← Back to World Clue

Policy

Privacy Policy

This page explains what personal data World Clue collects, why it is collected, how it is stored, and what rights you have.

Effective date: 18 March 2026

Data controller

World Clue is operated as an independent project. If you have questions about your data, contact us at [email protected].

Consent and legal basis

When you create an account — whether via email/password or Google sign-in — you are asked to confirm that you agree to these processing activities and to the Terms of Use. The legal bases for processing your personal data are:

  • Consent (Art. 6(1)(a) GDPR) — given when you create an account or sign in with Google.
  • Performance of a contract (Art. 6(1)(b)) — necessary to provide the game and account features described in the Terms of Use.
  • Legitimate interest (Art. 6(1)(f)) — for fraud/abuse prevention (e.g. hashed fingerprints to limit duplicate submissions).

Account data

When you create a World Clue account we store the following personal data:

  • Display name — shown publicly on leaderboards. If you sign in with Google and do not change your display name, it will be abbreviated (e.g. "FirstName L.") on public surfaces to limit exposure of your full name.
  • Email address — used for login; not displayed publicly.
  • Password hash — your password is hashed with PBKDF2 and never stored in plain text.
  • Avatar URL — imported from Google if you sign in with Google; otherwise none.

Google sign-in

If you choose "Continue with Google", World Clue requests limited profile information from Google (name, email, profile picture) via OAuth 2.0. This data is used solely to create or link your World Clue account. We do not access your Google contacts, calendar, or any other Google services.

Google's own privacy policy governs how Google processes your data: policies.google.com/privacy.

Gameplay results

World Clue stores daily game result submissions for features such as score distributions and leaderboards. Submitted data includes the game date, total guesses, number of countries completed, and per-country details. If you are logged in, results are linked to your account.

For anonymous players, the service may derive non-public hashed identifiers from request metadata (IP address and browser user agent) to limit duplicate submissions. These hashes cannot be reversed to identify you personally.

Analytics events

World Clue records anonymous, first-party analytics events (e.g. page views, game starts) to understand how the site is used and to improve it. These events contain no personal identifiers; they use locally generated random session and user IDs stored in localStorage. No third-party analytics services, advertising trackers, or cross-site tracking technologies are used. The legal basis for this processing is legitimate interest.

Country data

The country profiles and related facts shown in World Clue are assembled from public and license-compatible sources. The site is intended for informational and educational use.

Cookies and local storage

World Clue uses the following browser storage mechanisms:

  • wc_session — a secure, HttpOnly cookie that maintains your login session. It expires after 30 days of inactivity. This cookie is strictly necessary for the account feature to work and does not require separate cookie consent under the ePrivacy Directive.
  • Local storage — stores gameplay progress, theme preference, and related in-browser settings so the app can function smoothly between visits.

World Clue does not use third-party advertising or analytics cookies.

Third-party services

The site is hosted on Cloudflare Pages. Cloudflare may process request metadata (IP addresses, headers) for security and performance purposes under their own privacy policy: cloudflare.com/privacypolicy.

Data retention

Account data is retained as long as your account exists. Game results linked to your account are anonymised (user ID removed) if you delete your account. Anonymous gameplay hashes are stored indefinitely for abuse-prevention purposes.

International transfers

Your data is processed on Cloudflare's global edge network. Cloudflare has committed to Standard Contractual Clauses (SCCs) and other safeguards for any transfers of personal data outside the European Economic Area. See Cloudflare's GDPR centre for details.

Your rights

Under the GDPR and similar data protection laws you have the right to:

  • Access — view the personal data we hold about you.
  • Portability — export your data in a machine-readable format.
  • Rectification — correct inaccurate personal data.
  • Erasure — delete your account and personal data.
  • Objection — object to the processing of your data.
  • Withdraw consent — you may withdraw consent at any time by deleting your account; this does not affect the lawfulness of processing carried out before withdrawal.

You can exercise your right to access (export) and erasure (deletion) directly from the Account settings page when logged in. For other requests contact [email protected].

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement.

Minimum age

World Clue is not directed at children under 16. If you are under 16, please do not create an account without parental consent.

Changes

This policy may be updated as the project evolves. The "Effective date" at the top of this page will reflect the latest revision. Material changes will be noted on this page. Continued use of the site after changes means you accept the updated policy.