Privacy policy
Effective date: 4 September 2026. Applies to the MyMafia app
(com.mymafia.app) and the game service at
api.mymafia.app, both operated by RemNet, Netherlands.
In short: MyMafia is an online game, so it does need an account and it does store your progress on a server. It contains no advertising, no analytics or tracking SDKs, and no real-money payments of any kind. Nothing is sold or shared for marketing. You can have the whole account erased on request.
Our other app, Vacation Mode, collects nothing at all. MyMafia is different and it is worth being plain about why: the game is played against other people, on a shared server, so your account and your progress have to exist somewhere other than your phone. This page describes exactly what that means.
1. Who is responsible
RemNet, a development studio in the Netherlands, is the data controller. For any question about this policy, or to exercise any of the rights in section 7, email support@remnet.io.
2. What we store, and why
Your account
- Username and email address. Used to identify you and to sign you in. The email address is also the only way we can reach you about your account.
- Your password, hashed. Stored as a bcrypt hash, never as text. We cannot read it, and neither can anyone who obtains the database.
- Your display name. Visible to other players, which is the point of it.
A linked Google account, only if you choose to link one
If you sign in with Google, or connect Google from the app's settings, we store Google's stable account identifier for you and the email address on that Google account. The identifier is what signs you in; the address is stored only so the settings screen can show you which Google account is connected. We never receive your Google password, and we ask Google for nothing beyond your basic profile and email.
Your game progress
Level, experience, money, reputation, inventory, family membership, and a record of the actions you take in the game: crimes attempted, fights, casino rounds, jobs, and every movement of in-game currency. This is what a saved game is. The currency record also exists so that if someone finds a way to cheat, we can see it happen and put it right rather than guess.
Your device, for notifications
If you allow notifications, we store the push token your device issues and whether it is an Android or an iOS device. Decline notifications, or turn them off later, and no token is stored. Nothing else about your device is collected: no advertising identifier, no device fingerprint, no contacts, no location.
Technical records
- Sign-in sessions. Each active session is stored as a hash, with the browser or app version string your device sent, so you can be signed out everywhere if you ever need to be.
- IP addresses. These appear in our server logs and are used to limit how often anyone can hit the service, which is what stops one person overwhelming it or brute-forcing passwords. Logs are short-lived, and the rate-limiting records expire within minutes.
3. What we do not do
Being specific is more useful than a general reassurance, so:
- No advertising, and no advertising identifiers.
- No analytics, telemetry, attribution or crash-reporting SDK. There is no Facebook SDK, no AppsFlyer, no Firebase Analytics, no Sentry.
- No selling, renting or sharing of personal data, for marketing or otherwise.
- No profiling and no automated decision-making about you as a person.
- No real-money payments. There are no in-app purchases and no subscriptions; everything in the game is bought with money the game gave you. We never see a payment card, because there is nothing to pay for.
- No access to your contacts, photos, microphone, files or location. The app asks only for permission to send notifications and to vibrate.
4. Our legal basis
Under the GDPR we rely on:
- Performance of a contract for your account and your game progress. Without these the game cannot work at all.
- Legitimate interests for security and abuse prevention: rate limiting, sign-in session records, server logs and the in-game currency record. Our interest is keeping a shared game fair and available; the data involved is minimal and short-lived.
- Consent for push notifications, which you give by allowing them and withdraw by turning them off. Withdrawing it costs you nothing else.
5. Who else processes it
We use as few outside parties as we can, and none of them are advertising companies:
- Hetzner Online GmbH, Germany, hosts the server and therefore the database. Data stays in the EU.
- Cloudflare sits in front of the service to absorb attacks and to serve it over an encrypted connection. It necessarily sees the IP address of each request.
- Google verifies your identity, but only if you chose to use Google sign-in. If you did not, Google is not involved.
- Expo (Expo, Inc., United States) delivers push notifications to your device. It receives only the push token and the notification text, and only when a notification is actually sent. This is the one processor outside the EU; it handles no account data and nothing else about you.
Each of these acts on our instructions as a processor. None of them receives your data for their own purposes.
6. How long we keep it
- Your account and progress, for as long as the account exists. Ask us to delete it and it goes.
- Server logs, for a matter of days, then they roll away.
- Rate-limiting records, minutes.
- Sign-in sessions, until they expire or you sign out. Signing out genuinely invalidates the session on the server rather than only forgetting it on your device.
- Push tokens, until you disable notifications, uninstall the app, or the account is deleted.
7. Your rights
You can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable form, restrict what we do with it, or object to our relying on legitimate interests. Email support@remnet.io and we will answer within a month. There is a separate page about account deletion, because it is the request people most often want and it should be easy to find.
We do not require a reason and we will not make the game worse for you for asking. If you are unhappy with how we have handled it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
8. Children
MyMafia is not intended for children. The game is built around crime as a theme and includes simulated gambling with in-game money, so it is for players aged 16 and over. We do not knowingly create accounts for children. If you believe a child has an account, email us and we will remove it.
9. Security
All traffic between the app and the server is encrypted. Passwords are stored only as bcrypt hashes, and session tokens only as hashes, so neither can be read back out of the database. Sessions are short-lived and rotate, and reusing an old one invalidates the whole chain. The database and cache are not reachable from the internet at all; only the game service can talk to them.
No system is perfect. If you find a security problem, please tell us at support@remnet.io before telling anyone else, and we will credit you if you would like us to.
10. Changes to this policy
If this policy changes in a way that affects you, we will change the effective date above and say so in the app. We will not quietly start collecting something new.
11. Contact
RemNet, Netherlands · support@remnet.io