Privacy Policy
Last updated: October 2, 2026
Rabbit Royale is a free-to-play game. We collect as little as we can: no email, no password, no phone number, no real name. We show no ads and sell no data. We do measure how the Game is played and collect crash reports, with Google Firebase, to make it better — and if you are in Europe, we only measure with your permission.
This policy covers the game at rabbit.rip, the Android app and the Solana dApp Store app (together, “the Game”), operated by the Rabbit Royale team (“we”, “us”).
1. What we collect
Your account
- Guest accounts. When you press Play, we create an anonymous account identified by a random ID. Nothing about you or your device is collected to do this.
- Wallet accounts. If you connect a Solana wallet (Phantom, Solflare, Backpack, Seed Vault through Mobile Wallet Adapter…), we store your public wallet address. You prove you own it by signing a text message; this signature never moves funds and we never see your private key or seed phrase.
- Profile. Your rabbit name (random at first, you can change it), the avatar you pick from the Game's built-in characters, when the account was created and when you last played.
Your game
Game progress and state: carrots and score, energy, items, your burrow layout, quests, seasons and rankings, and your interactions with other players (raids, traps, fences and other in-game actions).
Purchases
If you buy an item with USDC, SOL or SKR, we record the item, the amount, the token, the price in USD, and the Solana transaction signature so we can verify the payment and deliver the item. Payments go straight from your wallet to ours on the Solana blockchain: we never handle cards or bank details.
Technical data
Like any web server, ours sees your IP address and browser details when you connect. They may appear in short-lived server logs used for security and debugging; we do not store them in your account or use them to track you.
How you play (analytics)
We use Google Analytics for Firebase to understand how the Game is played: which screens you open and for how long, where you tap (the position on the screen and the button touched), how far you get in the tutorial, your games, raids and defences, the items you buy, and when you pause or leave. These events are linked to your player ID, not to your name.
Firebase also collects, on its own, your device model, operating system, app version, language, screen
size, a random app-instance ID and your approximate location (country and region, worked out by Google
from your IP address — we never see a precise location). On Android it uses your device's
advertising ID; on the web it sets Google Analytics cookies (_ga,
_ga_*). If you are signed in to a Google account that allows it, Google may add
estimated age range, gender and interests to our reports; we only ever see these as
totals across many players, never for you alone. We do not show ads and do not use any of this to
target ads.
In the European Union, the EEA, the UK and Switzerland, the Game asks for your consent the first time you open it, and nothing is measured unless you accept (refusing is as easy as accepting). Elsewhere, measurement is on by default. Everywhere, you can change your choice at any time in the Game's settings.
Crash reports
When the Game crashes or hits an error, a report is sent so we can fix it: what went wrong and where in the code, the screen you were on, your level, the app version, your device model and operating system, and your player ID. On Android this goes through Firebase Crashlytics; on the web, errors are reported through Google Analytics. Crash reports are sent whatever your analytics choice, because we need them to keep the Game working (our legitimate interest); they contain nothing about your game beyond the moment of the crash.
Push notifications (Android and web)
If you allow notifications — the Game asks after your first real game, never before — we store a device token from Google Firebase Cloud Messaging, with your language and your time zone offset, so we can send them in your language and never at night. We use them to tell you that your burrow is being raided or was raided, that your garden is full, that your energy is full, or, once or twice, that you have not played for a while. At most a few per day. You can turn them off at any time in your phone or browser settings; the token is deleted when you sign out, when it stops working, or with your account.
2. What stays on your device
The Game keeps a few things in your browser storage or the app's local files: your session (so you stay
signed in), your language, sound settings, your analytics and notification choices, and a few “already
seen” flags for the tutorial. The website sets one cookie of its own, rr_session, which
keeps you signed in for up to 30 days, and — only if measurement is on — the Google Analytics cookies
described above. None of these are used for advertising or cross-site tracking.
A guest account exists only through the session stored on your device. If you clear your browser data or uninstall the app, a guest account cannot be recovered. Connect a wallet to keep your progress.
3. Why we use it
- To run the Game: save your progress, match you with other players, keep the leaderboard.
- To verify and deliver purchases.
- To send the notifications you asked for.
- To understand how the Game is played — where players get stuck, what they use — and improve it.
- To find and fix crashes and bugs.
- To keep the Game fair and secure: stop cheating, abuse and attacks.
We do not sell your data, share it with advertisers, or use it to build advertising profiles. Where the law asks for a legal basis, we rely on the performance of our agreement with you (running the Game you signed up for and sending the notifications you allowed), your consent for analytics in the EU, EEA, UK and Switzerland (you can withdraw it at any time in the settings), and our legitimate interest in measuring and improving the Game elsewhere, fixing crashes and keeping it secure.
4. What other players see
Rabbit Royale is multiplayer. Other players can see your rabbit name, avatar, score, burrow level and whether you are online, on the leaderboard and on the islands. Your burrow can be visited and raided. If you play with a wallet, your wallet address may be visible to other players.
Anything done on the Solana blockchain (your wallet address, payments) is public by design and cannot be erased by us or anyone else.
5. Who else processes data
- Our servers, which we run ourselves, host the Game, its database and its cache.
- Solana RPC provider (Alchemy): relays requests to the Solana blockchain and notifies us when a payment reaches our wallet.
- Jupiter: our server asks it for SOL and SKR prices. No data about you is sent.
- Google (Firebase): Google Analytics for Firebase measures how the Game is played, Firebase Crashlytics collects crash reports, and Firebase Cloud Messaging delivers push notifications. Analytics data may also be exported to Google BigQuery, in our own Google Cloud project, for our analysis. Google may process this data outside your country, including in the United States, under the EU–US Data Privacy Framework and standard contractual clauses. See Firebase's privacy information and Google's privacy policy.
- Google Fonts: serves the fonts of this website; your browser fetches them from Google.
- Your wallet app (Phantom, Solflare, Seed Vault…) has its own privacy policy, which applies to what you do in it.
6. How long we keep it
- Guest accounts are deleted automatically after 30 days without playing (after 1 day if you never finished a first game), or immediately when you abandon them from the Game.
- Wallet accounts are kept while you play, and deleted on request.
- Purchase records are kept as long as needed for accounting and to handle disputes.
- Server logs are kept for a short period and then rotated.
- Analytics events are kept for 14 months by Google Analytics, then deleted.
- Crash reports are kept for 90 days by Firebase Crashlytics.
- Notification tokens are deleted when you sign out, when they stop working, or with your account.
7. Your rights
You can ask us for a copy of your data, to correct it, or to delete your account. Guests can delete their account themselves from the Game. For a wallet account, write to us from the contact below with your wallet address; we may ask you to sign a message to prove it is yours. You can withdraw your analytics consent at any time in the Game's settings, and turn notifications off in your device settings. Depending on where you live (for example in the EU or UK), you may also have the right to object, to restrict processing and to complain to your data protection authority.
8. Children
The Game is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child under 13 has an account, contact us and we will delete it.
9. Security
Connections to the Game are encrypted (HTTPS), sessions are signed, and we store no passwords or private keys. No system is perfectly secure, but we keep what we hold to the minimum.
10. Changes
If this policy changes, we will update it here and change the date at the top. For significant changes, we will let you know in the Game.
11. Contact
Questions or requests: contact@gravity5.pro, or a direct message to @RabbitRoyaleX on X.