What we store
We create a random anonymous player identifier and keep it in a signed, secure browser cookie. Game sessions store your question progress, attempts, score, server-timed expiry and aggregate performance. The cookie does not contain your answers.
Abuse protection
Short-lived, minimized network signals may be used to rate-limit automated requests, false reports and repeated submissions. Where an IP-derived signal is needed, the production design uses a rotating salted representation rather than keeping the raw address in the game record.
Analytics
We measure privacy-conscious page views, Daily, Survival, Practice and private-room starts, completion, question drop-off, sharing and a small number of interface actions. These records can include the page path, referring website domain and coarse device, browser and country information. They never include a raw IP address, the correct answer, a complete cookie, an email address or unnecessary free text.
Sharing, referrals and private rooms
Result links can contain a random referral code so we can count referred visitors and whether they start a game. Private rooms store the short display names entered by both players, the room code, progress and score. A room becomes unavailable 24 hours after it is created or last renewed by a rematch. Seven days after expiry, its names, code, question set, attempts and detailed match records are automatically deleted. Only de-identified aggregate product events remain. These features do not require an email address or account.
Community submissions and reports
If you submit optional text or a display name, reviewers can see it for moderation. The core MVP does not publish submitter names. Reports are linked to the relevant frozen question version and anonymous session so that an issue can be investigated.
Your choices
You can remove the anonymous cookie using your browser settings. Doing so starts a new anonymous identity and may remove your ability to resume an unfinished Daily Challenge on that device. Theme choice is stored locally and can also be cleared.
Contact
A production privacy contact will be published before public launch. Until then, privacy requests are handled by the product owner through the deployment’s official support channel.