Back to Home
Privacy Policy

Diamond Loot · HustlrStudioz

Privacy Policy

App: Diamond Loot: Get Redeem CodeUpdated: May 17, 2026Effective: May 17, 2026
1

Introduction & Scope

Welcome to Diamond Loot, developed and operated by HustlrStudioz. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and your rights.

This policy applies to:

  • The Diamond Loot Android app (dev.hustlrstudioz.diamondloot)
  • Our website at https://hustlrstudioz.dev
  • All related support channels (email, in-app support)
By downloading, installing, or using Diamond Loot, you acknowledge you have read and understood this Privacy Policy. If you do not agree, please do not use the app.
2

Information We Collect

2.1 Account & Identity Information

DataSourceWhy
Firebase User ID (UID)Firebase AuthenticationUnique identifier across all systems
Email addressGoogle Sign-InAccount identification, support
Display nameGoogle Sign-InPersonalisation, leaderboard
Profile picture URLGoogle Sign-InDisplay in app UI (not stored on our servers)
Account creation timestampGenerated on signupFraud prevention, redemption eligibility
Anonymous auth tokenFirebase AuthAllows usage before Google Sign-In
Google Sign-In is only prompted before your first gift card redemption. Your profile picture is never stored on our servers — only the public Google URL is referenced.

2.2 In-App Activity & Progress Data

DataPurpose
Coin balanceCore functionality
Lifetime coins earnedAnalytics, fraud detection, leaderboard
Spin / scratch / slot cooldown timestampsEnforcing fair daily limits
Daily activity countsEnforcing daily earning limits
Streak days and last streak dateDaily streak feature
Redemption historyPayout verification, support
Referral code & referred-by UIDReferral reward attribution
Transaction logFraud prevention, audit trail, support

2.3 Device & Technical Information

DataPurpose
Device model and manufacturerCrash reporting, compatibility
Android OS versionCompatibility, crash diagnosis
App versionSupport, bug fixes
IP addressFraud detection, geographic compliance
Firebase Instance ID / FCM tokenPush notification delivery
Play Integrity attestation resultAnti-cheat — verifying device and app are genuine

2.4 Advertising Identifiers

DataSourcePurpose
Google Advertising ID (GAID)Android deviceAd personalisation, attribution, frequency capping
App set IDAndroid deviceAnalytics, fraud detection (non-advertising)
You can reset or opt out of personalised ads via: Settings → Privacy → Ads → Reset Advertising ID.
3

How We Collect Information

Directly from you

  • When you sign in with Google
  • When you contact support

Automatically when you use the app

  • Firebase Analytics (usage patterns, screen views, custom events)
  • Firebase Crashlytics (crash reports)
  • Google AdMob (ad impressions, clicks, performance)
  • Our Cloud Functions (coin grants, redemptions, cooldown timestamps)

From third parties

  • Google (account info via Sign-In)
  • Firebase / Google Play Services (device attestation via Play Integrity)
  • AdMob (ad serving and reporting)
  • Offerwall partners (task completion postbacks)
4

How We Use Your Information

PurposeLegal Basis
Core app functionality (coin balance, redemptions, notifications)Contract performance
Fraud prevention & fair economyLegitimate interests
Advertising via AdMobConsent
Analytics & product improvementLegitimate interests
Support & communicationsLegitimate interests / Consent
Legal & complianceLegal obligation
5

Third-Party Services & Data Sharing

PartnerData SharedPurpose
Google FirebaseUID, email, usage events, crash logsAuth, database, analytics, crash reporting
Google AdMobAdvertising ID, IP address, app usageAd serving and reporting
Google Play IntegrityDevice attestation requestApp authenticity verification
GiftPortDenomination requested, transaction IDGift card fulfilment
We do not: sell your personal data, share survey answers, share gift card codes, or share your coin balance or transaction history with ad networks.
6

Advertising & Ad Networks

Diamond Loot is free and supported by advertising through Google AdMob.

Ad types

  • Rewarded video ads — entirely voluntary, earn extra spins/cards
  • Interstitial ads — full-screen at natural break points, minimum 45-second gap enforced

Opt out of personalised ads

  • Android 12 and below: Settings → Google → Ads → Opt out of Ads Personalisation
  • Android 13 and above: Settings → Privacy → Ads → Delete Advertising ID

Frequency capping

  • Minimum 45 seconds between any two interstitial ads
  • Maximum 6 interstitial ads per session
  • Never shown on the Rewards/Redeem screen
  • Never shown during active game animations
7

Reward & Offerwall Partners

When you enter the offerwall, we pass a hashed, anonymous version of your Firebase UID (SHA-256, one-way, irreversible) to the provider. We do not share your name, email, or any personally identifiable information.

Task completions are verified via server-to-server postback with cryptographic signature verification. Your app never self-reports task completions.

8

In-App Currency & Reward Economy

Coins (◆) are a virtual in-app currency. They cannot be purchased with real money, cannot be transferred between accounts, and have no cash value except when redeemed for gift cards.

When you redeem coins, the gift card code is stored AES-256 encrypted in our database, associated only with your Firebase UID. The full code is only revealed when you explicitly tap "Reveal Code".

Every coin grant is logged with: source, amount, balance before/after, timestamp, and an idempotency key preventing double-crediting. You can request a copy of your transaction log by contacting us.

9

Fraud Prevention & Security

BehaviourDetectionAction
Clock manipulationServer-side timestamps (device clock never trusted)Cooldown enforced from server time
SQLite/local DB editingAll coin writes via Cloud Functions onlyEdits have no effect; re-synced from server
Emulator farmingFirebase App Check + Play IntegrityRequests from non-genuine devices rejected
Self-referral fraudServer: inviter UID ≠ invitee UIDReferral voided, no coins granted
Referral farmingInviter account must be >24 hours oldReward withheld until age requirement met
Multiple accountsDevice fingerprint cross-referenceOnly first account eligible for rewards
Offerwall tamperingHMAC signature verificationInvalid signatures rejected
If you believe your account was incorrectly banned, contact founder@hustlrstudioz.dev with your Firebase UID. We review appeals within 7 business days.
10

Data Retention

Data typeRetention period
Active account dataDuration of account + 30 days after deletion
Coin transaction logs12 months from transaction date
Redemption records24 months from redemption date
Crash logs (Crashlytics)90 days
Analytics events (Firebase)14 months (Firebase default)
Support emails24 months
Fraud-flagged account dataIndefinitely (anonymised after 12 months)
FCM push tokensUntil account deletion or token expiry
11

Data Security

Technical measures

  • Firebase Security Rules: coins field can only be modified by Cloud Functions
  • AES-256 encryption for gift card codes at rest
  • HTTPS/TLS 1.2+ for all data in transit
  • Firebase App Check + Play Integrity on every Cloud Function call
  • Idempotency keys on all coin grant operations
  • Completely separate development and production Firebase projects
  • API keys stored in Firebase Functions environment config — never in app code or APK

Organisational measures

  • Production Firebase console access restricted to studio owner
  • No third-party developer has access to the production database
  • Gift card codes are never printed in server logs
In the event of a data breach, we will notify affected users and the appropriate supervisory authority within 72 hours of becoming aware, in accordance with applicable law.
12

Your Rights & Data Control

RightHow to exercise
Access — copy of all data we holdEmail: founder@hustlrstudioz.dev, subject "Data Access Request". Response within 30 days.
Correction — fix inaccurate dataEdit directly in app settings, or contact us
Deletion — right to be forgottenIn-app: Profile → Settings → Delete Account. Or email us with subject "Account Deletion Request".
Portability — data in JSON formatEmail: founder@hustlrstudioz.dev
Restrict processingContact founder@hustlrstudioz.dev
Object to processingContact us. Note: objecting to fraud prevention may result in account termination.
Opt out of personalised adsAndroid device settings (see Section 6)
Disable push notificationsDevice Settings → Apps → Diamond Loot → Notifications
13

Children's Privacy

Diamond Loot is not directed at children under 13. We do not knowingly collect personal information from anyone under 13.

If you are a parent or guardian and believe your child under 13 has created an account, contact us immediately at founder@hustlrstudioz.dev. We will verify the claim, delete the account and all data within 72 hours, and confirm deletion by email.

14

International Data Transfers

Our backend infrastructure (Firebase) is operated by Google and may process data in the United States, Europe, and Asia. Google complies with standard contractual clauses and equivalent data protection frameworks.

15

India — Digital Personal Data Protection Act 2023

HustlrStudioz acts as the Data Fiduciary under the DPDPA 2023. Your rights as a data principal include:

  • Confirmation and access — know what personal data we process
  • Correction and erasure — have inaccurate or unnecessary data corrected or erased
  • Grievance redressal — have grievances addressed within a reasonable timeframe
  • Nomination — nominate an individual to exercise your rights in the event of death or incapacity
To exercise DPDPA rights: Email founder@hustlrstudioz.dev with subject "DPDPA Data Rights Request". We acknowledge within 72 hours and resolve within 30 days.
16

California Residents — CCPA

California residents have rights under CCPA/CPRA:

  • Right to know — request disclosure of what we collect, use, share, or sell
  • Right to delete — request deletion of personal information (see Section 12)
  • Right to opt-out of sale — we do not sell personal information
  • Right to non-discrimination — we will not deny services for exercising privacy rights
To exercise CCPA rights: Email founder@hustlrstudioz.dev with subject "CCPA Privacy Request".
17

European Users — GDPR

Processing activityLegal basis
Account creation and authenticationContract performance
Coin earning and redemptionContract performance
Fraud preventionLegitimate interests
Analytics (Firebase)Legitimate interests
Ad personalisation (AdMob)Consent
Push notifications (transactional)Contract performance
Push notifications (marketing)Consent
Legal complianceLegal obligation

HustlrStudioz acts as the data controller. You also have the right to lodge a complaint with your national data protection authority.

Our fraud detection system uses automated analysis. If your account is restricted as a result, you have the right to request human review by contacting us.

18

Changes to This Policy

When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Display an in-app notification on your next app open
  • For material changes affecting your rights, send a push notification or email

Significant changes include: adding a new third-party partner, changing use of advertising identifiers, changes to your data rights, or changes to retention periods.

Previous versions are available upon request at founder@hustlrstudioz.dev.

19

Contact Us

General enquiries

Within 7 business days

Data access requests

Within 30 days

Deletion requests

Within 30 days

Account ban appeals

Within 7 business days

Urgent matters (use subject: URGENT)

Within 24 hours

Contact

Email: founder@hustlrstudioz.dev

Website: hustlrstudioz.dev

Grievance Officer (India — DPDPA): Same email, subject: "DPDPA Grievance"

This Privacy Policy was written specifically for Diamond Loot by HustlrStudioz. It covers all SDKs and integrations active as of May 17, 2026.
© 2026 HustlrStudioz · hustlrstudioz.dev