Privacy Policy

May I Rummy · Back to app

Last updated: 19 June 2026

May I Rummy ("the app", "we", "our") is a card game you can play in a browser or as an iOS or Android app. This page explains what personal information we collect, why, who we share it with, and the rights you have over your data.

What we store, in plain words:

No ads. No analytics. No selling your data. No tracking across other apps or sites.

1. Who we are

The app is operated by an individual developer based in New Jersey, United States. You can reach us at mayirummy@gmail.com for any privacy question.

2. What we collect

2.1 Account information (only when you sign in with Google)

We do not receive your Google password. Sign-in is handled entirely by Google.

2.2 Game data

2.3 Local device storage

We store small pieces of information in your browser's local storage and IndexedDB so the app works:

All of this is wiped when you sign out.

2.4 What we do not collect

3. Why we collect it

4. Who we share with

We do not sell your data. The third parties below process data on our behalf so the service can function:

We do not use any other third-party processors. No advertising networks, no analytics providers, no email marketing platforms.

5. How long we keep it

6. Your rights

You can:

If you are in the EU, UK, or California, you have additional rights under GDPR, UK-GDPR, or CCPA respectively (including the right to lodge a complaint with your data protection authority). Email us to exercise any of them.

7. Children and age requirements

The game itself is family-friendly and suitable for all ages — there is no violence, no chat between strangers, no gambling, and no in-app purchases.

Parents who want younger children to play should use single-player mode. If you believe a child has somehow signed in despite Google's age requirement, email us and we will delete the account.

8. International transfers

The data we collect is processed on Google's and Vercel's infrastructure, primarily in the United States. If you are accessing the app from outside the United States, your data is transferred to the United States for processing. Both providers offer standard contractual clauses for transfers from the EU.

9. Security

All traffic between your device and our servers is encrypted via HTTPS. Firebase Authentication tokens are managed by Google's SDK and stored in your browser's secure storage. Database access is governed by per-collection rules that prevent users from reading other users' private data.

We use Firebase App Check with reCAPTCHA v3 to make it harder for bots and abusive scripts to reach our backend. Dependencies are monitored weekly via Dependabot, and known CVEs in production code block our CI pipeline.

10. Changes to this policy

We may update this policy when we add features or change how we handle data. The "Last updated" date at the top will reflect any change. Material changes will be announced inside the app the next time you open it.

11. Contact

Questions, requests, or complaints? Email mayirummy@gmail.com. We aim to respond within 7 days.