Rabbit Royale

Privacy Policy

Last updated: October 2, 2026

Rabbit Royale is a free-to-play game. We collect as little as we can: no email, no password, no phone number, no real name. We show no ads and sell no data. We do measure how the Game is played and collect crash reports, with Google Firebase, to make it better — and if you are in Europe, we only measure with your permission.

This policy covers the game at rabbit.rip, the Android app and the Solana dApp Store app (together, “the Game”), operated by the Rabbit Royale team (“we”, “us”).

1. What we collect

Your account

Your game

Game progress and state: carrots and score, energy, items, your burrow layout, quests, seasons and rankings, and your interactions with other players (raids, traps, fences and other in-game actions).

Purchases

If you buy an item with USDC, SOL or SKR, we record the item, the amount, the token, the price in USD, and the Solana transaction signature so we can verify the payment and deliver the item. Payments go straight from your wallet to ours on the Solana blockchain: we never handle cards or bank details.

Technical data

Like any web server, ours sees your IP address and browser details when you connect. They may appear in short-lived server logs used for security and debugging; we do not store them in your account or use them to track you.

How you play (analytics)

We use Google Analytics for Firebase to understand how the Game is played: which screens you open and for how long, where you tap (the position on the screen and the button touched), how far you get in the tutorial, your games, raids and defences, the items you buy, and when you pause or leave. These events are linked to your player ID, not to your name.

Firebase also collects, on its own, your device model, operating system, app version, language, screen size, a random app-instance ID and your approximate location (country and region, worked out by Google from your IP address — we never see a precise location). On Android it uses your device's advertising ID; on the web it sets Google Analytics cookies (_ga, _ga_*). If you are signed in to a Google account that allows it, Google may add estimated age range, gender and interests to our reports; we only ever see these as totals across many players, never for you alone. We do not show ads and do not use any of this to target ads.

In the European Union, the EEA, the UK and Switzerland, the Game asks for your consent the first time you open it, and nothing is measured unless you accept (refusing is as easy as accepting). Elsewhere, measurement is on by default. Everywhere, you can change your choice at any time in the Game's settings.

Crash reports

When the Game crashes or hits an error, a report is sent so we can fix it: what went wrong and where in the code, the screen you were on, your level, the app version, your device model and operating system, and your player ID. On Android this goes through Firebase Crashlytics; on the web, errors are reported through Google Analytics. Crash reports are sent whatever your analytics choice, because we need them to keep the Game working (our legitimate interest); they contain nothing about your game beyond the moment of the crash.

Push notifications (Android and web)

If you allow notifications — the Game asks after your first real game, never before — we store a device token from Google Firebase Cloud Messaging, with your language and your time zone offset, so we can send them in your language and never at night. We use them to tell you that your burrow is being raided or was raided, that your garden is full, that your energy is full, or, once or twice, that you have not played for a while. At most a few per day. You can turn them off at any time in your phone or browser settings; the token is deleted when you sign out, when it stops working, or with your account.

2. What stays on your device

The Game keeps a few things in your browser storage or the app's local files: your session (so you stay signed in), your language, sound settings, your analytics and notification choices, and a few “already seen” flags for the tutorial. The website sets one cookie of its own, rr_session, which keeps you signed in for up to 30 days, and — only if measurement is on — the Google Analytics cookies described above. None of these are used for advertising or cross-site tracking.

A guest account exists only through the session stored on your device. If you clear your browser data or uninstall the app, a guest account cannot be recovered. Connect a wallet to keep your progress.

3. Why we use it

We do not sell your data, share it with advertisers, or use it to build advertising profiles. Where the law asks for a legal basis, we rely on the performance of our agreement with you (running the Game you signed up for and sending the notifications you allowed), your consent for analytics in the EU, EEA, UK and Switzerland (you can withdraw it at any time in the settings), and our legitimate interest in measuring and improving the Game elsewhere, fixing crashes and keeping it secure.

4. What other players see

Rabbit Royale is multiplayer. Other players can see your rabbit name, avatar, score, burrow level and whether you are online, on the leaderboard and on the islands. Your burrow can be visited and raided. If you play with a wallet, your wallet address may be visible to other players.

Anything done on the Solana blockchain (your wallet address, payments) is public by design and cannot be erased by us or anyone else.

5. Who else processes data

6. How long we keep it

7. Your rights

You can ask us for a copy of your data, to correct it, or to delete your account. Guests can delete their account themselves from the Game. For a wallet account, write to us from the contact below with your wallet address; we may ask you to sign a message to prove it is yours. You can withdraw your analytics consent at any time in the Game's settings, and turn notifications off in your device settings. Depending on where you live (for example in the EU or UK), you may also have the right to object, to restrict processing and to complain to your data protection authority.

8. Children

The Game is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child under 13 has an account, contact us and we will delete it.

9. Security

Connections to the Game are encrypted (HTTPS), sessions are signed, and we store no passwords or private keys. No system is perfectly secure, but we keep what we hold to the minimum.

10. Changes

If this policy changes, we will update it here and change the date at the top. For significant changes, we will let you know in the Game.

11. Contact

Questions or requests: contact@gravity5.pro, or a direct message to @RabbitRoyaleX on X.