luoa.
Privacy & device identification
Pioneer Program 1.0 · Updated October 6, 2026
Key-based accounts and device identifiers
Joining creates an account key. The server stores a hash of that key for account recovery, and a secure browser cookie maintains your session. The device identifier is a random value assigned by the server to recognize repeat visits from the same browser. Clearing browser data or changing browsers or devices may change it. A device identifier cannot replace your key or reliably identify a unique real person.
What we record to keep rewards fair
We record browser and system details, language, time zone, screen size, pixel ratio, color depth, touch points, browser-reported CPU cores and memory tier, cookie support and automation signals; plus account links, visit times, registration, recovery, claim requests and verification results. Unavailable fields are left blank. We also hash the rendering of fixed test graphics and text, and record browser-reported graphics renderer details to help detect repeat participation after storage is cleared. These tests do not read your entered text, images or other page content. If the browser restricts these features, we use the signals available.
The server receives connection IP, country or region, and network ASN. Application risk logs store a keyed hash of the IP; network data also helps rate-limit requests. Hashes can still link visits and are not fully anonymous.
How we use this information
We use it to limit automated bulk requests, detect duplicate accounts and unusual invitation relationships, and support manual reviews and appeals. We do not collect contacts, personal files, precise location, camera or microphone content, or use keys or form content for fingerprints. Browsers bound to a reward account are restricted from creating or claiming through multiple accounts. Shared browsers between inviters and friends pause related invitation payouts. Similar environments require recent network or invitation evidence before claims are held for review; sharing an IP alone does not trigger a ban. Device identification can be wrong, and you can request a review.
Verification services and retention
We use Cloudflare for hosting, security and Turnstile verification. Cloudflare processes necessary technical and interaction data during verification. See the Cloudflare Privacy Policy ↗。
Application access and risk events are retained for 90 days. Device details and account-device links are removed 180 days after last access. During the program, necessary eligibility bindings, rendering hashes and recent network hashes are retained to prevent repeat claims by clearing access records. They are not used to recover accounts or display keys. Reward ledgers, invitation links and necessary review and administrative records support balance maintenance and payout reconciliation. Keys are displayed only when generated; store yours safely.
Access and review requests
View your balance and payout history on the rewards page. Use “My account → Request an account review” to report device identification errors or account issues. Signing out clears the current session, not your balance. Keep your key safe while email recovery is unavailable.
Successful logins record the method, time, connection IP and detected operating system for account administration and security review. Login history is retained for 90 days, with the latest successful login retained for each account. The successful email binding time is recorded for binding statistics. This information is available only to authorized administrators.
Back to the Pioneer Program ↗