Nothing here is a specification sheet: no vendor publishes one. It is what follows from the distribution model.
On Android
The client is small and undemanding, and runs on hardware several generations old. In a market where a lot of play happens on budget phones, that is a real advantage and part of why the brand persisted while heavier competitors did not.
Installing requires allowing packages from outside the store. That permission is the thing worth being careful about: it applies to whatever you install next as well, so turn it off again once you are done rather than leaving it on.
On iOS
iOS distribution uses a configuration profile rather than the App Store. Apple revokes these when it finds them, so an install that worked last month can stop launching without warning, usually with a certificate error.
This is not a sign that anything has been stolen. It is the ordinary lifecycle of a profile-distributed app, and the fix is a fresh profile from your operator — not from a search result.
Permissions worth checking
A gambling client needs very little: storage and network access cover it. Anything beyond that deserves an explanation.
Requests for SMS access, contacts, accessibility services or device administrator rights are not normal for this category. Accessibility and device-admin permissions in particular are what credential-stealing malware asks for, because they allow reading other apps’ screens. A build that asks for either is one to remove immediately.