Privacy Policy
The short version: We collect what we need to run a word game. We don't sell your data, we don't track you across the web, and we don't build advertising profiles. Our full promise is here.
1. Who We Are
Data Controller: Rounds for Squares LLC, a Florida limited liability company.
Contact: privacy@wordfreak.ai
Mailing Address: Rounds for Squares LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702
Word Freak is a Scrabble-style puzzle and coaching platform available at wordfreak.ai and via mobile applications.
2. Data We Collect
| Category | Specific Data | Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|---|---|
| Account | Email, username, hashed password, date of birth | Account management, COPPA compliance, age verification | Contract (Art. 6(1)(b)), Legal obligation (Art. 6(1)(c)) | Until deletion + 30 days |
| Gameplay | Moves, rack, timing, scores, board states, outcomes, puzzle ratings | Core service, leaderboards, coaching | Contract (Art. 6(1)(b)) | Until deletion + 30 days |
| Social | Friends list, invite codes, co-op session data, tournament entries | Social features, multiplayer, competitions | Contract (Art. 6(1)(b)) | Until deletion + 30 days; co-op sessions hard-deleted 2 hours after expiry |
| Payment | Stripe customer ID, subscription events (we never see full card numbers) | Billing | Contract (Art. 6(1)(b)) | As required by tax law |
| Usage | Feature usage events (daily puzzle count, analysis count) | Rate limiting, entitlement enforcement | Contract (Art. 6(1)(b)) | Until deletion + 30 days |
| Game History | Game records (mode, status, player IDs, board state) | Game replay, coaching features | Contract (Art. 6(1)(b)) | Until deletion + 30 days |
| Technical | Device type, OS version, app version, crash logs | Bug fixing, compatibility | Legitimate interest (Art. 6(1)(f)) | 90 days rolling |
| Analytics | Aggregate page views via Plausible (no cookies, no personal identifiers) | Usage patterns | Legitimate interest (Art. 6(1)(f)) | Aggregate only, no individual records |
3. Data We Do Not Collect
- Location data (GPS or IP-based geolocation beyond country)
- Contact lists or address books
- Microphone or camera access
- Browsing history outside Word Freak
- Data from other apps on your device
- Advertising identifiers (IDFA, GAID)
- Biometric data
- Keystroke patterns, mouse movements, or screen recordings
4. No Sale of Personal Data
We do not sell, rent, lease, or otherwise transfer personal data to third parties for monetary or other valuable consideration. This constitutes our response to the CCPA/CPRA "Do Not Sell or Share My Personal Information" requirement (Cal. Civ. Code Section 1798.120). We do not engage in "sharing" for cross-context behavioral advertising.
5. No Targeted Advertising
Word Freak does not display targeted, behavioral, or programmatic advertising. If we ever introduce advertising, it will be contextual only and not based on user data or behavior.
6. Service Providers (Subprocessors)
We use the following service providers, each operating under a data processing agreement:
| Provider | Purpose | Data Shared | DPA Status |
|---|---|---|---|
| Clerk | Authentication | Email, OAuth tokens | In progress |
| Convex | Database | All application data | In progress |
| Stripe | Payments | Customer ID, billing events | In progress |
| Vercel | Hosting | Server logs, deployment | In progress |
| Plausible | Analytics | Aggregate page views (no cookies, no PII) | In progress |
Current subprocessor list maintained at wordfreak.ai/subprocessors, updated within 30 days of any change.
7. Social Features and Data Sharing Between Users
When you use social features, certain data is visible to other users:
- Friends: Your display name, avatar, daily score, sparks, and puzzle count are visible to accepted friends.
- Tournaments: Your display name, avatar, rank, and scores appear on leaderboards. Tournament leaderboards are currently accessible without authentication — we plan to add an auth gate in a future update.
- Co-op: Your cursor position and placed tiles are visible to your co-op partner during shared sessions.
- Ratings: Your difficulty ratings are aggregated anonymously. Any free-text comments are associated with your display name.
You may control visibility through profile settings and by choosing which features to use.
8. AI and Machine Learning
Word Freak's engine was trained exclusively on self-play data (computers playing computers). No human game data was used in training.
We do not currently use any user game data for AI training. If we build an opt-in program in the future, it will require separate affirmative consent, will be clearly announced, and this policy will be updated before it launches.
9. Data Retention and Deletion
Upon account deletion:
- 30 days: Active data purged from production systems.
- 90 days: Data purged from encrypted backups.
- Co-op sessions: Hard-deleted 2 hours after expiry via automated cleanup.
- Exceptions: Anonymized aggregate statistics (non-reidentifiable) and data required by law (tax records, legal process).
- Confirmation: We send an email confirming deletion completion.
10. Children's Privacy (COPPA)
Word Freak requires users to be 13 or older. We do not knowingly collect personal information from children under 13.
During registration, users provide their birth year. Users under 13 are blocked from creating an account. We do not currently have a verifiable parental consent (VPC) mechanism as required by COPPA (15 U.S.C. Sections 6501-6506) for under-13 accounts. Until we build one properly, we block rather than misrepresent compliance.
If you believe a child under 13 has created an account, contact us at privacy@wordfreak.ai and we will delete it promptly.
11. Community Ratings Disclosure
Per FTC 16 CFR Part 465 (Consumer Review Rule): community difficulty ratings reflect genuine user opinions. Sparks are awarded for participation regardless of rating value. Developer and internal test ratings are purged before public display. We do not suppress, edit, or re-order ratings based on sentiment.
12. Your Rights
All Users
- Access: Request a copy of your personal data.
- Deletion: Delete your account and all associated data.
- Portability: Export game data in GCG, JSON, or CSV format.
- Correction: Update inaccurate personal information.
- Opt-out of analytics: We honor Global Privacy Control (GPC) signals.
California Residents (CCPA/CPRA)
Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of Sale/Sharing (we don't sell), Right to Limit Sensitive Data Use, Non-Discrimination. Contact: privacy@wordfreak.ai.
Texas Residents (TDPSA)
Right to confirm processing, access, correct, delete, and obtain portable copies. Right to opt out of targeted advertising, sale, and profiling (we don't engage in any). We honor GPC signals. 60-day right to cure from violation notice.
EEA/UK/Switzerland Residents (GDPR)
Rights under Articles 15-21: Access, Rectification, Erasure, Restriction, Portability, Object. International transfers rely on Standard Contractual Clauses. You may lodge a complaint with your local supervisory authority.
13. Cookies and Local Storage
Word Freak uses:
- Authentication cookies (Clerk): Strictly necessary for login. Not used for tracking.
- localStorage: Game state, preferences, streak data. Never transmitted to servers or third parties.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
14. Breach Notification
In the event of a data breach affecting your personal data:
- Supervisory authorities: Notified within 72 hours of confirmed breach where required (GDPR Art. 33).
- Affected users: Notified without undue delay when the breach is likely to result in high risk to your rights and freedoms (GDPR Art. 34), and within the timeframes required by applicable state law (Florida: 30 days; other states: as specified by statute).
- Notification will include: what happened, what data was affected, what we're doing about it, and what you can do.
Security vulnerabilities may be reported to security@wordfreak.ai.
15. Changes to This Policy
We provide 30 days' advance email notice before material changes. The notice includes a plain-English summary and a redlined diff. Version history maintained at wordfreak.ai/legal/history.
16. Contact
Privacy inquiries: privacy@wordfreak.ai
Data Controller: Rounds for Squares LLC, Florida, United States