v.vimooraGAMES
MOON MUNCH

Your account
and your data.

Updated 13 September 2026 · Android test version 0.6.4

Who operates the game

Vimoora operates Moon Munch and its game server. Contact support@vimoora.io about your account or data. Moon Munch has separate game records from Jump & Stack.

Game and account records

We store your player ID and chosen or generated name, verified run results, run verification records, coin transactions, hourly gift claims and cooldowns, Level Road progress, challenge participation and outcomes, competition results and credited prizes. These records provide progress, recover accounts, settle rewards and verify submitted gameplay. The server stores hashes of access and recovery credentials. It replays submitted tap timing and retains a proof hash with the run record.

Chosen profile photos

A profile photo is optional. The app lets you choose, preview and save a cropped photo. The server accepts bounded still JPG, PNG or WebP input, decodes it, removes metadata such as EXIF/GPS, and stores a 96-pixel thumbnail and an image up to 640 pixels as WebP. The source upload is not kept as a separate original file. Your saved photo is public in game identity views, including rankings, Global Challenges, Level Road and a larger preview available through its public image link.

Replacing or removing a photo deletes its current server record and changes or removes its public image URL. Deleting the account removes the current photo too. Image responses may remain in short-lived caches for up to five minutes; other people can keep copies of images they have viewed. Reports store the photo ID, reporting player ID and time. Authorized operators can remove reported photos or dismiss reports; moderation actions are audited.

Native Google sign-in

Google sign-in is optional. The Android app includes the native Android account chooser and a configured Moon Munch client; real-phone validation is still pending. When used, the app sends the Google identity token to Vimoora’s own server for verification. Moon Munch persists Google’s stable account identifier to link or restore your account, rather than retaining your Google email address, display name or Google profile photo. A photo you separately choose to upload is handled as described above. Moon Munch never receives your Google password.

Short-lived sign-in requests, nonces and hashed handoff credentials support recoverable sign-in. Requests expire after ten minutes; expired request records are cleaned up when a later sign-in starts. Google handles its own account information under its privacy terms. The previous browser sign-in routes remain for older installed app versions; the new Android flow uses its native chooser.

Public activity and simulated rivals

Your player name, photo, score, rank and road level appear in relevant game views. Global Challenges show participant identities, targets, prizes, deadlines and outcomes to those who can view the challenge. Player names use 3–16 letters or numbers and must be unique regardless of capitalization. Tap your name in Settings → Account to edit it. Google email addresses and account identifiers are not displayed to other players. Some opponents are computer-controlled and held in separate records. Settings → Game → About competitions explains their participation. They use the same player-card design but are not real player accounts or verified human runs. They do not receive real-player competition prizes.

Notification records and preferences

We store notification event titles, bodies, destination references, creation and read times, plus preferences for game badges, challenge results, rank updates and a daily reminder hour. Events support badges on the relevant game screens and optional Android alerts. Opening a results screen acknowledges the relevant displayed events. Daily and weekly prize receipts record confirmed awards and whether you have acknowledged their popup; showing the popup does not award coins again. Messages may include progress, competition results and permitted Vimoora game announcements.

Device alerts default to selected for new installations; Android permission is requested after your first game interaction. Previous OFF or denied choices are respected. Android alerts require your permission. The app checks Vimoora’s own server in the background and schedules the optional daily reminder locally; it does not send game credentials to a third-party push service. Alert configuration is tied to the active account and cleared on logout or account change. Turning alerts off does not by itself delete existing server event records.

Your device and connection

The Android app keeps its access token, saved recovery code and pending sign-in handoff in Android Keystore-backed encrypted storage. It stores game settings, cached progress, pending gameplay and operation records locally. Chosen photo previews stay local until saved. Online game requests use HTTPS to Vimoora’s server; Google sign-in additionally communicates with Google. Connection details, including request IP addresses, operate and protect the service, including rate limiting. Artwork, the game font, an original soundtrack and sound effects are bundled locally. This version includes the Google Mobile Ads SDK for optional rewarded videos; it has no purchase SDK.

Rewarded videos

When you choose a rewarded video, the Google Mobile Ads SDK contacts Google to load and show it. Google describes collection of IP addresses, ad interactions, diagnostics and device or account identifiers for ad delivery, measurement and fraud prevention in its SDK data disclosure. Ad requests use encrypted transport. This build is configured for Moon Munch’s own rewarded advertising placement. Designated QA accounts use Google’s test inventory. Google’s consent flow is shown when applicable, and Settings → Game provides Ad privacy choices.

Vimoora stores the run ID, an expiring reward attempt, earned-reward or verification status, and the continuation relationship. The device keeps a pending earned receipt in encrypted storage until the server grant is saved or the attempt is abandoned. These records prevent duplicate extra lives and duplicate coin rewards. Signed advertising transaction records may be retained after account deletion to prevent reuse; they do not restore the deleted profile.

Support and reward integrity

Authorized Vimoora operators can inspect game activity, balances, public photos, reports, challenges and notification records to operate the game and resolve support issues. Account adjustments, moderation and operator actions are audited. Challenge promotion records include hashed Google account identifiers, participation pairs and reserved or credited amounts to enforce eligibility and allocation limits. Sponsored-rival budgets and simulation activity are recorded separately from real-player wallets.

Logout, recovery and deletion

Logging out revokes the current device credential and clears its saved account access; it keeps cloud scores, coins, photo and recoverable identity. Save your recovery code before logging out or switching from the old Alpha package. Keep the code private: anyone with it can restore your account.

In Settings → Account, open recovery/account options, choose Delete Account and confirm Delete Forever to remove the active Moon Munch profile, Google link, current photo, owned scores, wallet, hourly gift claims, road progress, notification records and preferences. Its access and recovery credentials stop working. This does not delete your Google account or separate Jump & Stack progress.

Shared challenge outcomes may remain so the other participant keeps their result; your participant name is replaced with “Deleted player.” Promotion and operator audit records can retain player identifiers, hashed identity values, photo identifiers and transaction details after deletion. These retained records are not an active player profile. The current test service has no fixed automatic deletion period for them.

If you cannot access the game, email support@vimoora.io with your Moon Munch player ID for access or deletion help. Do not send a password, access token or recovery code.

Retention and changes

Active game and notification records are kept while the account exists unless removed through game operations or a test reset. Current photo records are replaced or removed through the controls above; there is no scheduled age-based purge for game history, promotion or support audit records. Test progress may be reset before a public release. We will update this page when data handling changes. General Vimoora contact information is also available in the Vimoora privacy policy.