Ethics & safety

The page for skeptics. We wrote it first.

"Bandwidth sharing" has earned its reputation problem. Here is exactly who uses the traffic, what can never be reached through it, what happens when someone looks suspicious, and where the money comes from. If anything on this page is unclear, ask us: partnerships@cashraven.io.

Where the traffic goes

Public web data. The boring kind.

The bandwidth is bought through Rayobyte, our own brand, in business since 2015, by consumers and businesses collecting publicly available web data. Collecting public data is legal, and you already benefit from it every day:

  • E-commerce price monitoring: the comparison data that keeps retailers honest and prices lower.
  • Flight & hotel search: the engines you compare fares on are built on scraped public availability.
  • AI training & tooling: the assistants and tools you use are powered by public web data.
  • SEO, ad verification & market research: checking that what's published is what's shown.

It pays for real work too. Read how one Rayobyte customer built data-collection jobs in South Africa: rayobyte.com/stories/kirstin-barth.

Blocked by default — for everyone
All .gov and .edu domains.
Banks and financial institutions, card processors, PayPal-type payment sites.
Login and authentication endpoints, plus API endpoints a residential network should never need.
Any domain with a reported abuse complaint, added permanently for every customer. The list only ever grows.
Your users' local networks and sensitive ports, blocked in the compiled SDK core itself.

Only strictly vetted businesses with a legitimate, documented use case are ever considered for an exception to parts of this list.

What happens when someone looks suspicious

Alert policies watch every customer. Trip one, and you're identifying yourself.

  1. TRIGGERS

    Suspicious behaviour

    Requests toward sensitive endpoints, request patterns that don't look like data collection, unusual volume against a single site. Every customer runs under usage limits and these alerts from day one.

  2. RESPONSE

    KYC via Sumsub

    The customer is identity-verified through Sumsub and must document a legitimate use case before another request goes out. No verification, no traffic.

  3. OUTCOME

    Verified — or gone

    Legitimate users continue under their limits. Everyone else is cut off, and anything they touched joins the permanent blacklist for all customers.

Users hold the switch

Opt-in required. Opt-out required. Sometimes we opt them out ourselves.

Sharing can't start until the user accepts the consent agreement; the SDK has no other code path. Every app must ship a visible opt-out control, and we check for it before approval. When a protection trigger hits, the SDK opts the device out on its own without waiting for anyone.

Publishers are verified too

We KYC the people we pay.

Every developer is verified before payout, and compliance reviews every build for a working opt-out before the device cap lifts. Not because we enjoy paperwork, but because a network is only worth joining if everyone on it was checked. That goes for the people we pay as much as the people who pay us.

See it working today

Don't take our word for it. Install it.

The consumer Cash Raven app on Google Play runs this exact engine: consent screen, caps, auto-opt-out and all. Per-platform sample apps are downloadable from the developer portal too; they're plain reference builds (we spent the design budget on the SDK, not their UI), but the behaviour is the real thing.

Still skeptical? Good. Bring questions.

We'd rather answer hard questions before you integrate than after. Or sign up free and inspect everything yourself.