Privacy

This site makes puzzles. It works without an account, and it is built to know as little about you as it can. This page says what that means in practice.

If you are under 16

Please leave analytics off. You can make, print, share and solve every puzzle without turning it on, and nothing here asks your age or stops you. If somebody else already turned it on in this browser, you can turn it off again from Privacy & analytics, at the foot of every page.

Your choice, and how long it lasts

Analytics is off until you press Allow analytics. Closing the banner, ignoring it or pressing Escape leaves it off. Whichever you choose, the answer is remembered in this browser for 180 days and then we ask again. Clearing your browser data forgets it, and so does a change to what we would collect: a different list is a new question, not an old answer.

You can change your mind at any moment from Privacy & analytics, at the foot of every page. Turning it off stops collection there and then. Nothing that happened before you turned it on is sent afterwards.

What analytics collects, if you allow it

Two halves. The first is the screens: which page you opened, in which order, how long you stayed, when you left, what you pressed and where on the page it was, and how quickly the page loaded. It also carries the plain facts of the browser you are reading in. Which browser and operating system, the whole line your browser announces itself with, how big the screen is, the language. And where you arrived from: the page that linked you, and the campaign tag on that link if it had one. The second is seven moments our own code names one by one: that a puzzle was started, that a grid was accepted, that a puzzle was published, that a share link, mail, image or print was chosen, that a solve was started, that a solve was finished, and that a paid feature was reached. Each of those seven carries at most one short word, picked from a fixed list: which share option was chosen, for instance.

What analytics never collects

No name and no email address is attached to any of it. If you are signed in, one thing is: a code derived from your account rather than the account itself, which is what lets the same person be counted across visits and devices and cannot be used to reach anything of yours. It exists only while you are signed in, and only if you have allowed these counts. What is attached is a random number kept in this browser, so the pages of one visit hang together and a second visit is not counted as a stranger; it means nothing outside these counts, and it goes when you turn them off. Puzzle links and codes never travel: an address arrives with the identifying part taken out, so “/p/[id]” is as much as anyone sees. None of the words you type: no seed words, no clues, no titles, no answers. The text on the page is stripped before anything is sent. No session recording. Nothing describing you is ever sent: no properties are attached to that code, so what it can answer is how many people came back, and nothing else about them.

When something breaks

If the page fails while you are using it, the same choice covers a short report about the failure. It carries what broke, which line of our code it broke on, and which screen you were on. That last one is the pattern, like “a puzzle page”, never the address of your puzzle. It carries your browser and screen size, the language and theme you are reading in, and the last few of the counts above. It never carries the words you typed. Sentry, in the EU, receives it and nothing else does. With analytics off, nothing is sent when the page fails either.

Who else sees it

PostHog Cloud EU, in Frankfurt, processes all of this on our behalf and does nothing else with it. Like any site you open, it sees the address your browser connects from, and our project is set to discard that address rather than keep it. What it does keep is the random number above, which is how one visit is told from another.

If you give us an email address

Three different things can happen to it, and they last for different lengths of time. An address you type so we can tell you a puzzle is ready, and then never confirm by clicking the link we send, is deleted along with the generation it belongs to, about seven days later. An address you do confirm becomes your account, and lasts as long as the account does. And if you tick the separate box asking to hear from us, that permission is kept on its own until you take it back. Every such email carries a one-click link that does exactly that, and nothing else.

What is kept in your browser anyway

Independent of analytics, and never sent anywhere: the theme you picked, the paper size you print on, the solving options you switched, the puzzles you have made on this device, how far you have got in a puzzle you are solving, and, only while a grid is being built, the words you typed and the number of the build itself, so that closing the tab does not lose it. Making a puzzle also sets one cookie, so that the puzzle stays yours to edit. Solving one sets nothing. Your answer to the analytics question is kept here too. And with analytics allowed, PostHog adds a cookie and an entry of its own, holding the random number that ties one visit together and nothing else. Turning analytics off throws that number away and stops anything being sent; clearing your browser data removes what is left behind.

Who runs this

An individual professional established in Italy, who decides what is collected here and is responsible for it. You can ask what is held about you, ask for it to be deleted, or object. The counts above are tied to a random browser number and not to a name, so we cannot look yours up from who you are. What we can do is stop collecting. Turning analytics off does that, the moment you do it.