Get Started

Adult readers only. Skill-based content; outcomes depend on ability, not chance.

Download

Direct download paths for desktop and Android APK.

The official download paths for the desktop installer (Windows and macOS) and the Android APK, with size, version and checksum references so you can verify what you downloaded.

Choose a build

Three options, one per platform.

Pick the build that matches your device. iOS users should use the App Store listing linked from the app page.

Windows installer

A close-up of an adult hand holding a laptop showing a download page, on a wooden tabletop.
Editorial photograph — the moment a desktop build is downloaded.

The Windows installer is a signed .exe file. The signature is from the publisher named on the platform's download page. After download, right-click the file, choose Properties, then Digital Signatures. The signer name should match the publisher.

Filename: rummy-desktop-setup-3.4.1.exe
Size: 84.2 MB
SHA-256: 8e4f1b… (truncated; full hash on the platform's download page)

macOS installer

The macOS installer is a signed .dmg file. macOS Gatekeeper will verify the signature on first open; if the file is not signed, you will see a warning. Right-click and Open to bypass the warning only if you have verified the SHA-256 against the publisher's published value.

Filename: rummy-desktop-3.4.1.dmg
Size: 91.7 MB
SHA-256: 2c9a87… (truncated; full hash on the platform's download page)

Verifying the file

How to verify on Windows

Open PowerShell. Run: Get-FileHash .\rummy-desktop-setup-3.4.1.exe -Algorithm SHA256. Compare the output against the publisher's published hash.

How to verify on macOS

Open Terminal. Run: shasum -a 256 ~/Downloads/rummy-desktop-3.4.1.dmg. Compare the output against the publisher's published hash.

Direct APK download

The Android build is published as a signed APK. We link to the official publisher page; third-party APK mirrors are not endorsed and may carry modified versions.

Filename: rummy-3.4.1.apk
Size: 36.4 MB
Min Android: 8.0 (API level 26)
Target Android: 14 (API level 34)
SHA-256: f13e29… (truncated; full hash on the platform's download page)

Install on your device

Android blocks APKs from unknown sources by default. To install: open Settings → Apps → Special access → Install unknown apps, and grant permission to your browser or file manager. Open the downloaded APK and confirm the install prompt.

Verify the file

Open a terminal app or connect your device to a computer with ADB available. Run adb sha256sum rummy-3.4.1.apk on the computer, or use a file manager with a hash-check feature on the device. Compare the output against the publisher's published hash.

Caution

If the SHA-256 does not match the publisher's published value, do not install the file. A modified APK can contain code that does not match the publisher's published behaviour — including code that exfiltrates KYC documents or redirects withdrawals.

Need help with the install?

The customer-care page lists the support channels and what to expect for installation tickets.

Installation troubleshooting

Five problems and their fixes.

The five most common installation issues, ordered by frequency.

01

The installer is blocked by Windows SmartScreen

Windows SmartScreen blocks installers from publishers it does not recognise. Click "More info", then "Run anyway". If you have verified the SHA-256 hash matches the publisher's published value, the block is a heuristic miss, not a security finding.

02

macOS Gatekeeper says the file is from an unidentified developer

Right-click the .dmg file, choose Open, then click Open in the dialog. macOS allows this bypass once for a specific file; the next double-click will still be blocked. Verify the SHA-256 hash before you bypass — an unidentified-developer warning on a file whose hash does not match the publisher's is a security finding, not a heuristic miss.

03

Android blocks the APK with "For your security, your phone is not allowed to install unknown apps from this source"

Open Settings → Apps → Special access → Install unknown apps. Grant the permission to the browser or file manager you used to download the APK. Try the install again. Revoke the permission after install — leaving it granted is a security risk for any other APK you might be tricked into downloading later.

04

The installer completes but the app does not launch

On Windows: right-click the desktop shortcut, choose Properties, then "Open file location". Confirm the executable exists and is the same size as the published value. On macOS: open the Applications folder and confirm the .app bundle is there. On Android: confirm the package name in Settings → Apps matches the published value. If any of these is wrong, reinstall.

05

The app launches but cannot reach the platform's servers

Confirm your network connection is active. Confirm the platform's status page shows no outage. If both are clear, the issue is likely DNS or routing — switch to a different network (Wi-Fi to mobile data or vice versa) and try again. Persistent connection issues should be reported to customer support with the timestamp and network details.

Build verification

What the checksum actually proves.

Three things the SHA-256 hash confirms, and one thing it does not.

The hash confirms that the file you downloaded is byte-identical to the file the publisher published. If the hash matches, no bytes have been changed in transit, and the file is exactly what the publisher intended you to receive.

The hash confirms that no third party has modified the file after publication. Modification by a third party — including by an attacker who has intercepted the download — would change at least one byte, and the hash would not match.

The hash confirms the integrity of the file as a piece of data. This is the strongest guarantee cryptography gives you for a single file download.

What the hash does not confirm is the integrity of the publisher. A publisher who published a malicious file in the first place would publish the matching hash; the file would still be malicious, and the hash would still match. The hash is a check against modification, not against intent. That is why the verification process is two-step: first confirm the publisher, then confirm the hash.

Where the file lives

Why we link to the publisher's page, not a mirror.

Three reasons the publisher-hosted download is the right place to get the file.

The first reason is integrity. The publisher-hosted file is the file the publisher intended you to receive. Mirrors may be exact copies today and modified copies tomorrow; the publisher-hosted file is the only file whose integrity is guaranteed by the publisher itself.

The second reason is version currency. The publisher-hosted file is, by definition, the current version. Mirrors may lag behind the publisher's release cycle by days or weeks, leaving you on an older version with the security and responsible-play implications that follow.

The third reason is audit trail. If something goes wrong with the file you downloaded, the publisher-hosted page is the place where the publisher can publish a corrected version, a security advisory or a takedown notice. A mirror has no such audit trail.

Mirror caution

If you must use a mirror — for example, because the publisher's hosting is region-blocked in your location — verify the SHA-256 against the publisher's published value on every download. A mirror that does not publish the same hash as the publisher is a mirror that has modified the file, and a modified file is not a file you should install.

Permissions on first run

What the installer may request when it first launches.

Two requests to expect, and one request that should make you uninstall immediately.

The first request to expect is Windows: the installer may ask for administrator rights. This is normal for an installer that needs to write to Program Files and create a start-menu shortcut. Granting administrator rights to a verified publisher's installer is the right call.

The second request to expect is macOS: macOS Gatekeeper will prompt you to confirm the publisher. If you have already verified the SHA-256, click Open to proceed. If you have not verified, cancel and verify first.

The third request — the one that should make you uninstall immediately — is a request for an inbound network port or for firewall exception on a non-standard port. Rummy apps do not need inbound ports to function; the request is a sign of either a poorly-written installer or a malicious file masquerading as the installer.

Reinstalls

Reinstalling without losing data.

A clean reinstall is sometimes the right fix. Here is how to do it without losing your account, balance or verified KYC status.

Before you reinstall, back up your account state. For the desktop installer, your account state lives on the publisher's servers, not on your hard drive — your login credentials, balance, transaction history, KYC documents, and responsible-play settings are all server-side. The only thing that lives on your machine is the local cache of tiles and reels, which is rebuilt automatically on first launch of the new install. For the Android APK, the same server-side model applies: account state is bound to your phone number or email, not to the device. Backing up the APK is not a backup of your account; reinstalling the APK and logging in returns you to the same account.

That distinction matters because it changes when reinstall is the right move. Reinstall is appropriate when the local install is corrupted — for example, when the app launches but the tile spinner does not render, or when the login dialog accepts your credentials but then returns to a blank screen. Reinstall is also appropriate when the platform has published a security advisory that requires a clean install, or when you are switching devices and want to start fresh rather than migrate a local cache. Reinstall is not appropriate as a first response to a connectivity issue, a transaction delay or a login failure — those are server-side events diagnosed through the customer-care channel, not local issues fixed by reinstalling.

01

Back up what the server does not store

Before uninstall, export any locally-stored notes you keep inside the app — favourite table stakes, hand-history files you saved locally, and screenshot folders. The publisher does not back these up for you; they live on your device and are removed by uninstall. The settings, balance and KYC status are server-side and persist.

02

Verify account continuity after reinstall

After the new install completes, log in with the same credentials. The first screen after login should show your real balance, your real display name, and your verified KYC status badge. If any of these is missing or shows a previous user's data, log out immediately and contact customer care — this is a sign the publisher's account-merge logic has misfired, and customer care resolves it from the server side.

03

Reinstall after a suspected account compromise

If you are reinstalling because you suspect your account has been accessed by someone else — for example, an unfamiliar login notification, a withdrawal you did not make, or a changed password you did not change — the reinstall itself is not enough. Change your password from the login screen, revoke any active sessions from the security settings, and contact customer care to flag the incident. Reinstall without those steps leaves the attacker with the same session and the same access on the new install.

Account continuity is verified by three checks after the reinstall. First, the balance matches the balance you saw before the uninstall. Second, the responsible-play settings you previously configured — deposit limits, session timeouts, self-exclusion — are still active. Third, your withdrawal method is still linked and the last four digits of the bank account or UPI ID match. If all three match, the reinstall was clean and your account is intact. If any of the three is wrong, log out and contact customer care before placing a deposit or a withdrawal request.

One more point worth recording. The publisher's customer-care channel is the authoritative source for account-state questions after reinstall. The app's UI on the new install is a server-side view of the same account, so what the UI shows is what the server records; if the UI shows a number you do not recognise, the server has a number you do not recognise, and the only resolution path is the support ticket that the customer-care team can action on the server side. Documenting the timestamp of your reinstall, the build number you moved from, and the build number you moved to will shorten the resolution time when that ticket is filed.

Version security

Older versions and security.

Four reasons the latest published version is the only version you should be running, and what happens when you stay on an older one.

An older version of the app is missing the security patches that the newer version carries. The publisher publishes a newer version when a vulnerability is discovered — either by internal audit, by external research, or by an incident report from a user. The fix is shipped in the newer version, and the older version remains exposed until you update. Running the older version means running a build with a known vulnerability that the publisher has already fixed in the version you have not yet installed.

An older version is also missing the responsible-play updates the publisher has shipped. Deposit-limit enforcement, session-timeout behaviour, and self-exclusion propagation are all features that evolve as regulation and platform policy evolve. The version you installed six months ago may not enforce the deposit limits that the current version enforces, not because the publisher removed the enforcement, but because the version you are running is too old to know about the new enforcement rule.

Older versions are also easier targets for tampering. A build that has been published for a long time has been analysed by more attackers, and any structural weakness in the installer, the update channel, or the in-app protections is more likely to be known and exploited. The latest version is the least-analysed version, which is a weak form of security through obscurity but is not zero — every day that the latest version is live is a day that the older version is being targeted.

The right operating model is to enable automatic updates on the desktop installer and to download the newest APK from the publisher's page on Android. The publisher publishes a release note with every version that lists the security patches, the responsible-play updates, and the bug fixes included. Skim the release note before you update; if a release note mentions a security advisory, update on the same day. If a release note mentions a breaking change in the responsible-play feature, update at a time when you are not in the middle of a session, so the update can apply without interrupting play. The cumulative effect of these habits is that you are always a few days behind the latest patch rather than a few months, and the security and policy exposure is correspondingly smaller.

Already have the app installed?

The app page walks through the permissions, settings and post-install checks.

Editorial onlyWe do not run tables. Affiliate links are tagged.
PLAY NOW