Compliance

Built to pass legal review — and app store review.

Consent-first architecture, an EU operator, and policies published in full. This page is written for your counsel and your store reviewer — everything they need for a yes, in one visit.

review_checklist · clearhop_sdkRUNNING
Legal review
GDPR 6(1)(a) consent basis · EU operator
App store review
explicit opt-in · two equal buttons
Antivirus review
no personal data · transparent process
Public policies
terms · privacy · acceptable use

Not “we comply”. Here is what compliance looks like.

Valid consent must be freely given, specific, informed, unambiguous and withdrawable. Each of those is a design decision in the dialog below.

11:02wi-fi · charging
Support this app — no ads

Allow the app to use a small amount of your unused internet bandwidth. Only on Wi-Fi, only while charging.

no personal data · turn off anytime in settings

AllowDon't allow

annotated · numbers match the principles

01
Informed — the benefit is in the user's words

“Support this app — no ads” states what the user gets in exchange. A purpose that is disclosed but not understandable does not make consent informed.

02
Specific — conditions on the same screen

Wi-Fi only, charging only, no personal data, scope named. Conditions that appear after the tap are not conditions the user agreed to.

03
Freely given — two buttons of equal weight

Same size, same position, same tap target, no pre-selection. A decline that is harder to reach than an accept is the single most common reason a consent flow fails review.

04
Unambiguous — nothing runs before the tap

The SDK stays inactive until a grant exists. On decline it does not initialise, does not retry, and does not ask again on the next launch.

05
Withdrawable — one tap, in settings

Withdrawal has to be as easy as granting. The revocation is written to the log and honored on the device within seconds, not at the next session.

Every decision leaves a receipt.

A grant and a withdrawal are the same kind of record. That is what makes the consent state auditable rather than assumed.

Consent receipt contains
Timestamp2026-08-12T11:02:44Z
Policy versionaup 1.2 · pp 1.4
Scopebandwidth_share
Withdrawalsame record type
Choicegranted
Never collected
Page content or traffic bodies
Browsing history
Files, photos, contacts, messages
Precise location
Anything tied to a personal identity

One master list, enforced at the gateway.

Not a statement of intent. Requests to prohibited categories are dropped before they leave our infrastructure.

Acceptable use categories and their status
No.CategoryExamplesStatus
01Public web dataPrice monitoring, ad verification, brand protection, market researchPERMITTED
02Search results & SERPRank tracking, visibility monitoring at documented ratesPERMITTED
03Critical infrastructureEnergy, utilities, telecom, transportation, emergency servicesPROHIBITED
04Email, cloud & productivityEmail providers, cloud storage, collaboration platformsPROHIBITED
05Financial infrastructureBanks, payment systems, card networks, crypto exchangesPROHIBITED
06Government & military.gov, .mil, law enforcement, public administrationPROHIBITED
07Healthcare & educationMedical databases, .edu, student information systemsPROHIBITED
08Account creation & abuseBulk registration, credential stuffing, ticket and sneaker botsPROHIBITED
09Attack trafficDDoS, port scanning, vulnerability probing, malware distributionPROHIBITED

Four steps, one gate.

Prohibited destinations are dropped at our gateway, in the EU — not on the user's device, and not on trust.

01
Integrate the SDK

Async, off the UI thread, inactive until consent exists.

02
The user opts in

One dialog, two equal buttons, a written record either way.

03
Idle bandwidth is shared

Wi-Fi only, charging only. Filtered and logged at the EU gateway.

04
You get paid per device

Per consenting active device, monthly, terms set in the agreement.

prohibited destinations dropped at the gatewayread the full mechanics →

Data and jurisdiction.

Controlling entity
NextGen Connectivity OÜ
Governing law
Estonian law, EU regulation
Gateway location
European Union
Sub-processors
Sumsub — identity verification

Store readiness.

What a partner gets for the review process, so the store conversation is not improvised:

store_safety_kit · contents
01A consent flow that already meets the platform requirements
02Wording for Google Play Data Safety and Apple Privacy Nutrition Labels
03Prepared answers to the questions reviewers ask about bandwidth SDKs
04A named contact if a reviewer escalates
descriptions now · document links after the SDK build
Founding partners — closed pilot

First in, best terms.

A limited set of founding partners get elevated rates, a direct line to the team, and a say in the SDK roadmap.

Request access