Last updated: July 21, 2026
Privacy Policy
This policy explains the information used by the current Dremads competition MVP and the controls applied to its role-based campaign workflows.
Information we process
- Account details such as name, email address, account role, verification state, and profile information.
- Advertiser campaign information, including budgets, schedules, targeting, article content, quiz questions, and answer configuration.
- Participant quiz responses, attempt timestamps, scores, pass or fail outcomes, capacity records, and completion history.
- Demo wallet and immutable reward-ledger records, including amounts, currencies, transaction references, status, and timestamps.
- Authentication, session, consent, operational, administrative, and security-event information needed to run and audit the MVP.
- Waitlist email address, optional full name and interest type, contact-consent timestamp, submission source, and notification-delivery status.
How information is used
Dremads uses this information to provide account access, operate role-based workspaces, moderate and activate campaigns, determine participant eligibility, score ARTICLE_QUIZ attempts, enforce campaign capacity, prevent duplicate rewards, display activity, and support operational troubleshooting and security review. Waitlist information is used only to provide Dremads product updates and early-access information under the consent given with the submission.
Role-based access
Participants receive only the campaign content required to participate. Answer keys and correctness metadata are withheld until backend scoring is complete. Advertisers can manage their own campaign content within lifecycle restrictions, while authorized administrators can review moderation and operational details. Backend authorization is required for protected actions.
Storage, retention, and third parties
The MVP stores application data in its configured PostgreSQL database and uses the services identified in the repository configuration. Retention periods and production data-deletion procedures have not been finalized. Operators should retain data only as long as needed for the demonstrated workflows, auditing, security, and applicable obligations.
No third-party payment processor is integrated. Simulated campaign funding and demo wallet balances do not represent deposits, bank settlement, withdrawals, or payouts. Hosting, monitoring, email, or other production processors are configured by the operator and must be reviewed as the deployment evolves.
Security practices
Current controls include password hashing, authenticated API access, role checks, server-side validation and scoring, lifecycle restrictions, idempotent financial records, and auditable administrative and ledger events. No software system can guarantee absolute security, and this MVP has not been represented as independently certified or production audited.
Your choices and responsibilities
Use accurate account information, protect your credentials, and avoid submitting sensitive information that campaign instructions do not require. Account-management capabilities remain limited in this MVP. Questions about stored information or account access can be directed to support@dremads.com or the contact page.
