Privacy Policy
Effective date: September 27, 2026
Majlis (مجلس) is a free app for classic card games, made by AMB Ltd. ("we", "us"). This policy explains what the Majlis app and its game server collect, why, who can see it, how long it is kept and how you delete it, for every game on Majlis today and any added later.
The short version
- No ads. We do not sell your data or share it for advertising.
- No real money. Majlis has no gambling and no purchases. Points and levels have no cash value.
- Analytics and crash reports are off until you switch them on, and you can switch them off again in Settings.
- Push notifications are off until you turn them on in Settings.
- You can delete your account inside the app, or ask us by email.
1. What we collect and why
Your account
- Guest account. When you first open Majlis you are signed in anonymously through Google Firebase Authentication. This creates a random account ID. You do not need to give an email to play.
- Optional email or Google sign-in. If you link an email address and password, or a Google account, Firebase Authentication stores that email address (and, for Google, the name and photo link on your Google account). Our game server never stores your email address or password; it receives a signed sign-in token and keeps only your account ID.
- Display name. The name other players see at the table, in friends lists and on leaderboards. You choose it and can change it in your Profile. Until you choose one, you are shown as a neutral "Player 1234" (in Arabic, "لاعب 1234"), made from your random account ID. We never use your Google account name or your email address as your display name.
- Username. An optional @handle, available only to accounts with email or Google linked, so other players can send you a friend request by typing it exactly or from a table you share. There is no public directory of users.
- Profile photo (optional). If you add one from your camera or gallery, the app crops it and re-draws it on your phone as a small square image (about 256×256 pixels). Only the pixels are uploaded — no location or camera metadata. It is stored on our game server (Cloudflare) and shown to other signed-in players. You can remove it at any time.
Playing
- Tables and matches. The tables you create or join, your seat, the game, the join code and invite links (invite links expire after 24 hours). Your cards are dealt and kept on the server and are only sent to you.
- Public tables. If a host makes a table public, it is listed in the app so any signed-in player can join it, showing the game, the host's display name and level, and how many seats are taken. Once seated, everyone at the table sees each other's names, photos and levels.
- Match results. A record of each finished online match (game, scores by seat, time). These records do not contain your account ID or name.
- Points and levels. Points earned in online matches, your level, and your weekly points. Offline practice against bots stays on your phone and earns no points.
- Leaderboards. The all-time and weekly top 100 show each player's rank, display name, profile photo and level. Guest accounts appear too. Your exact point total is shown only to you.
Friends and presence
- Friend requests, your friends list and the players you block.
- Last seen. Your friends can see when you were last active and whether you are in a match. You can turn this off in Settings.
Chat, reports and safety
- Table chat. Messages you send at a table (typed text up to 200 characters, or ready-made quick messages) are shown to the players at that table. The server keeps the last 50 typed messages of each table so that a report can be checked against what was really said (quick messages and filtered messages are not kept). Before your first message or profile photo, the app asks you once to agree to the Terms of use and community rules.
- Profanity filter. Messages and display names are checked automatically against a word list. A flagged message is hidden from everyone; a flagged name is refused. The server records when your messages were filtered (not the words), and repeated filtering can lead to a chat mute.
- Reports. You can report a player's name, photo or chat message. A report stores who reported whom, the reason, and a copy of the reported name, message or photo reference. When three different players report the same thing, the server hides it automatically (a name is replaced with "Player 1234"-style text, a photo is hidden, chat is muted for 24 hours, then 7 days, then permanently). We review reports ourselves.
Notifications (optional)
- Only if you turn on notifications in Settings, we store your device's Firebase Cloud Messaging token and platform so we can tell you about friend requests and table invites. These notifications contain the sender's display name.
Analytics and crash reports (optional, off by default)
- Analytics (Google Analytics for Firebase), only if you switch it on: counts of things like matches started and finished, invites created and connection problems. We do not send names, chat, cards, join codes or invite links. Google's SDK also collects standard device information (an app-instance ID, device model, operating system, app version, language and approximate country). Majlis does not use or collect your device's advertising ID: the app removes the advertising ID permission and turns advertising-ID collection off in Analytics.
- Crash reports (Firebase Crashlytics), only if you switch them on: the technical details of a crash (stack trace, device model, operating system, app version, a Crashlytics installation ID) plus the game being played and the connection state.
- We do not attach your account ID, name or email to analytics or crash reports.
Technical data
- IP address. Your IP address reaches Cloudflare, which runs our game server, and Google Firebase whenever the app talks to them. Our server uses it briefly to limit abuse (for example, how often an invite can be looked up from one address); only the times of recent requests are counted, not a history of what you did.
- On your phone. Your settings, language, your analytics/crash answers, an offline practice match in progress and your guest sign-in are stored on your device.
What we do not collect
We do not collect your location, contacts, phone number, payment details or any photo other than the one you choose as your profile photo.
2. Who we share it with
We do not sell personal data and do not share it with advertisers or data brokers. We use these service providers to run Majlis, and they process data on our behalf:
- Google Firebase (Google LLC): sign-in (Firebase Authentication, Google Sign-In), Analytics, Crashlytics, Cloud Messaging and website hosting.
- Cloudflare (Cloudflare, Inc.): our game server, its database and profile photo storage.
These providers may process data in the United States and other countries. We may also disclose data if the law requires it, or to protect players from abuse.
Other players can see your display name, profile photo, level, chat messages at your table, and (friends only, unless you turn it off) your last-seen status.
3. How long we keep it
- Account, profile, friends, points and leaderboard data: until you delete your account.
- Invite links: 24 hours.
- Reports and mutes: until reviewed and resolved, and in any case they are deleted when either the reporter or the reported player deletes their account.
- Table chat: at most the last 50 typed messages per table, and never longer than 30 days; older messages are deleted automatically. When you delete your account, your messages are erased from every table, including tables you already left. Copies of a message someone reported are kept with the report and deleted with it (see Reports above).
- Match results: kept without your account ID or name, so other players' history stays complete.
- Your username: after you delete your account, the handle itself stays reserved for 180 days so nobody can impersonate you to your former friends; it is not linked to any account.
- Analytics data: kept by Google Analytics for Firebase for 2 months (its default retention setting; this has not been changed in the Firebase console). Crash reports: kept by Crashlytics for about 90 days.
- Our database provider may keep a short recovery history of deleted records (up to 30 days) before they are gone for good.
4. Deleting your account
In the app: Profile → Account → Delete account, then confirm twice. This needs an internet connection.
Without the app: email support@majlis-game.com from the address you signed in with, with your username. See majlis-66d8d.web.app/delete-account for exactly what to send.
Deleting removes your sign-in account, display name, username, profile photo, points and levels, leaderboard entries, friends, friend requests, blocks, notification tokens, reports by or about you, chat mutes and filter records, your table chat messages, and your seat at every table. Invites you created stop working. Finished match results stay, without your identity. The app also erases your data stored on the phone.
5. Your choices and rights
- Switch analytics or crash reports on or off: Settings.
- Turn notifications on or off: Settings, or your phone's settings.
- Stop sharing your last-seen status: Settings.
- Change your display name or remove your photo: Profile.
- Block or report a player from the table or your friends list.
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, or to object to how we use it. Email support@majlis-game.com and we will answer within 30 days. You can also complain to your local data protection authority.
6. Brazil: your rights under the LGPD
Our terms are governed by the laws of Brazil, so this section sets out how Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, Lei nº 13.709/2018, the "LGPD") applies alongside the rest of this policy, for any player it covers.
- Legal basis. We rely on your consent for analytics and crash reports (off until you switch them on, and revocable at any time in Settings); performance of a contract with you for your account, profile, matches, points, leaderboards, friends and chat — the data needed to run the game you asked to play; and our legitimate interest in keeping Majlis safe and working, for moderation, abuse prevention and the technical data described in "Technical data" above.
- Your rights (LGPD art. 18). You may ask us to confirm whether we process your data; give you access to it; correct incomplete, inaccurate or outdated data; anonymise, block or delete data that is unnecessary, excessive or processed in breach of the law; port it to another provider; tell you which public and private entities we share it with; tell you the consequences of not giving consent, where consent is the basis; and revoke your consent at any time. Email support@majlis-game.com to exercise any of these.
- Complaints. You may also petition Brazil's data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD).
- International transfer. As described in "Who we share it with" above, our providers — Google Firebase (Google LLC) and Cloudflare, Inc. — may process data outside Brazil, including in the United States, under their standard contractual safeguards.
- Person in charge (encarregado). Reach the person responsible for data protection matters at support@majlis-game.com.
7. Children
Majlis is for players aged 13 and over and is not directed at children. We do not knowingly collect data from children under 13. If you believe a child under 13 has an account, email support@majlis-game.com and we will delete it.
8. Security
All traffic between the app and our servers is encrypted in transit (HTTPS/TLS). Your cards and other players' hands are kept on the server so nobody can see them early. No system is perfectly secure, but we keep what we store to the minimum the game needs.
9. Changes
If we change this policy we will update the effective date above, and tell you in the app when a change is significant.
10. Contact
AMB Ltd. — support@majlis-game.com