Privacy Policy
Wordlink is a two-player word game. This policy explains what information the service processes, why it is needed, how long it is kept, and the choices available to you.
1. Scope and operator
This policy applies to the Wordlink website at wordlink-88525.web.app. Wordlink is an independently maintained project. References to “Wordlink,” “we,” or “us” mean the maintainer of this service.
Wordlink does not currently sell personal information, serve advertising, or use Google Analytics for advertising or personalization.
2. Information we process
| Category | Examples | When it is processed |
|---|---|---|
| Guest and account identifiers | A Firebase user ID; if you choose to link an account, your email address, display name, profile image, authentication provider, and provider identifier. | A guest identifier is created automatically. Additional details are received only when you choose Facebook, Google, or email-link sign-in. |
| Game and room information | Your chosen player name, room membership and role, room code, timestamps, word-chain entries, guesses, match confirmations, typing presence, round settings, word-list version and next-word cursor for each language, and connection state. | When you create, join, or play in a room. Your invited partner can see the information required to play the round and avoid seed words either of you has already seen. |
| Dictionary and semantic match processing | An eligible normalized one- or two-word guess or linked word, language, dictionary provenance and review flags, derived embeddings, hashed term and pair identifiers, similarity score, decision, model version, and aggregate usage counts. | Eligible gameplay terms are added to a permanent shared dictionary without a room code or player identifier. When semantic catches are enabled and the local exact and spelling matchers do not find a match, the two phrases are also sent to OpenAI for embedding. |
| Statistics | Rounds and matches, streaks, aggregate guess counts, best average speed, last-played date, and locally stored per-partner chemistry history. | As you complete rounds. Aggregate statistics are synced to the cloud only after you link an account. |
| Security and operations | Network address processed transiently into a daily rotating salted hash, user agent, App Check and reCAPTCHA signals or tokens, request timestamps, authentication events, error information, and rate-limit counters. Wordlink does not store the raw network address in its application database or logs. | Automatically when your browser connects to Firebase Hosting and backend services. Firebase and Google infrastructure may process the source IP under their own policies. |
| Optional product analytics | Funnel steps such as start, invite, play, finish, replay and share; round outcome; aggregate timing and count fields; approximate location; browser and device information; and a pseudonymous Analytics client ID. | Only after you select “Accept analytics.” Names, email addresses, room codes, seed words, chain words, and guesses are not sent to Google Analytics. |
Information stored in your browser
Wordlink uses local browser storage for your player name, UI and word-language choices, the versioned Free Play word-list cache and next-word cursor for each language, local statistics and partner history, analytics choice, and an email address used to complete email-link sign-in. That email remains on the device until it is replaced or you clear the site’s browser data. Firebase Authentication may also use browser storage to keep you signed in.
Sharing a room or result uses your browser’s clipboard only when you press a copy or share control. Wordlink does not read unrelated clipboard contents.
3. How we use information
- Provide guest sessions, rooms, multiplayer synchronization, Free Play words, results, and optional cross-device statistics.
- Build a reusable multilingual dictionary from normalized gameplay terms, while keeping player-observed terms ineligible for Free Play seeds unless separately reviewed.
- Compare eligible word pairs after a local spelling miss, return a consistent semantic match decision, and reuse cached decisions to reduce repeat processing.
- Authenticate users and link a guest session to a provider selected by the user.
- Enforce security rules, detect automated abuse, apply hourly usage limits, diagnose errors, and protect service availability.
- Remember local preferences and statistics on the device.
- With consent, understand the anonymous start-to-finish product funnel and improve the game.
- Comply with applicable law and protect users, the service, and the rights of others.
Where applicable law requires a legal basis, service and security processing is performed to provide the service you request and for legitimate interests in operating and protecting Wordlink. Optional Analytics processing is based on your consent, which you may withdraw at any time.
6. Retention
- Room data: rooms and their word/guess messages expire after 12 hours and are removed by an hourly cleanup process.
- Dictionary and semantic scoring: eligible normalized terms, their hashes, provenance and review flags, and any derived vectors are retained as a permanent shared dictionary. Hashed pair identifiers, scores, version metadata, and override audit history are also retained so repeated pairs stay consistent. Dictionary and pair records contain no player UID or room code, but normalized terms can still contain personal information a player chose to type and are not treated as anonymous.
- Typing presence: removed after inactivity or disconnection.
- Rate-limit records: per-account counters and daily rotating salted network hashes are retained for up to about three hours after their current hourly window starts, then removed by scheduled cleanup. Wordlink does not store raw network addresses in these records.
- Free Play word list: the canonical versioned language list is a public static game asset and contains no player identifiers.
- Guest authentication: anonymous Firebase accounts more than 30 days old are eligible for automatic deletion. Firebase may retain authentication security logs, including IP addresses, for its own shorter operational periods.
- Linked accounts and cloud statistics: retained until the account is deleted or a valid deletion request is completed, subject to limited backup, security, fraud-prevention, and legal retention.
- Local browser data: retained until you clear it, the browser removes it, or you use a different browser profile.
- Analytics: retained according to the configured Google Analytics retention settings and Google’s policies. Analytics cookies on the device are configured for up to 180 days.
7. Your choices and rights
- Play without linking Facebook, Google, or an email address.
- Decline optional Analytics or change your choice later through Analytics settings.
- Clear locally stored names, preferences, word-list progress, statistics, and authentication state through your browser’s site-data controls.
- Manage Wordlink’s connection from your Facebook or Google account settings. Revoking provider access does not by itself delete the separate Firebase account or already stored Wordlink statistics.
- Request access, correction, deletion, restriction, or a portable copy where required by applicable law.
- Object to certain processing or withdraw consent without affecting processing that occurred before withdrawal.
- Complain to the privacy or data-protection authority in your jurisdiction.
We may need to verify that you control the relevant account before acting on a request. Some requests may be limited where retaining information is required for security, fraud prevention, legal compliance, or the rights of others.
8. Account and data deletion instructions
Permanent instructions URL: https://wordlink-88525.web.app/data-deletion.html.
Registered users can delete their Wordlink account directly in the game:
- Sign in to the account you want to delete.
- Open Save your stats from the account control.
- Select Delete account and data and confirm.
- If prompted, sign in again. This recent-authentication check helps prevent someone with temporary access to an unlocked browser from deleting the account.
This deletes the Firebase Authentication account, cloud statistics, account rate-limit record, locally stored game statistics and sign-in email, and the account’s data in its current room. If the user owns the current room, the entire room is removed; otherwise their membership, typed gameplay records, control events, and typing presence are removed. A short-lived shared network limiter cannot be tied back to or deleted for one account and expires automatically; other room data expires within 12 hours. Permanent shared dictionary, semantic-pair, and aggregate-usage records contain no player UID or room code and cannot be isolated to one account, so they are not removed automatically by account deletion. Deleting a Wordlink account does not delete the separate Facebook or Google account.
Other browser-only preferences, including the local player name, language, and Analytics choice, can be removed through the browser’s site-data controls for wordlinkapp.com, wordlink-88525.web.app, and wordlink-88525.firebaseapp.com.
9. Children’s privacy
Wordlink is a general-audience service and is not directed to children under 13. We do not knowingly request that children provide personal information. If you believe a child has provided account information, contact us so it can be reviewed and deleted as appropriate.
10. Security
Wordlink uses encrypted HTTPS connections, Firebase Authentication, App Check, access-control rules, bounded data schemas, short room retention, and rate limiting. No internet service can guarantee absolute security, so avoid entering sensitive personal information as a player name, word, or guess.
11. Changes to this policy
This policy may be updated when Wordlink’s features, providers, or legal obligations change. The revised date will appear at the top. Material changes may also be highlighted in the product where appropriate.
12. Contact
For privacy questions, contact the Wordlink maintainer through the Wordlink GitHub repository. Do not include personal information in a public issue; request a private contact channel instead.
This policy describes the service’s current implementation. Provider practices may change independently; consult the linked provider policies for their latest terms.