real places. real rewards.

privacy.

Applies to the floor app and flooronrh.com. Last updated 24 September 2026.

floor lets you pick up token rewards by standing at a real-world drop, posting about it, and getting paid to a wallet. To do that we need a small amount of data. This page lists all of it.

What we collect

  • Account. You sign in with Apple or Google through Privy, our login provider. We store the identifier Privy gives us and, if your login shares it, your email address. We never see your password.
  • Location while you use the app. The map and drop screen use your location to show your position, distance and whether you are close enough to verify. During verification, usually about 20 seconds, the app sends GPS samples to our backend. We retain that trail with the verification record for claim review and fraud checks, including whether the phone reports a simulated location. The app does not request background location tracking.
  • Country from your IP address. During verification we compare the country of your connection with the country of the drop. We store the country code, not the IP address.
  • Device identifier. An identifier for your phone (Apple’s identifier for vendor on iPhone, the Android device ID on Android, or a random one when neither is available) is sent with each verification so we can see when one person claims from several accounts.
  • App integrity. Supported app versions request proof through Apple App Attest or Google Play Integrity. Our backend checks the proof and records the result for fraud review. For App Attest, we also store the public key and verification counter. These checks are currently report-only.
  • App milestones. We record login completion, location permission choices, and whether you open a drop or the creator screen, with timestamps linked to your account. These events help us understand where people get stuck; they contain no GPS coordinates.
  • Your post and X account. On Android you can connect X so the app posts your floor photo when you claim; we then store your X username and, encrypted, the access tokens X gives us, until you disconnect X or delete your account. We keep the link of the post with your claim. On iPhone the app does not connect to X: sharing goes through the system share sheet and we see nothing of it.
  • Drops you place. The title, message, post text, place name and artwork you give a drop, linked to your account and shown to others.
  • Your floor photo. The photo you take or choose from your library for a claim. The original is kept in a private archive, with location and camera metadata removed when you submit the claim. If automated screening or an admin approves it for the wall, a resized copy without location metadata is shown publicly on flooronrh.com. You agree to that when you claim.
  • Wallet address. The address of the wallet your rewards are paid to. Payouts are recorded on a public blockchain. Each drop pays on one chain, which is shown on the drop and in your rewards.
  • Push token. If you allow notifications, a token that lets us tell you when a reward is ready.
  • Crash reports. If the app crashes, a report goes to Sentry with the error, the app version and the device model. Reports are scrubbed of coordinates, wallet addresses and post links before they leave the phone.

What we do with it

Review and pay claims, stop cheating, show approved floor photos on the wall, notify you about rewards, understand where people get stuck, and fix crashes. Nothing is sold or used for advertising.

Who else sees it

  • Privy handles login and wallets.
  • Cloudflare stores photos and serves the website.
  • Railway hosts the backend and database.
  • Expo provides app builds, over-the-air updates and push notifications.
  • Sentry receives crash reports.
  • OpenStreetMap services. When you search for a place while placing a drop, the search text and the map point to search near go straight from your phone to Photon (run by komoot); we do not store them. Our backend looks up place names for drop locations with Nominatim.
  • X receives your floor photo and post text when you post on X from the Android app.
  • Google Cloud Vision receives resized claim photos for automated explicit-content screening before publication. Photos that need further review are held for an admin.
  • Apple and Google provide sign-in and app integrity checks through App Attest and Play Integrity. Apple also distributes iPhone beta builds through TestFlight.

Payouts are visible to anyone on the block explorer of the chain the drop paid on, as with any blockchain transaction.

How long we keep it

Account, claim and verification data stay while your account exists. Original photos are kept as an archive. Crash reports are deleted by Sentry after 90 days.

Your choices

  • Location, camera and notification permissions can be changed in your phone settings at any time. Without location you cannot verify a drop.
  • Delete your account in the app (you tab, then delete account), or follow the account deletion instructions to ask by email. You can email support without signing in or using X. On-chain payouts cannot be deleted.

Safety

Things people ask before installing a beta app that pays out crypto.

  • Permissions the app asks for. Location (while in use), camera and photo library (only when you take or pick a floor photo), and notifications. Nothing else: no contacts, no microphone, no background location, no reading of other apps.
  • Wallets and transactions. Privy provides an embedded wallet connected to your login. Our server sends approved rewards to that wallet. Sending rewards opens the wallet website. Creators use the embedded wallet in the app to sign transactions that fund drops or withdraw unclaimed funds.
  • The reward money is in a public contract. Drops are funded into a vault contract on the chain the drop is on. The same contract runs at the same address on every chain floor supports, with its source published on each: Robinhood Chain, Base and Arbitrum. Drops placed before it went live stay in the earlier vault until they end. Anyone can read exactly what it can and cannot do, and every payout is a public transaction. The contract has not had a third-party audit yet, which is why drop sizes stay small during the beta.
  • Where the builds come from. iPhone builds are distributed through TestFlight. Apple reviews the first external testing build of a version; later builds may not need a full review. Android APKs come from Expo's build service. The get the app page shows the APK's SHA-256 fingerprint so you can check the downloaded file. App updates can also arrive over the air through Expo without a new TestFlight review or APK download; the APK fingerprint does not cover those updates.
  • What the server can see. Only what is listed above under "What we collect". Verification trails, photos and post links go to our backend. Resized photos are also sent to Google Cloud Vision for content screening, as described above.
  • Deleting the app removes everything stored on the phone. Your account stays until you ask us to delete it.

Children

floor is not for anyone under 18.

Changes

If this page changes in a way that matters, the date at the top moves and the change is listed in the app's release notes.