Reward apps ask for more than a typical utility app — motion data, an advertising identifier, sometimes notifications. Most of those requests are legitimate. Knowing which is which takes about two minutes, and the checking can be done before you install rather than after.
Start with the permissions
The useful question is not “is this app asking for a lot?” but “does each request match what the app actually does?”
- Motion and fitness data is necessary for a step-counting app. Without it there is no step count. On iPhone this data is handled by the system and you can revoke it at any time in Settings.
- Notifications are reasonable for daily streaks and reminders, and are always declinable.
- Tracking permission is the iOS prompt asking to track you across other apps and websites. Declining it is fine and should not break anything.
- Contacts, photos, precise location, or microphone have no obvious use in a step counter or a quiz app. Treat these as a question that needs answering.
Our four apps, as a worked example
Generic advice is easy to write and hard to act on, so here is the specific version. This is the complete list of permissions our own apps request. We can publish it exactly because we can read it out of the projects that build them, and you can check most of it yourself from the App Store listing before you install anything.
| Permission | Step and Earn | The other three |
|---|---|---|
| Health — step count, read only | Yes | No |
| Health — writing anything back | Never | Never |
| Tracking (the iOS ATT prompt) | Yes | Yes |
| Precise or approximate location | No | No |
| Camera, photos or microphone | No | No |
| Contacts or calendar | No | No |
That is the entire list. Two permissions in the walking app, one in each of the others.
The Health entry is the one worth explaining, because a step counter reading your health data sounds like the largest ask on the page and is actually the most constrained thing we do. Step and Earn requests read access to your step count and nothing else in Health, and it holds no permission to write to Health at all — the app tells you so in the permission prompt itself. iOS enforces that rather than trusting us: an app granted read access to steps cannot reach your heart rate, your sleep, your weight or your medical records, and you can revoke the whole thing in Settings without uninstalling anything.
What actually leaves the device
Permissions are what an app may look at. A separate question — the one people usually mean — is what gets sent somewhere. Since 2024 Apple has required every app to ship a machine-readable privacy manifest declaring exactly that, which is why this list can be specific rather than reassuring:
- Your step count, in the walking app only, and only to work out what you have earned.
- Your name and email address, because a payout has to reach a person. This is also the only reason we hold either.
- An account identifier that ties your coin balance to you. Signing in happens anonymously behind the scenes — there is no password to create and no account to make before you can use the app.
- Whatever you write to support, if you contact us.
- An advertising identifier and general in-app activity, which go to the ad network so that ads can be selected and a rewarded ad can be confirmed as watched.
- Crash reports, which are not tied to your identity and exist so we can fix what broke.
The first four are the app working. The fifth is the business model, and it is the one to weigh — how reward apps make money explains where the money comes from and what it costs you.
Advertising identifiers, briefly
Ad networks use a resettable identifier to decide which ads to show and to confirm that a rewarded ad was watched in full. On iPhone you can reset it, limit it, or decline tracking outright in Settings, and apps are required to ask before tracking you across other companies' apps and sites.
Declining should cost you nothing. In our apps it does not change how many ads you see, how much you earn, or what you can use — it changes how well targeted the ads are, which is the ad network's problem rather than yours. That is worth testing on any reward app you install: decline the tracking prompt, and if the app then nags, degrades or locks something, you have learned what it was really asking for.
How to check an app before you install it
None of this requires taking a developer's word for anything. Three checks, about two minutes:
- Read the App Store privacy label. Scroll to “App Privacy” on the listing. It splits data into what is linked to you and what is used to track you across other companies' apps. An app whose label is far larger than its function is the signal you are looking for — a quiz app collecting precise location, say.
- Check the permission prompts against the job. A step counter needs steps. A to-do list does not need your contacts. The prompt text itself is written by the developer, so a vague one (“to improve your experience”) is worth a moment's suspicion.
- Find the privacy policy and the support contact before installing, not after. Both should name a real company. If the developer page links to nothing, that is the answer.
Red flags
- Permission requests with no relationship to what the app does.
- No privacy policy, or one that never mentions advertising.
- Any request for card details, a deposit, or a fee to withdraw.
- A developer with no website and no way to contact a person.
- Reviews describing redemptions that never arrive.
- An app that stops working properly when you decline tracking.
- A balance that expires, or a threshold high enough that you are unlikely to reach it — not a safety problem exactly, but the most common way people in this category end up with nothing.
A reasonable checklist
- Read what the app asks for and check each request against what it does
- Read the App Store privacy label, not just the description
- Find the privacy policy and confirm it mentions advertising
- Check the developer has a real website and a support contact
- Skim recent reviews specifically for payout complaints
- Decline tracking if you would rather not be tracked — it should still work
- Cash out early rather than saving up, whoever you are using
We have already done this for the big ones
Running that checklist against a specific app is the slow part, so the reviews do it one app at a time, from each company's own terms and help pages rather than from its marketing. Most of what the last two items on the list are warning about turns up there. The Fetch terms say points expire after 90 quiet days and that you hold no property rights in them. The Ibotta terms charge a maintenance fee against a balance left sitting. Mistplay reserves the right to pay two people differently for identical actions. None of those is a safety problem in the malware sense. All of them are the reason people end up with nothing.
Where we stand
Our privacy policy sets out what our apps and this site collect, including advertising and analytics, and how to request deletion. If anything in it is unclear, the contact page reaches a person.
We would rather be checked than believed. Everything on this page about our own apps is visible from the outside: the permission prompts are in the apps, the collected-data list is on the App Store listing, and the payout terms are on what you can actually earn. If any of it does not match what you see, we would genuinely like to know.