English

My Account

With Friends

Privacy policy

Privacy policy

Last updated: 10 August 2026

This Privacy Policy explains how personal data is collected, used, disclosed and protected in connection with the City Code website, online game platform, pre-orders, purchases, marketing communications and related services.

For the purposes of this Privacy Policy, “City Code,” “we,” “us,” or “our” refers to the City Code service operated and distributed by TheAI Ltd.

1. Who is responsible for your personal data

The data controller responsible for the processing of your personal data is:

TheAI Ltd
Tax Registration Number: 105345863200001
Licensing Authority: Dubai International Financial Centre Authority (DIFCA)
Licence Number: 12561
Registered address: Innovation One, IH-00-01-03-OF-05, DIFC, Dubai, United Arab Emirates
Telephone: +971 52 626 6400
Email: contact@theai.com

TheAI Ltd determines the purposes for which personal data is processed in connection with the City Code website, game platform, waitlist, marketing, pre-orders, purchases, customer communications and related services.

The processing of personal data by TheAI Ltd is subject to applicable data protection laws, including the DIFC Data Protection Law No. 5 of 2020 and, where applicable, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and other applicable privacy laws.

2. Scope of this Privacy Policy

This Privacy Policy applies when you:

  • visit the City Code website or game platform;

  • join our waitlist or subscribe to updates;

  • create or use an account;

  • place a pre-order;

  • purchase access to a game scenario, subscription, bundle or other digital product;

  • play City Code;

  • use game features, including interactive features and AI-assisted features;

  • communicate with us;

  • interact with our advertising or marketing communications.

The Service is intended for users aged 18 or older.

3. Personal data we collect

The personal data we collect depends on how you interact with City Code.

3.1 Contact and waitlist information

If you join our waitlist, request information or subscribe to communications, we may collect:

  • your email address;

  • your subscription or consent status;

  • the date and time of your subscription or consent;

  • information necessary to manage your communication preferences.

3.2 Account and game access information

Where an account or game access is provided, we may process:

  • email address;

  • internal user or account identifier;

  • purchased or activated scenario;

  • subscription or bundle information;

  • access status;

  • access start and expiry dates.

3.3 Gameplay information

When you use the Game, we may process information concerning your interaction with the Service, including:

  • game progress;

  • scenarios started or completed;

  • progress within a scenario;

  • interaction with gameplay elements;

  • use of hints and interactive hints;

  • timestamps and session information;

  • gameplay events;

  • technical errors and performance information.

This information is used primarily to provide the Game, maintain progress, improve functionality, identify technical issues and understand how the Service is used.

3.4 AI-assisted features

If you use an AI-assisted feature within the Game, we may process the text or other information that you submit to that feature together with relevant game context necessary to provide a response.

Please do not submit sensitive personal information or unnecessary personal information about yourself or other people through AI-assisted features.

Where third-party AI technology is used to provide a feature, information may be transmitted to the relevant technology provider in accordance with our contractual arrangements and applicable data protection requirements.

3.5 Purchase and transaction information

When you make a pre-order or purchase, we or the applicable payment provider may process information including:

  • email address used for the transaction;

  • product, scenario, subscription or bundle purchased;

  • purchase date and time;

  • purchase price and currency;

  • billing country or region;

  • customer, order or transaction identifier;

  • payment status;

  • fulfilment status;

  • refund or chargeback status;

  • limited tax or invoice information where required.

We do not intend to store complete payment card numbers, card security codes or complete banking credentials.

Payment credentials are generally submitted directly to the applicable payment provider or Merchant of Record.

3.6 Device, technical and security information

When you access the website or Game, certain information may be collected automatically, including:

  • IP address;

  • browser type and version;

  • device type;

  • operating system;

  • approximate country or region derived from technical information;

  • date and time of access;

  • session identifiers;

  • server logs;

  • error and diagnostic information;

  • security and fraud-prevention information.

3.7 Cookies, analytics and advertising information

Subject to your choices and applicable law, we may use cookies, pixels, SDKs and similar technologies to collect:

  • cookie identifiers;

  • advertising identifiers;

  • website and game interactions;

  • referral information;

  • campaign information;

  • pages viewed;

  • interaction with advertisements;

  • analytics information.

Additional information about these technologies should be provided in our Cookie Policy and through the cookie preference interface.

3.8 Communications

If you contact us, we may process:

  • your email address;

  • the contents of your message;

  • information concerning your account or purchase;

  • correspondence history;

  • information reasonably necessary to respond to or resolve your request.

4. How we obtain personal data

We may obtain personal data:

  • directly from you;

  • automatically when you use the website or Game;

  • from payment providers and Merchants of Record;

  • from analytics and advertising providers where permitted;

  • from email and communication providers;

  • from technical and infrastructure service providers;

  • from commercial partners where you have interacted with City Code through that partner.

Where we obtain personal data from another organisation, we process it only where we have an appropriate lawful basis to do so.

5. Why we process your personal data

We process personal data for the following purposes.

Providing the Service

We use personal data to:

  • provide access to City Code;

  • activate purchased scenarios;

  • maintain gameplay progress;

  • provide subscriptions and bundles;

  • operate interactive and AI-assisted features;

  • provide customer support.

Where applicable, the lawful basis for this processing is the performance of a contract or taking steps requested by you before entering into a contract.

Pre-orders and purchases

We use relevant information to:

  • process and confirm purchases;

  • verify transactions;

  • provide access to purchased content;

  • manage subscriptions;

  • manage refunds or disputes where applicable;

  • prevent duplicate or fraudulent transactions.

Depending on the processing activity, the lawful basis may be performance of a contract, compliance with applicable law or our legitimate interests in operating and protecting the Service.

Waitlist and marketing communications

Where required by applicable law, we send promotional emails and other direct marketing communications on the basis of your consent.

You may unsubscribe at any time by using the unsubscribe mechanism included in the communication or by contacting us.

Withdrawal of consent does not affect processing that occurred lawfully before consent was withdrawn.

Analytics and improvement

We may analyse use of the website and Game to:

  • understand how users interact with the Service;

  • identify technical problems;

  • improve game mechanics and usability;

  • evaluate the performance of scenarios and features;

  • improve stability and security.

We rely on our legitimate interests where permitted by law and on consent where consent is required for the relevant cookies or tracking technology.

Security and fraud prevention

We may process technical and transaction-related information to:

  • protect accounts;

  • prevent fraud and abuse;

  • investigate suspicious activity;

  • protect the integrity of the Service;

  • secure our systems.

We rely on our legitimate interests in maintaining the security and integrity of our services and, where relevant, compliance with legal obligations.

Legal and regulatory compliance

We may process and retain information where necessary to:

  • comply with tax and accounting obligations;

  • respond to lawful requests from authorities;

  • comply with sanctions or other regulatory requirements;

  • establish, exercise or defend legal claims.

The lawful basis is compliance with applicable legal obligations and, where appropriate, our legitimate interests in protecting our legal rights.

The DIFC Data Protection Law expressly recognises consent, contractual necessity, compliance with applicable law and legitimate interests as possible lawful bases for processing.

6. Payment providers and Merchants of Record

We may use third-party payment providers, payment processors, resellers or Merchants of Record to process transactions.

The payment provider used for a particular transaction may be identified during checkout, in the payment interface, order confirmation, receipt or invoice.

Depending on the commercial arrangement, such a provider may:

  • process payments;

  • calculate or collect applicable taxes;

  • issue receipts or invoices;

  • conduct fraud prevention;

  • process refunds;

  • manage disputes and chargebacks;

  • carry out regulatory, sanctions or compliance checks;

  • provide transaction-related customer support.

A payment provider may act as our processor or service provider for certain activities and as an independent controller for activities it determines itself, including compliance, taxation, anti-fraud and payment-regulatory purposes.

Where a provider acts independently, its own privacy notice applies to that processing.

7. Service providers and other recipients

We may disclose personal data where reasonably necessary to service providers that assist us with:

  • payment processing;

  • hosting and cloud infrastructure;

  • game operation and technical support;

  • email delivery;

  • analytics;

  • advertising;

  • security and fraud prevention;

  • AI functionality;

  • customer communication;

  • professional, legal and accounting services.

For development, hosting, technical operation and maintenance of the Game, certain personal data may be processed on our instructions by Spark Studios LLC, Identification Number 405876789, registered at Georgia, Tbilisi, Vake district, Besarion Zhgenti Street N49, Flat N20, acting as a data processor and technical service provider.

We may also disclose personal data:

  • where required by applicable law or a competent authority;

  • to protect our rights or the rights of other persons;

  • in connection with litigation or legal proceedings;

  • in connection with a merger, acquisition, corporate restructuring, financing or transfer of all or part of our business, subject to appropriate safeguards.

Processors acting on our behalf are required to process personal data in accordance with contractual instructions and applicable data protection requirements. Under GDPR, the relationship between a controller and processor must be governed by appropriate contractual obligations.

8. International transfers

City Code is operated internationally.

TheAI Ltd is established in the Dubai International Financial Centre, and our service providers and users may be located in different countries.

As a result, personal data may be transferred to or processed in countries outside your country of residence, including the United Arab Emirates, Georgia and countries in which our service providers operate.

Where applicable data protection law requires safeguards for an international transfer, we use an appropriate legal mechanism, which may include:

  • a recognised adequacy mechanism;

  • contractual data-protection safeguards;

  • European Commission Standard Contractual Clauses;

  • applicable UK international-transfer safeguards;

  • safeguards recognised under DIFC data protection law;

  • another lawful transfer mechanism.

We may also implement additional technical and organisational safeguards where appropriate.

9. How long we keep personal data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, accounting, security and dispute-resolution requirements.

In particular:

Waitlist and marketing data is generally retained while you remain subscribed or while it is reasonably necessary for the relevant marketing purpose. If you unsubscribe, limited information may be retained where necessary to record and respect your opt-out.

Account and gameplay information may be retained while your account or access remains active and for a reasonable period afterwards where necessary for support, security, service improvement or legal purposes.

Purchase and transaction records may be retained for the period required under applicable tax, accounting, consumer, fraud-prevention and legal requirements.

Cookie and advertising information is retained according to the duration of the relevant technology and your privacy preferences.

Customer-support records may be retained for as long as reasonably necessary to resolve the issue and establish, exercise or defend legal claims.

A payment provider acting as an independent controller determines its own retention periods under its own privacy policy.

10. Your rights

Depending on the laws applicable to you and to the relevant processing, you may have the right to:

  • request access to your personal data;

  • obtain information about how your data is processed;

  • request correction of inaccurate personal data;

  • request deletion of personal data;

  • request restriction of processing;

  • object to certain processing;

  • receive certain personal data in a portable format;

  • withdraw consent where processing is based on consent;

  • object to direct marketing;

  • request appropriate safeguards in relation to certain automated decisions;

  • lodge a complaint with an applicable data protection authority.

The DIFC Data Protection Law provides rights including withdrawal of consent, access, rectification, erasure, restriction, objection and portability.

If the GDPR applies to the relevant processing, you may also exercise the rights available under GDPR. Information provided to individuals under GDPR must include, among other things, the identity of the controller, purposes and legal bases, recipients, retention, international transfers and the principal data-subject rights.

If you are located in the United Kingdom and the UK GDPR applies, corresponding rights may also apply.

To exercise a right, contact us using the information in Section 15.

We may request reasonable information necessary to verify your identity and protect your personal data.

11. Marketing and cookies

You may withdraw your consent to marketing communications at any time.

You can unsubscribe from marketing emails through the unsubscribe link contained in the email or by contacting us.

Where required by applicable law, non-essential cookies and advertising technologies will not be activated unless you have provided the required consent.

You can manage available cookie preferences through our cookie consent interface.

Withdrawing marketing or advertising consent will not prevent us from sending communications that are strictly necessary to provide a service you requested, such as transaction or service messages.

12. Security

We use reasonable technical and organisational measures designed to protect personal data against:

  • unauthorised access;

  • accidental or unlawful disclosure;

  • alteration;

  • loss;

  • destruction;

  • misuse.

Such measures may include access controls, restricted permissions, encryption where appropriate, logging, security monitoring and data minimisation.

No internet service can guarantee absolute security. You should also take reasonable steps to protect your account and devices.

The DIFC Data Protection Law requires controllers and processors to implement appropriate technical and organisational measures and to apply data protection by design and by default.

13. Children

City Code is intended for persons aged 18 and over.

We do not intentionally offer the Service to children under 18.

If we become aware that personal data has been provided by a person under 18 in circumstances where we should not process it, we may delete or restrict that information as appropriate.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to City Code;

  • new functionality;

  • changes to service providers;

  • changes to our commercial structure;

  • changes in applicable law or regulatory guidance.

The latest version will be published on this page with an updated “Last updated” date.

Where required by applicable law, we will provide additional notice or request new consent before materially changing how personal data is used.

15. Contact

For questions concerning this Privacy Policy, the processing of your personal data, or the exercise of your privacy rights, contact:

TheAI Ltd
Tax Registration Number: 105345863200001
Licence Number: 12561
Innovation One, IH-00-01-03-OF-05
DIFC, Dubai
United Arab Emirates

Telephone: +971 52 626 6400
Email: contact@theai.com

If your request relates to a payment processed independently by a Merchant of Record or other payment provider, we may direct you to that provider where appropriate.

You may also have the right to lodge a complaint with the DIFC Commissioner of Data Protection or, where another privacy regime applies to your processing, the competent data protection authority in your jurisdiction.

© 2026 City Code. Operated and distributed by TheAI Ltd.


TheAI Ltd — DIFC, Dubai, United Arab Emirates

DIFCA Licence No. 12561 · Tax Registration No. 105345863200001

© 2026 City Code. Operated and distributed by TheAI Ltd.


TheAI Ltd — DIFC, Dubai, United Arab Emirates

DIFCA Licence No. 12561 · Tax Registration No. 105345863200001

© 2026 City Code. Operated and distributed by TheAI Ltd.


TheAI Ltd — DIFC, Dubai, United Arab Emirates

DIFCA Licence No. 12561 · Tax Registration No. 105345863200001