Effective Date: March 23, 2026 · Last Updated: September 13, 2026
Hye Labs LLC ("Hye Labs," "we," "us," or "our") operates the Mafia mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App. Please read this policy carefully. By downloading or using the App, you agree to the practices described in this Privacy Policy.
The App does not:
Anonymous Diagnostic Data: The App uses Sentry, a third-party error monitoring service, to collect anonymous crash reports and performance data. This includes:
This diagnostic data is not linked to your identity and is not used by us to identify you. It is used solely to diagnose and fix bugs and improve app performance.
Anonymous Usage Analytics: The App uses PostHog, a third-party analytics service, to collect anonymous usage data. This helps us understand how the App is used and improve the experience. This includes:
This analytics data is not linked to your identity and is not used by us to identify you. We do not use any advertising identifier - Apple's IDFA or the Google Advertising ID - for analytics purposes. We do not track you across other apps or websites ourselves. Third-party advertising partners may do so where you have permitted it (see Section 5).
Saved player profiles - including names, games played, and points - are stored locally on your device and are never transmitted to any server, except when the optional QR Code role distribution feature is used (see below), in which case only player names are transmitted.
QR Code Role Distribution (Optional): When the Game Master enables QR Code Mode, the following data is temporarily transmitted to a relay server operated by Cloudflare Workers on our behalf:
This data is stored temporarily (maximum 30 minutes) to facilitate role distribution and is automatically deleted after the session expires. No data is retained after the game begins. The relay server does not store any persistent data, does not use cookies, and does not track users across sessions. Data is transmitted over encrypted connections (HTTPS/TLS). This feature requires an internet connection and is entirely optional - the standard phone-passing mode does not transmit any data.
Advertising Data: The App uses Google AdMob mediation to display optional rewarded video advertisements. Mediation runs an auction across a waterfall of advertising networks - currently Google AdMob, Unity Ads and Liftoff Monetize on both platforms, plus AppLovin and Mintegral on iOS only - and the highest-bidding network serves the ad. The data each network may collect is similar in scope and is described below:
This data is used by Google to serve, measure, and improve advertisements. On iOS, if you have granted App Tracking Transparency (ATT) permission, your Advertising Identifier (IDFA) may be used to deliver more relevant ads; you can change this at any time in Settings > Privacy & Security > Tracking. On Android, there is no ATT equivalent: where the law requires consent we show Google's consent form inside the App, and you can reopen it at any time from the App's Settings screen under "Manage Ad Privacy". Your Google Advertising ID can also be reset or deleted in Android Settings > Privacy > Ads.
In-App Purchase Data: The App offers optional in-app purchases processed entirely by the platform store - Apple through the App Store on iOS, and Google through Google Play on Android. We do not collect or store any payment information (credit card numbers, billing addresses, etc.). We receive only a confirmation of purchase status to unlock features within the App. Anonymous purchase success/failure events and the product identifier (but not your Apple ID, Google Account, name, or payment details) are logged to the analytics service described above so we can measure conversion and diagnose failures.
Support Communications: If you contact us through our support form or by email, we collect the information you voluntarily provide, including your name, email address, and message content. This information is used solely to respond to your inquiry and provide support. We do not use this information for marketing purposes, and we do not share it with third parties except as necessary to respond to your request. Support communications are retained for up to 24 months for quality and record-keeping purposes, unless a longer retention period is required for legal purposes, after which they are deleted.
The App uses the following third-party services, each acting as a data processor on our behalf:
None of Sentry, PostHog, Google, AppLovin, Mintegral, Unity Ads, or Liftoff Monetize receives player names or any information that could directly identify you. The advertising networks (Google AdMob, Unity Ads and Liftoff Monetize, plus AppLovin and Mintegral on iOS) may use device identifiers and interaction data for ad serving and measurement purposes. Should we integrate additional third-party services in future updates, this Privacy Policy will be updated accordingly.
Hye Labs LLC is the data controller for purposes of the GDPR. We have entered into data processing agreements with our third-party service providers where required.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process anonymous diagnostic and analytics data under the following legal basis:
We retain anonymous diagnostic and analytics data for up to 12 months from the date of collection, after which it is automatically deleted. Crash reports stored by Sentry are retained for 90 days. You may request early deletion of your analytics data at any time by contacting us (see Section 11).
The App displays optional rewarded video advertisements through Google AdMob mediation, which serves ads from a waterfall of partner networks: Google AdMob, Unity Ads and Liftoff Monetize on both platforms, and additionally AppLovin and Mintegral on iOS. These ads are entirely voluntary — you choose to watch them in exchange for temporary access to in-game content (valid for one game session).
Data collected by ad networks: When you watch an ad, the network that serves it may collect device identifiers, IP address (for approximate location), ad interaction data, and device performance information. This data is used to serve, measure, and improve advertisements.
Personalized vs. non-personalized ads: On iOS, if you grant App Tracking Transparency (ATT) permission, AdMob may use your Advertising Identifier (IDFA) to deliver personalized ads based on your interests; if you decline or have not been prompted, only contextual (non-personalized) ads are served. On Android, where the law requires it we show Google's consent form inside the App before any personalized advertising, and only contextual ads are served unless you consent.
Opt-out of personalized ads: You can opt out of personalized advertising by:
Children: The App is not directed to children under 13. We do not knowingly serve personalized advertising to users under 13 and rely on user and device-level settings and Google's policies to enforce this. The App is designed for a general audience aged 13 and older.
For more information about how Google uses data, see Google's Privacy Policy at policies.google.com/privacy.
Mafia is a social deduction game intended for a general audience, not specifically directed at children. The App does not knowingly collect personal information from children under the age of 13 (or under the age of 16 in the European Economic Area).
Because we do not directly collect personal data and our third-party services process only device-level identifiers, we believe we are in compliance with the Children's Online Privacy Protection Act (COPPA), the European Union's General Data Protection Regulation (GDPR) as it applies to children, and other applicable children's privacy laws. If we become aware that we have inadvertently collected personal information from a child, we will take immediate steps to delete that information.
If you are a parent or guardian and believe your child has provided personal information to us, please contact us at the address below.
We do not collect or store personal data through the App itself. Anonymous diagnostic data and usage analytics are transmitted over encrypted connections (HTTPS/TLS) and are stored securely on Sentry's and PostHog's infrastructure, respectively. All game data (player names, roles, scores) exists only on your device and is not transmitted to any server, except when the optional QR Code role distribution feature is used (see Section 1).
Depending on your jurisdiction, you may have rights under applicable data protection laws, including:
To exercise any of these rights, please contact us. We will respond within 30 days.
The App is available worldwide through the Apple App Store and Google Play. Anonymous diagnostic and analytics data is processed on servers located in the United States (Sentry and PostHog). For users in the European Economic Area (EEA), United Kingdom, or Switzerland, this data transfer is conducted in accordance with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) where required. Since we do not collect personal data through the App itself, the risk associated with these transfers is minimal.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. If the changes are material — particularly if we begin collecting personal data through the App — we will provide clear and prominent notice before such changes take effect, where required by law, through the App or through the store listing's update description. We encourage you to review this Privacy Policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or the App's privacy practices, please contact us: