers |
| Inferences | Offerwall and rewarded-offer partners, survey providers |
We disclose personal information to service providers and contractors that are bound by contract to use it only to perform services for us. We also disclose personal information to authorities, advisors or an acquirer where legally required or in a business transfer, as described in Sections 4 and 15.
Your California privacy rights
Subject to certain exceptions, California residents have the following rights:
- Right to know. To request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties to whom we disclosed it.
- Right to delete. To request that we delete personal information we collected from you, subject to legal exceptions such as completing a transaction, security, fraud prevention and compliance with our legal obligations.
- Right to correct. To request that we correct inaccurate personal information we hold about you.
- Right to opt out of sale or sharing. You have the right to opt out of the sale of your personal information and of sharing for cross-context behavioral advertising. We do not sell or share your personal information, so there is nothing for you to opt out of, and we do not display a “Do Not Sell or Share My Personal Information” link because it does not apply.
- Right to limit the use of sensitive personal information. You have the right to limit our use and disclosure of sensitive personal information to what is necessary to provide the service. We only use sensitive personal information (your account log-in) for permitted purposes such as authenticating you and securing your account, so this right does not change how we handle it.
- Right to non-discrimination. We will not discriminate against you for exercising any of these rights. We do not offer financial incentives in exchange for your personal information.
How to submit a request and how we verify it
You can submit a request to know, delete or correct by emailing us at support@blmapp.se with the subject line “California Privacy Request”. You can also delete your account at any time from Settings → Delete account in the app.
To protect your information, we will verify your identity before acting on a request. We do this by asking you to make the request from, or confirm, the email address associated with your Earnly account, and we may ask you to provide additional information that matches what we already hold so we can reasonably confirm that you are the person about whom we collected the personal information. We will not use information collected for verification for any other purpose. We will respond within the timeframes required by the CCPA.
Authorized agents
You may use an authorized agent to submit a request on your behalf. We may require the authorized agent to provide proof that you gave them signed permission to act for you, and we may still require you to verify your own identity directly with us or to confirm that you gave the agent permission, as allowed by the CCPA.
If you have questions about your California privacy rights, contact us at support@blmapp.se.
13. Virginia residents (VCDPA)
If you are a resident of the Commonwealth of Virginia, the Virginia Consumer Data Protection Act (VCDPA) gives you the rights described in this section in relation to the personal data we process about you. This section supplements the rest of this policy and controls if there is any conflict with it for Virginia residents.
Categories of personal data we process, and our purposes
The categories of personal data we process, and the purposes for which we process them, are described in Section 1 (purposes), Section 2 (the data we collect) and the detailed tables in Section 6. In summary, we process identifiers such as your name, email address and a device identifier; your advertising ID (GAID), IP address and approximate country; device and technical data; the list of apps installed on your device and your app usage, collected to verify rewarded game offers and to detect fraud; optional profile data (your gender and year of birth); your PayPal email and related payment data; and your activity within the app, such as offers and surveys completed, coins earned and spent, check-ins, leaderboard standing and withdrawal history.
Categories of personal data we share, and the categories of third parties
The categories of personal data we share, and the categories of third parties we share them with, are set out in the table in Section 4. Those categories of third parties include hosting and IT infrastructure providers, a sign-in and identity provider, offerwall and rewarded-offer partners, survey providers, an advertising provider, an analytics and diagnostics provider, a payment provider, a notification provider, a device-integrity and anti-fraud provider, and, where legally required or in a business transfer, authorities, advisors or acquirers.
Your VCDPA rights
Subject to the conditions and exceptions in the VCDPA, you have the right to:
- Confirm and access. Confirm whether we are processing your personal data and access that personal data.
- Correct. Correct inaccuracies in your personal data, taking into account the nature of the data and the purposes of the processing.
- Delete. Delete personal data provided by or obtained about you.
- Obtain a copy. Obtain a copy of the personal data you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller without hindrance.
- Opt out of the processing of your personal data for purposes of (a) targeted advertising, (b) the sale of personal data, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
Targeted advertising, sale and profiling
We do not sell your personal data for money or other valuable consideration, and we do not engage in profiling that produces legal or similarly significant effects concerning you. We use automated processing to match offers and surveys to your profile, but this only affects which offers you are shown and does not produce legal or similarly significant effects.
You can control processing used for targeted advertising at any time. Advertising and other non-essential processing stays switched off until you allow it through our consent management platform, and you can change your choices at any time from Settings → My Consents, as described in Section 7. You may also reset your advertising ID or limit ad personalisation in your device settings. To opt out of targeted advertising, the sale of personal data (should our practices ever change), or such profiling, you may also contact us at support@blmapp.se.
How to exercise your VCDPA rights
To submit a request to confirm, access, correct, delete or obtain a copy of your personal data, or to opt out, contact us at support@blmapp.se. You can delete your account and much of your data directly in the app from Settings → Delete account, and manage advertising and analytics choices from Settings → My Consents. We will take reasonable steps to verify your identity before acting on a request, generally by confirming control of the email address associated with your account, and we may ask for additional information where needed to authenticate the request.
We will respond to your request without undue delay and within 45 days of receipt. When reasonably necessary, we may extend that period by an additional 45 days, in which case we will inform you of the extension and the reason for it within the first 45 days. There is no charge for exercising your rights, unless your request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline to act and will explain our decision.
Your right to appeal
If we decline to take action on your request, we will inform you of the reasons for our decision. You have the right to appeal that decision. To appeal, reply to our decision message or email us at support@blmapp.se with the subject line “VCDPA Appeal”, and include your name, the email associated with your account, and the request and decision you are appealing.
Within 60 days of receiving your appeal, we will review it and inform you in writing of the outcome, together with a written explanation of the reasons for our decision. If we deny your appeal, we will also provide you with a method to contact the Virginia Attorney General to submit a complaint. You can reach the Office of the Virginia Attorney General at https://www.oag.state.va.us/consumer-protection/index.php/file-a-complaint.
14. Brazil residents (LGPD)
If you are located in Brazil, the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Lei No. 13.709/2018, the “LGPD”) applies to our processing of your personal data, in addition to the general information in this policy. BL APPS MANAGEMENT AB is the controller of your personal data for the purposes of the LGPD.
Legal bases for processing (LGPD Art. 7)
We process your personal data only where the LGPD allows it. Depending on the activity, we rely on one or more of the following legal bases: your consent; the performance of a contract or preliminary procedures related to a contract to which you are a party (your Earnly membership and the payment of your withdrawals); compliance with a legal or regulatory obligation; the regular exercise of rights in judicial, administrative or arbitration proceedings; and our legitimate interests, such as preventing fraud and securing the service, provided your fundamental rights and freedoms are respected. The specific basis for each purpose corresponds to the purpose tables in Section 6.
Your rights under the LGPD (Art. 18)
As a data subject under the LGPD, you may request, free of charge, that we:
- confirm whether we process your personal data;
- give you access to your personal data;
- correct incomplete, inaccurate or out-of-date data;
- anonymise, block or delete data that is unnecessary, excessive or processed in a way that does not comply with the LGPD;
- provide your data in a portable format so it can be transferred to another provider or service, subject to our commercial and industrial secrets;
- delete personal data that we process on the basis of your consent, except where the law allows us to keep it (for example to comply with accounting obligations or to defend legal claims);
- give you information about the public and private entities with which we have shared your data;
- give you information about the possibility of not providing consent and the consequences of refusing; and
- let you withdraw a consent you have given, at any time, without affecting processing carried out before the withdrawal.
You can also use the consent management platform described in Section 7 (Settings → My Consents) to grant or withdraw consent for advertising, analytics and crash reporting at any time.
How to exercise your rights and contact our person in charge
To exercise any of these rights, or to contact the person in charge of data processing (the encarregado / Data Protection Officer) for BL APPS MANAGEMENT AB, write to us at support@blmapp.se. We do not sell or rent your personal data.
If you believe our processing does not comply with the LGPD, you may also lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD).
15. Business transfers
If BL APPS MANAGEMENT AB, or substantially all of its assets, is acquired by or merged with another company, or in the unlikely event of insolvency, your personal data may be among the assets transferred. In such a case you will be informed before your personal data becomes subject to a different privacy policy, and the acquiring party will be required to continue to process it in accordance with applicable data protection law.
16. Changes to this policy
We may update this privacy policy from time to time, including to reflect new or changed third-party services, SDKs or partners that we use (for example advertising, analytics or attribution providers). Such providers fall within the categories of recipients and data already described in this policy. By using Earnly and accepting this policy you agree that we may make such additions and updates, and your continued use of the service after an update constitutes your acceptance of the updated policy. When we make a significant change, we will notify you through the app or by email. The date at the top of this page shows when it was last updated.
17. Contact us and data protection contact
Data protection contact
BL APPS MANAGEMENT AB is the controller responsible for your personal data and is your point of contact for all data protection and privacy matters. We are a small company and are not required under Article 37 of the GDPR to appoint a Data Protection Officer, and we have not appointed one. Instead, we have designated a dedicated data protection contact who is responsible for handling privacy questions, requests to exercise your rights and any other data protection matters.
You can reach our data protection contact at any time using the details below. We aim to respond to data protection enquiries without undue delay and, where the law sets a deadline, within the time required by applicable data protection law.
- Controller: BL APPS MANAGEMENT AB
- Data protection / privacy contact email: support@blmapp.se
- Postal address: Bagartorpsringen 78, 170 65 Solna, Sweden
- Company registration number (org.nr): 559275-3932
General contact
If you have any other questions about this policy, you can also contact us using the same details:
- BL APPS MANAGEMENT AB
- Bagartorpsringen 78, 170 65 Solna, Sweden
- Company registration number (org.nr): 559275-3932
- Email: support@blmapp.se
18. Language
This privacy policy is provided in several languages for your convenience. If there is any conflict or inconsistency between the English version and a translated version, the English version prevails.