Legal
Privacy Policy
This policy explains how Premium Miner processes information when you use Google or Telegram authentication, link a wallet, purchase Premium access, or use the remote dashboard.
What the app does
Premium Miner is a remote dashboard and controller for server-side mining. The Android application does not mine cryptocurrency on your phone and does not use your phone's CPU or GPU to create taps, roots, proofs, or rewards.
Information we process
- Google authentication data, including the stable Google subject identifier used as the canonical Google identity and limited profile metadata such as email address, display name, and locale when Google supplies them. Email is not used as the canonical identity.
- Telegram account identifiers and profile display fields when you choose Telegram authentication.
- Your Premium Miner account, lowercase wallet name, permanent Google-to-wallet association, wallet-ownership verification state, and Premium expiration.
- Application and device-session identifiers, labels, creation and last-used times, expiration, refresh history, and revocation status.
- Hashed one-time link codes and hashed access or refresh tokens.
- Mining state, daily taps, epoch preference, balances, network status, and reward observations.
- Google Play product, order, purchase token hash and encrypted token, purchase state/time, verification, consumption, entitlement, refund, and revocation records.
- Limited security and reliability data, such as IP-derived security hashes, request time, response status, rate-limit events, identity conflicts, and error category.
- Google Play Integrity request and verdict records, including package, certificate, version, licensing, recognition, device-integrity, and request-binding results.
- Theme, reduced-motion preference, last page, and a bounded display cache stored locally on your device.
We do not request contacts, SMS, phone logs, precise location, camera, microphone, photos, advertising ID, IMEI, seed phrases, wallet private keys, or mining private keys.
Why we process information
We use information to authenticate accounts, permanently bind a verified Google identity to one wallet, link and secure devices, display account state, perform commands you request, prevent replay and duplicate purchases, verify Google Play purchases, maintain Premium access, reconcile refunds, investigate failures or abuse, and meet legal or accounting obligations.
Service providers
Information may be processed by Google Play and Google Cloud for app distribution and purchases, our infrastructure providers for secure account and application hosting, Telegram for account linking and the existing bot, and Acki Nacki/Bee network services for external mining state. We do not sell personal information and this release contains no advertising or third-party analytics SDK.
Security
Production traffic uses HTTPS. Android refresh tokens use Android Keystore-backed encryption. Server-side refresh tokens and link codes are stored as hashes. Sensitive values are excluded from normal logs and client responses. No security measure can eliminate every risk.
Retention
- Unused pairing codes expire after about ten minutes.
- Used or revoked pairing and mobile-session records are retained on a bounded schedule, generally for up to approximately 90 days, for security and operational recovery.
- Purchase records are retained as needed for entitlement integrity, refunds, fraud prevention, accounting, and legal obligations.
- Security tombstones and minimum token hashes may be retained to prevent a deleted or refunded credential from being reused.
- Operational backups expire under the infrastructure backup schedule and may remain for up to three months.
- Local display data is bounded; raw reward history is limited to current and previous epoch data with seven daily aggregates.
Your choices and deletion
You can revoke an Android device through Telegram using /app_devices, /revoke_app_device, or /revoke_all_app_devices. Logging out of Android revokes the current session and clears its secure local credentials.
To request access, correction, export, or deletion of account information, follow the instructions on our account deletion page or contact dev.a47p@gmail.com. A verified deletion request immediately revokes active application sessions and begins a 30-day deletion window. At completion, direct identity and wallet fields are removed or pseudonymized. Required purchase, refund, dispute, fraud, accounting, security-tombstone, or legal records may be retained with identifying information minimized.
Children
The service is intended for adults and is not directed to children.
International processing
Service providers may process information in countries other than your own. Their contractual and legal safeguards apply to that processing.
Changes
Material changes will be posted on this page with an updated effective date.