This Privacy Policy describes the personal data we collect when you use wordle.global, why we collect it, how we use and protect it, and the rights you have over it. We are a small independent publisher and handle personal data with care.
1 · Who we are
The data controller is Hugo Montenegro, operator of wordle.global, reachable at contact@wordle.global. Operating address is available on request. Hugo Montenegro (operator) acts as the privacy officer responsible for data protection and is your point of contact for any privacy question at contact@wordle.global. If you're in the EU/EEA and need to exercise any data subject right, contact that address and we will respond without undue delay and in any case within 30 days.
2 · Personal data we collect
The categories of personal data we collect are:
- Account data (if you sign up): email address, chosen display name, hashed password or OAuth identifiers (Google, Apple, etc.), account creation timestamp.
- Game data: results of puzzles you play (which game, which language, win/loss, number of guesses, timings), streaks, badges, and derived statistics.
- User-submitted content: comments, bug reports, feedback you submit via the Service.
- Settings and preferences: language, dark mode, high-contrast mode, reduce-motion, accessibility settings — stored in your browser's localStorage and synced to your account if signed in.
- Technical data: IP address, user-agent, screen size, referrer URL, and approximate geographic region derived from IP. Used for security, abuse prevention, and analytics.
- Analytics events: page views, game events, errors, and aggregate performance metrics (see §10 below).
We do not knowingly collect: precise geolocation, financial data (outside of any future Premium checkout handled by a regulated payment processor), health data, or other special-category data under GDPR Article 9.
3 · Why we collect it (purposes and legal bases)
Under GDPR Article 6, our lawful bases are:
- Performance of contract (Art. 6(1)(b)): to provide the Service you asked for — game play, stats, accounts, comments, sync across devices.
- Legitimate interests (Art. 6(1)(f)): security and abuse prevention, aggregate analytics, bug diagnosis, improving the product. Your interests and rights are carefully balanced against ours; contact us if you disagree with a specific use.
- Consent (Art. 6(1)(a)): optional tracking technologies beyond what is strictly necessary (see §9). You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): responding to lawful requests from authorities and keeping records required by tax or consumer-protection law.
4 · How long we keep it (retention)
- Account data and game results: for as long as your account is active, and up to 90 days after deletion in backup systems.
- Server logs with IP addresses: up to 30 days for security and diagnostic purposes, then rotated.
- Analytics events: retained per the provider's defaults (see §10); aggregate reports are kept indefinitely.
- Comments and reports: while public, plus 12 months after hiding or deletion for moderation audit.
- Records required by law: for the minimum period required by applicable statute.
5 · Who we share data with
We do not sell, rent, or trade your personal data. We share limited data with the following processors, each bound by contract to process data only on our instructions and with appropriate safeguards:
- Hosting: Render (hosting, Postgres, CDN edges) — servers in the European Union and the United States.
- Content delivery and media storage: Cloudflare (CDN and R2 object storage) — used to serve the Service and store generated media.
- Error monitoring: Sentry — captures diagnostic error reports so we can fix crashes and bugs.
- Authentication (optional): Google (OAuth), Apple, and similar identity providers — only if you choose to sign in with them.
- Analytics: Google Analytics 4 and PostHog (see §10).
- Transactional email (if applicable): a reputable provider such as Resend or SendGrid — used only for account verification and similar service messages.
- Payment processing (future): if we offer Premium, a regulated payment processor (e.g. Polar, Stripe) handles payment data directly — we do not store card numbers.
- Law enforcement and legal authorities where we have a good-faith belief we are legally required to share, or to protect the rights, property, or safety of users or the public.
- Successors: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquirer under the same privacy commitments.
6 · International data transfers
Some of our processors are located outside the European Economic Area (for example, in the United States). When we transfer personal data of EU/EEA or UK users outside those regions, we rely on the European Commission's Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent safeguards to protect your data. A copy of our standard transfer agreements is available on request.
7 · Your rights
If you are in the European Economic Area, United Kingdom, or Switzerland, the GDPR gives you the following rights:
- Access: get a copy of your personal data.
- Rectification: correct inaccurate data.
- Erasure: ask us to delete your data ("right to be forgotten"), subject to lawful retention obligations.
- Restriction: pause processing while we verify a request.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests, including profiling.
- Withdraw consent: where processing is based on consent.
- Lodge a complaint with your national data protection authority (for Portugal: CNPD, cnpd.pt).
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the rights to know, delete, correct, and opt out of the sale or sharing of personal information, and to non-discrimination for exercising these rights. We do not sell personal information as defined by the CCPA.
To exercise any right, email contact@wordle.global. We may need to verify your identity before acting on a request. We will respond within 30 days (GDPR) or 45 days (CCPA).
8 · Security
We use industry-standard technical and organisational measures to protect personal data, including TLS encryption in transit, encryption at rest for account credentials, access controls, audit logs, and secure software development practices. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.
9 · Cookies and similar technologies
We use the following categories of storage in your browser:
- Strictly necessary: session cookies for authentication, CSRF protection, and localStorage for game state. These do not require consent under GDPR/ePrivacy.
- Preference: localStorage for your settings (language, dark mode, accessibility toggles). Necessary to provide the Service.
- Analytics: first-party analytics cookies (Google Analytics 4, PostHog). Where your jurisdiction requires consent for analytics cookies, we obtain it via a clear opt-in. You can control analytics consent in Settings or via your browser's cookie controls.
We do not currently use advertising cookies. If we introduce them in the future, we will update this Policy and request appropriate consent.
10 · Analytics specifics
Google Analytics 4: we use GA4 with IP-anonymisation enabled to measure aggregate traffic and feature usage. We do not use GA4 for advertising remarketing, signals, or demographics reporting. Google is the data controller for some GA4 data as described in their Privacy Policy. You can opt out via Google's opt-out browser add-on.
PostHog: product-analytics events captured through PostHog's EU-hosted infrastructure. We use PostHog to understand which features players use, diagnose bugs, and improve the product. You can opt out via Settings.
11 · Children
The Service is not directed at children under the age of 13 (US) or the age of digital consent under applicable EU member state law (13–16). We do not knowingly collect personal data from children under these thresholds. If you believe a child has provided us with personal data, please contact contact@wordle.global and we will delete it promptly.
Korea. Under the Korean Personal Information Protection Act (PIPA), the threshold is 14: creating an account requires attesting that you are 14 or older, and we refuse account creation for anyone under 14 pending verified guardian consent. If you are a parent or guardian who wishes to consent to an under-14 account, contact contact@wordle.global. Users under 14 may still use the Service without an account (guest mode), which collects no directly identifying information — only a random device identifier used to save game progress on that device.
12 · Automated decision-making and profiling
We do not engage in automated decision-making that produces legal or similarly significant effects concerning you. We perform basic profiling for analytics purposes (e.g. which puzzle difficulties are popular) but this does not affect your access to any feature.
13 · Changes to this Policy
We may update this Policy to reflect new features, new processors, or regulatory changes. If changes are material we will give reasonable advance notice. The "Last updated" date above reflects the current version.
14 · Contact
Privacy questions and requests: contact@wordle.global.