1. Scope
This Privacy Policy applies to Lucky District, its mobile app, related player support, and services operated by Bunny Dash (collectively, the “Services”). Some features may not be available in every build, platform, or territory.
2. Information we collect
Account and profile information
We may collect a player identifier, authentication token, nickname, selected profile details, and identifiers from Apple Game Center when Game Center is available and signed in on your device. On Android, we may collect Google Play Games identifiers when an existing Play Games profile is automatically authenticated for this game.
When Game Center is signed in, the app automatically sends us an Apple-signed team player identifier and verification proof at launch so we can connect or restore the correct Lucky District account. We retain a one-way hash of that identifier, not the original Game Center identifier. Your Game Center display name is sent separately from that proof. If you have not chosen your own Lucky District nickname, we automatically use the display name as your rankings nickname and keep it in sync. Once you choose your own nickname, we do not overwrite it or retain later Game Center display names in your profile. We never use a display name to identify, connect, restore, or merge accounts.
On Android, Google Play Games Services checks for an existing Play Games profile when the app starts. If one is available, the app sends us a single-use server authorization code. Our server exchanges that code with Google and receives the game-specific Play Games player identifier and display name. We retain a one-way hash of the player identifier, not the original identifier. We do not retain the display name unless you choose to use it as your Lucky District nickname. We do not request your Google email address, additional Google profile details, or a long-lived refresh token for this connection. We do not use Play Games Saved Games or directly read files from your Google Drive. If you do not have a Play Games profile, you can continue as a guest without being required to create one.
Gameplay and virtual economy information
We process game progress, home and item state, virtual-currency balances, virtual transactions, game sessions, rewards, scores, and leaderboard activity so the game can save and restore your progress.
Friends and referral information
To provide friends and invitations, we process your public player identifier and nickname, friend requests, accepted friendships, blocked relationships, invitation claims, qualification progress, and referral reward status. Friends may see your public nickname, title, housing progress score, and friends-leaderboard rank. District rankings also show the combined total of your current virtual cash and chips to other players in your league and to your friends. Home, furniture, room, and exterior upgrade values are excluded. Chip rankings may also display your current virtual chip balance. Other players do not see your transaction history.
We issue an opaque token for an invitation link and retain a cryptographic digest of that token on our server. Sharing a link does not itself earn a reward. A reward can be considered only after a new player opens or installs the app through the link, accepts the friend request, and completes the stated in-game requirement. We do not access your device contacts, Facebook account, or Facebook friends list for this feature.
Gameplay analytics
We use Google Firebase Analytics to measure app sessions, screen and casino-game entries, low virtual-currency prompts, reward screens, and purchase-screen interactions. After your Lucky District player account is established or restored, our server provides the app with a separate pseudonymous analytics identifier. It is created with a one-way keyed function and is not your player ID, nickname, email address, Game Center identifier, or Play Games identifier. We use it to connect these product events with authoritative game-session and virtual-economy facts for game design and reliability analysis. We do not use this information for advertising, marketing, or cross-app tracking.
We also measure which tutorial steps were displayed or advanced, time spent on those steps, the first interaction after loading, reward and notification choices, game-loading stages, and the last screen before the app moved to the background. These records use step identifiers, not dialogue text, touch coordinates, or text you enter. An interruption alone does not tell us whether you chose to leave or the app failed.
Product analytics may record that a friends screen or invitation explanation was viewed, that sharing was started, or that a friend request was reviewed. Server analytics may record the invitation claim, request acceptance, qualification, and reward stages. These events use pseudonymous identifiers and do not include invitation tokens, friendship identifiers, public player identifiers, or nicknames.
Install attribution analytics
We use AppsFlyer to measure app installs, sessions, casino-game entry, checkout initiation, low virtual-currency prompts, and slot engagement milestones such as sustained play and next-day return. AppsFlyer may process a per-install AppsFlyer identifier, app and device information, event timestamps, IP-derived approximate location, and app-store or campaign referral information for attribution, analytics, and fraud prevention. We do not send AppsFlyer your Lucky District player ID, Firebase analytics user ID, nickname, email address, purchase transaction identifier, or receipt.
For purchases, our server sends AppsFlyer the verified product, quantity, amount, currency, purchase or refund time, and an opaque event reference together with the purchasing installation's AppsFlyer ID and reported OS version. The amount is the one the store confirmed for that order, and we do not send the payment method, billing address, or store receipt. We use these records to measure purchases and adjust revenue when the store confirms a refund or refund reversal. Test purchases are measured separately from real revenue. We block sharing these individual iOS events with advertising partners. On Android, these purchase events may reach an advertising partner we have activated, as described below.
For slot engagement during the first 48 hours after account creation, our server checks completed regular spins and limited foreground activity reports. When a milestone is reached, we send its name, game, active duration, spin count, time, and an opaque event reference with the installation's AppsFlyer ID and OS version. These events contain no purchase value. Individual iOS events remain blocked from advertising partners; enabled Android partners may receive them to improve campaigns.
AppsFlyer OneLink invitation links carry the opaque invitation token and campaign information needed to return the player to the invitation flow after opening or installing the app. AppsFlyer attribution is used to deliver this app feature and measure the invitation flow. The reward decision remains on our server and is not based on which sharing app the inviter selected.
The iOS app uses AppsFlyer's Strict SDK without IDFA or AdSupport and does not display the App Tracking Transparency prompt. Apple's SKAdNetwork and AdAttributionKit may still provide privacy-preserving aggregate attribution postbacks. On Android, AppsFlyer may collect the Google Advertising ID, a user-resettable and user-deletable identifier, to match installs and the limited events above with advertising campaigns and to prevent attribution fraud. We continue to disable Android App Set ID collection, Firebase Advertising ID collection, and Firebase ad personalization signals. We do not use AppsFlyer customer user IDs.
AppsFlyer may send Android campaign attribution information to an advertising partner only after we separately activate that partner for Lucky District, such as Meta or Google Ads for a campaign. That information may include the Google Advertising ID, IP-derived approximate location, campaign or referral information, the limited app events listed above, and, for Android purchases, the product, amount, and currency the store confirmed. Advertising partners receive this to measure and improve the campaigns that brought players to the game. We do not enable every partner in the AppsFlyer marketplace.
Device, diagnostics, and network information
We may receive device or platform type, operating-system and app version, language or locale, event timestamps, error messages and stack traces, crash and app-hang information, WebView reload reasons, recent memory-warning state, and server logs. Network information such as an IP address may be processed for delivery, security, and fraud prevention.
On supported Android versions, a later app launch may retrieve the operating system's reason for the previous app process ending, such as a crash, unresponsive app, or low memory. We use the reason and time for diagnostics without retrieving the operating system's trace file.
We use Sentry as a diagnostics service provider for app, web, and server errors. Sentry events may include the current screen, game, home floor, app and web build, device model, operating system, and technical crash or hang details. We configure this reporting not to include your Lucky District player ID, cookies, request or response bodies and headers, URL query parameters, friendship identifiers in API paths, or stack-frame local variables. Performance tracing and session replay are disabled.
When the app creates a new account, we send our operations team a signup summary through Slack containing the available device model or type, operating system, IP-derived country, and signup time. This helps us monitor app adoption and operation. The summary does not include your player identifier, installation identifier, nickname, IP address, or full browser or app User-Agent.
We also use Slack for operational payment and support alerts. Payment alerts contain the product, quantity, store, test or renewal status, verified amount and currency when available, and server confirmation time. We do not include your account, order, or store transaction identifiers. Support alerts contain the message time and a conversation link that requires staff authentication. We do not copy support message text, attachments, or nicknames into these alerts.
Push notification information
When you allow notifications, either in the system permission prompt shown once when you open the app or through an in-game prompt, we store a random installation identifier with the push registration token issued by Google Firebase Cloud Messaging, your device time zone and language, and your notification permission state. We link these to your player account so we can send the reminders or support-reply alerts you asked for and open the right screen when you tap one. We do not create a push registration token before you grant OS notification permission. Daily reward and full rent reminders are enabled by default after permission is granted, and each can be turned off in the game. Support-reply alerts require a separate opt-in. Race reminders also require a separate opt-in for each ticket on the current device. For a race reminder, we store the ticket and installation association, scheduled and expiry times, and delivery status. These identifiers are used only to deliver the in-game notifications you enabled. They are not advertising identifiers and we do not use them for advertising, marketing, or cross-app tracking. You can turn each setting off in the game or turn notifications off entirely in your device settings.
Purchase information
If purchases are available, we receive the product identifier, transaction and original-transaction identifiers, purchase environment, status, purchase, expiration, and refund times, subscription-renewal status, and, where the store provides them, storefront, currency, and price information from Apple or Google. Google Play purchase verification does not provide the amount charged, so we read the amount and currency of that order, before tax, from the Google Play order record. We link verified purchase records to your Lucky District player account so we can deliver and restore purchases, prevent duplicate grants, process subscription changes and refunds, investigate fraud, and measure product performance. We do not retain the raw signed transaction or notification payload after verification. For Google Play, we retain the purchase token in encrypted form because it is required to recheck and complete a purchase, and we do not log it. We keep one-way hashes to find purchase records and detect duplicate or conflicting payloads. We do not receive or store your full payment-card number or Apple or Google payment-account credentials.
Support communications
If you use in-game support, we collect the text you send, any optional PNG or JPEG images you choose to attach, the linked player account, and a limited snapshot of app context recorded when the conversation begins. That snapshot is limited to the platform, app version, build number, locale, time zone, and latest app route and game ID. If you contact us by email, we also collect your email address and the contents of your request.
We use this information to respond to support requests, including error, purchase or payment, and feedback inquiries. Do not share passwords or full payment-card numbers in support messages or images.
If you report a player, we collect the reported player's public ID, nickname at the time of the report, selected reason, and any details you provide. We link the report to your support conversation to review inappropriate content, unwanted contact, and suspected cheating. Only you and our authorized support team can view your report. We do not notify the reported player or send report contents to analytics services.
3. How we use information
- Provide, maintain, and personalize the Services.
- Save progress and operate virtual balances and transactions.
- Operate friend requests, friends rankings, invitations, and referral rewards.
- Verify purchases, provide subscriptions, and process refunds.
- Authenticate players and protect accounts.
- Respond to support requests, including error, purchase or payment, and feedback inquiries, as well as deletion and privacy requests.
- Measure reliability, diagnose errors, and improve game design.
- Measure app-install and campaign attribution, evaluate acquisition performance, and prevent attribution fraud.
- Send the in-game notifications you turned on, and measure whether they helped, without using them for advertising or marketing.
- Detect abuse, cheating, fraud, and security incidents.
- Meet legal, accounting, and regulatory obligations.
4. How we share information
We may share information only as needed with:
- Apple, Google, and other platform operators for distribution, platform sign-in, purchases, and fraud prevention.
- Hosting, storage, analytics, diagnostics, security, and customer support providers working on our behalf, including Google Firebase, AppsFlyer, Sentry, and Slack where those services are enabled.
- Advertising partners that we explicitly activate, such as Google Ads, to attribute Android installs and limited in-app events to campaigns, measure campaign performance, and prevent attribution fraud.
- Authorities or other parties when required by law or reasonably necessary to protect players, the Services, or legal rights.
- Other Lucky District players who view rankings, limited to your public nickname, title, score, and rank. Friend requests and friends rankings also display the public profile and housing progress information described above. District rankings display the combined cash and chip total described above, and chip rankings display your chip balance. Your transaction history is not shown to other players.
- A successor in connection with a merger, financing, acquisition, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell your personal information for money.
In-game support images are stored in a dedicated private Amazon S3 bucket with public access blocked. Access is limited to authorized support operators and background processing services acting on our behalf. Operators receive only short-lived signed links when they need to view an image.
5. Retention
We keep information for as long as reasonably needed to provide the Services, protect security, resolve disputes, and meet legal or accounting obligations. Retention periods vary by data type. When information is no longer needed, we delete or de-identify it.
Detailed notification records, including support-reply push delivery status and race reminder schedules and delivery status, are kept for up to 14 days and then deleted; only de-identified daily counts are kept longer. If a push registration token becomes invalid, we delete it as soon as the notification service tells us.
Support images that are still not attached to a message after 24 hours are scheduled for deletion. Rejected or failed support uploads are also scheduled for deletion. We retry temporary storage deletion failures until they complete. Unless you delete your account earlier, resolved in-game support conversations, messages, attachment records, and private support images are kept for up to 180 days after resolution and then deleted. Player reports follow this same rule and are removed if the reporting player deletes their account. If a reported player deletes their account, their public ID and nickname in another player's report remain subject to the support conversation retention period.
Diagnostic events are retained under our configured provider retention settings and are deleted or de-identified when they are no longer needed for reliability, security, or support. Sentry diagnostic events are not assigned your Lucky District player ID.
AppsFlyer attribution and event records are retained under our configured provider settings and are not assigned your Lucky District player ID or pseudonymous Firebase analytics user ID. On our server, the link between an AppsFlyer installation and a purchase is retained for up to 180 days. Slot engagement installation links and activity progress are cleared by daily cleanup after 7 days; milestone delivery records are cleared after 30 days. Account deletion removes that server-side link and queued events. Requests about data already sent to AppsFlyer can be sent to our privacy contact below.
Raw pseudonymous gameplay analytics and server analytics facts are kept for up to 90 days. De-identified daily aggregates may be kept for up to 24 months. Deleting your player account removes the account-side data and the remaining link to its pseudonymous analytics identifier; raw analytics then expires under the retention period above.
To reduce missing events, the app can keep up to 100 pending interaction records and one last-session checkpoint on your device. Records older than 24 hours are discarded the next time the app processes them. Pending records are removed when you switch or delete accounts or when analytics collection is disabled. If the app is not running, cleanup takes place when it is next used. We do not resend one account's pending records under another account.
Operational Slack notification delivery records are deleted by a daily cleanup after seven days. Signup delivery records are not linked to a player account. Payment and support delivery records are linked to their source transaction or message and are also removed when that source is deleted, including during account deletion. Messages already sent to our internal Slack channels follow our workspace retention settings. Contact us using the privacy contact below about these records.
Friend requests, accepted friendships, and referral progress are kept while needed to provide the feature. Removing a friend hides both players from each other's friends list and friends rankings. We keep each player's block separately until that player unblocks the other or either account is deleted. Deleting either account removes relationships and referral claims that identify that player. Invitation token digests issued by a player are removed when that player deletes the account.
Account-linked purchase, transaction, and subscription records are kept while needed to provide purchases, prevent duplicate grants, handle refunds and disputes, and meet legal, tax, or accounting requirements. Deleting your player account removes the account-side purchase records unless limited records must be retained for one of those legal purposes. Apple or Google may retain their own platform purchase history under their policies.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, or to object to or restrict certain processing. We may need to verify your request before acting on it.
You can permanently delete your Lucky District account by opening Menu, then Settings, Manage Account, and Delete Account in the app. If you cannot access the app, follow the alternate request steps on our account deletion page. You can stop future Game Center verification by signing out of Game Center in your device settings. You can manage the Play Games profile used for Lucky District in your Android or Google Play Games settings. On Android, you can reset or delete your Google Advertising ID in your device's privacy and ads settings; deleting it prevents apps from receiving the prior identifier. For other privacy requests, email privacy@bunnydash.net.
In the friends screen, you can decline a pending request or remove an accepted friend. Removing a friend removes the relationship and hides that player from your friends list and friends rankings. It does not prevent either player from appearing in the same district league. Use a friend's options menu, or tap another player's nickname in rankings, invitations, or a friend request, to report or block them. Blocking removes the friendship, prevents new friend requests, and hides you from each other in rankings and invitations. In Settings, open Blocked Players to undo your block. Unblocking does not restore friendship or remove a block placed by the other player.
7. Children
The Services are not directed to children under 13. Additional or higher age restrictions may apply based on the app’s rating and local law. If you believe a child provided personal information contrary to these rules, contact us so we can investigate and take appropriate action.
8. International processing and security
Information may be processed in countries other than the one where you live. We use reasonable administrative, technical, and physical safeguards, but no transmission or storage system is completely secure.
9. Changes to this policy
We may update this policy as the Services or legal requirements change. We will post the revised policy here and update the effective date. Where required, we will provide additional notice.
10. Contact us
Privacy questions or requests: privacy@bunnydash.net
General support: support@bunnydash.net
Operator: Bunny Dash
