Hashpit Privacy Policy
Last updated: 1 July 2026
Hashpit is a solo cryptocurrency-mining console for iPhone, iPad, Mac, and Android. It is a
personal tool operated by an individual developer (“we”, “us”). This policy explains what
information the app handles, where it is stored, and who it is shared with. We have tried to
keep this honest and specific rather than generic.
The short version: Hashpit does not use any analytics, advertising, or
third-party tracking. Your mining-service API keys never leave your device. The only data kept
on our server is what is needed to run your account and your mining ledger.
1. Information stored on our server
Hashpit talks to a backend we operate at hashpit.mohdelfatih.com. The following
account information is stored there:
- Account identity — your email address and a securely hashed (never
plaintext) password. If you use Sign in with Apple, we store Apple’s
anonymous user identifier and the email address Apple provides (which may be a private
relay address you can revoke at any time). We never receive your Apple password.
- Payout addresses — the public blockchain wallet address(es) you enter to
monitor and receive solo-mining rewards (e.g. your Bitcoin Cash address).
- Your mining ledger — records of the rental orders you place or simulate,
their budgets, outcomes, and profit/loss, so the app can show your history and advice.
- Login sessions — an opaque session token (stored only as a hash) so you
stay signed in. Deleting a session immediately signs that device out.
- Pool requests — if you tap “Request this pool” for a mining pool we don’t
yet recognise, we store that pool’s hostname so we can add support for it.
2. Information kept only on your device
Some sensitive credentials are stored only on your device, in the system
secure store (Apple Keychain on iOS/Mac, the Android Keystore on Android). These are
never sent to, or logged by, the Hashpit server:
- Your NiceHash API key, secret, and organization ID.
- Your MiningRigRentals API key and secret.
- Your login session token.
The app uses these keys on your device to sign requests directly to those services on your
behalf. If you delete the app, these on-device credentials are removed with it.
3. Third-party services
Hashpit connects directly from your device to the mining services you choose to use:
- NiceHash (
api2.nicehash.com) — to read prices and, when you
explicitly place an order, to rent hashpower using your own API keys.
- MiningRigRentals (
miningrigrentals.com) — to rent rigs and
process payouts using your own API keys.
- Apple — only if you choose Sign in with Apple.
- Public mining-pool and blockchain data sources — to show block-found status, pool luck,
and network information. These requests carry your public payout address but no account
credentials.
Your use of NiceHash and MiningRigRentals is also governed by their own privacy policies and
terms. We are not affiliated with those companies.
4. Device permissions
- Notifications — to alert you when a block is found or matures. Optional;
you can decline or disable them.
- Local network (iOS) — optional. If you use the rig scanner, the app
probes your own Wi-Fi network to find mining rigs. This scan runs entirely on your device;
the results are not sent to our server.
5. What we do NOT do
- No analytics, advertising, or third-party tracking SDKs.
- No selling or renting of your data to anyone.
- No collection of your location, contacts, photos, or device advertising identifier.
6. Data retention and deletion
We keep your account data for as long as your account exists. You can request deletion of your
account and its associated data at any time by contacting us at the address below; we will
delete your account, payout addresses, and ledger from our server. Credentials stored on your
device are removed when you delete the app.
7. Children
Hashpit is not directed to children under 13 (or the equivalent minimum age in your country)
and we do not knowingly collect information from them.
8. Changes to this policy
If this policy changes, we will update the “Last updated” date above and post the revised
version at this URL.
9. Contact
Questions or deletion requests: mohd.elfatih@icloud.com.