The faucet stores your FaucetPay email, password hash, account balances, claims, referral relationship, withdrawal records, and limited security metadata such as hashed IP addresses.
Advertising limits use a keyed hash of your IP address with per-ad daily counters and cooldown timestamps. The raw IP is not stored in these counters, and expired counter rows are removed automatically.
Before a new account session is created, an IP not already whitelisted or cached may be sent to AdsLab Anti Proxy for proxy, VPN, and hosting/datacenter detection. MoneyRain stores the keyed IP hash, detection flags, limited network-provider metadata, and expiry for 30 days. Raw IPs placed on the permanent admin whitelist remain until removed.
Every fourth successful direct faucet claim may use AdsLab Monetized Captcha. When sponsored account verification is enabled, every password login and account creation attempt also starts an AdsLab Monetized Captcha before MoneyRain processes account credentials. MoneyRain sends AdsLab an opaque, single-use challenge identifier and receives a signed completion callback. AdsLab can process your IP address, browser details, and advertising interaction under its own privacy terms. MoneyRain stores only token hashes, purpose, keyed browser/network bindings, and short-lived challenge state; it never sends or stores your password in the captcha challenge. Terminal challenge details are removed after one day.
During signup, MoneyRain sends the entered email to FaucetPay's account-check API. Signup is allowed only when FaucetPay confirms that the destination belongs to a FaucetPay account. MoneyRain stores a keyed hash of the checked email and the result temporarily to reduce provider requests; it does not send a MoneyRain verification email.
Email is used for password resets, optional notification categories, and FaucetPay payout delivery. Password-reset email requests require Turnstile or hCaptcha followed by AdsLab Monetized Captcha, are rate limited, and retain only keyed email hashes and short-lived challenge state. MoneyRain never asks for or stores your FaucetPay password.
When Rain Pool reporting is enabled, eligible earning events are placed in a local transactional outbox and sent over signed HTTPS to MoneyRain's separate global statistics database. Current activity is compacted into one live row per normalized FaucetPay email with hourly and daily fixed-point totals. Delivery hashes remain for one day to prevent duplicate batches without retaining claim details. Pending direct FaucetPay pool rewards retain the recipient email until paid, rejected three times, or carried to a payable amount.
Opening AoyTasks loads an external offerwall with your numeric Faucet user ID. AoyTasks may process your IP address, browser details, offer activity, and other data under its own privacy terms. MoneyRain receives signed reward and chargeback postbacks and retains a compact provider transaction ID, account ID, reward amounts, status, and limited offer type for duplicate prevention and financial corrections; raw callback queries and provider-reported IP addresses are not stored.
The Telegram Mini App validates Telegram launch identity data and stores a one-to-one link between your Telegram user ID and FaucetPay-confirmed Faucet account. It also stores limited profile fields supplied by Telegram, hashed IP and user-agent bindings, daily attempt totals, short-lived validated game sessions, AdsGram reward intents, GH/s lease buckets, and compact miner aggregates.
Rewarded Telegram play requests ads from AdsGram. AdsGram receives the Telegram identity value required for its Reward URL and processes advertising requests under its own privacy terms. A client-side ad result never grants GH/s by itself; MoneyRain waits for the matching signed server callback. Practice mode runs locally without ads, Energy, reward attempts, or gameplay database rows.
Your dark-mode and captcha preferences are stored with your account. Leaderboards may show a masked version of your email together with aggregate activity, referral, rank, and prize information; full email addresses are not published.
Temporary authentication, rate-limit, claim-detail, callback, and completed payout records expire according to the retention policy. Daily aggregates and platform totals may remain for accounting and abuse prevention.
Contact support@moneyrain.top for privacy questions.