Privacy Policy
Topo Puzzles is a daily map puzzle at topopuzzles.io. This policy explains what we collect when you use the site or sign up for email, why, how long we keep it, and what you can do about it. We collect as little as we can. There are no accounts, no ads, no analytics and no third-party trackers.
In this policy, "Topo Puzzles", "we" and "us" mean the people who run topopuzzles.io. For privacy laws such as the GDPR, we are the "controller" of your personal data.
Contact: privacy@topopuzzles.io. Write to us about anything in this policy, or to use any of the rights in section 7.
1. The short version
- You can play without giving us your name, email or anything else about you.
- To save your progress and stop extra tries, your browser gets a random ID. Our server stores your answers and scores against it.
- If you sign up for email, we store your email address and a record that you agreed. We ask your birth month and year to check you're 13 or older, then throw them away.
- We don't sell or share your personal information, and we don't use it for advertising.
- You can download or delete your play data at any time on the Your data page, and unsubscribe from email with one click.
2. What we collect and why
When you play
| What | Why | Legal basis (GDPR) |
|---|---|---|
| A random player ID, created the first time you play. It's kept in your browser's local storage. Our server keeps only a scrambled (hashed) copy. | Links your answers to you so your progress survives a reload, and so each level takes only one final answer. | Legitimate interests: running the game fairly. |
| Your answers for each level, the number of tries, your points and when you answered. | To score your answers, show your results and history, and stop extra tries. | Legitimate interests: running the game. |
| The date your player ID was created and the date it was last used (date only, no time). | To delete play data that hasn't been used in 24 months. | Legitimate interests: keeping only what we need. |
We don't know who a player ID belongs to. We don't link it to your email address, your device or your IP address.
When you sign up for email
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Your email address. | To send you the emails you asked for. | Your consent. |
| A consent record: when you signed up, which form you used, the exact wording you agreed to, and the version of this policy at the time. | To show you agreed, as privacy and anti-spam laws require. | Legal obligation and legitimate interests (proving consent). |
| Whether you passed the age check (yes only). | To show we only sign up people 13 or older. | Legal obligation. |
| Whether you confirmed your address, and when. | Double opt-in: we send nothing else until you tap the link in our confirmation email. | Your consent. |
| Scrambled one-time codes for your confirmation and unsubscribe links. | So the links work, and only for you. | Legitimate interests: security. |
We ask for your birth month and year when you sign up. We use them only to check that you're 13 or older. We don't store them. If you're under 13, we store nothing from the form, and your browser remembers (in local storage) that sign-up isn't available.
Technical data
- IP address. Your IP address reaches our server with every request, as it does for any website. Our app keeps it in memory for up to 1 hour, only to limit how fast one connection can send requests (rate limiting). It isn't written to disk or linked to your player ID or email.
- Web server logs. Our web server keeps short logs (the page requested, the time and the response code) for up to 7 days to keep the site working and secure. They don't include IP addresses, browser details or link codes.
- No cookies. The site doesn't set cookies. It uses your browser's local storage for two things only: your player ID and, if it applies, the note that email sign-up isn't available. Both are needed for the features you use, so we don't show a cookie banner. You can clear them at any time in your browser settings.
What we don't collect
No names, accounts, passwords, phone numbers, birth dates, precise location, contacts, device fingerprints, ad IDs or analytics. We don't use advertising, tracking pixels, social media widgets or third-party fonts or scripts.
3. Email
If you sign up, we'll email you the daily puzzle email, a short note when each day's new map goes up at 7:00 AM Mountain Time, plus occasional updates and announcements, which may arrive on the same day as the puzzle email. You can unsubscribe anytime. Every email, including the confirmation email, says who it's from and includes an unsubscribe link and our postal address. Mail apps that support it also show a one-click unsubscribe button. Unsubscribing takes effect right away.
When you unsubscribe, we delete your email address and consent record. We keep only a scrambled (hashed) version of your address on a do-not-email list, so it isn't added back by mistake. If you sign up again later and confirm, it comes off that list.
We send email through Amazon Simple Email Service (Amazon SES), run by Amazon Web Services, Inc. (AWS) in the United States. SES receives your email address and the content of each email only to deliver it for us, under the AWS Data Processing Addendum, which includes the EU Standard Contractual Clauses. AWS keeps delivery records (such as the address, time and delivery result) for a limited time to run and secure the service.
If an email to you bounces, or you mark one of our emails as spam, SES tells us and adds your address to a do-not-email list. We then stop emailing you and keep only a scrambled (hashed) note of your address, so it isn't added back.
Our emails have no tracking pixels and no tracked links. We don't record whether you open an email or click a link in it.
4. How long we keep data
| Data | How long |
|---|---|
| Play data (player ID, answers, scores) | Until you delete it, or 24 months after the player ID was last used |
| Unconfirmed email sign-ups | 7 days, then deleted if not confirmed |
| Confirmed email list members | Until you unsubscribe or ask us to delete it |
| Do-not-email list (hashed address) | As long as we send email, so we honor your choice |
| IP addresses for rate limiting | Up to 1 hour, in memory only |
| Web server logs (no IP addresses) | Up to 7 days |
| Backups | Encrypted, kept up to 30 days, then deleted. Data you delete leaves our backups within 30 days. |
5. Who else handles your data
We don't sell, rent or share your personal information with anyone for their own use. We use a small number of service providers ("processors") who handle data only to run the site for us:
- Hosting: our server provider, which hosts the site and its database in the United States.
- Email delivery: Amazon Simple Email Service (Amazon SES), from Amazon Web Services, Inc., in the United States. It handles your email address and our emails to you only to deliver them (see section 3).
We may disclose information if the law requires it, to protect people's safety, or to protect the site from fraud or abuse. If Topo Puzzles is ever sold or transferred, this data would go to the new owner under the same promises, and we'd tell email subscribers first.
If you tap "Share" or "Post on X" on the results page, you choose to send your score text to that app or site. Their own privacy policies apply. Your score text and share card never include answers or personal information.
6. Where your data is stored
Our servers are in the United States. If you use the site from outside the US, your data is transferred to the US. Where the law requires it, we use safeguards such as the European Commission's Standard Contractual Clauses with our providers.
7. Your rights
Wherever you live, you can:
- See and download your play data: Your data → Download my data.
- Delete your play data: Your data → Delete my data.
- Unsubscribe from email: the link in any email, at any time.
- Ask for a copy of, correction of or deletion of anything else we hold about you, by writing to privacy@topopuzzles.io.
If you're in the EU, UK or EEA, you also have the right to object to our use of your data, to restrict it, to data portability, and to withdraw consent at any time (this doesn't affect what we did before). You can complain to your local data protection authority, but please contact us first so we can try to fix it.
If you're in California or another US state with a privacy law, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing. We don't sell or share personal information, or use it for targeted advertising, so there's nothing to opt out of. That also covers opt-out signals such as Global Privacy Control: the opt-out already applies to everyone. We won't treat you differently for using any of these rights. You can use an authorized agent to make a request.
How we handle requests. We reply within 30 days (45 days where a US state law allows it, and we'll tell you if we need the extra time). Because we don't know who a player ID belongs to, the self-serve page is the way to reach play data. For email data, we'll confirm the request by writing to that address. Requests are free.
8. Children
Topo Puzzles is for a general audience. It isn't aimed at children under 13, and we don't knowingly collect personal information from them. Anyone under 13 can't sign up for email: the sign-up form asks for a birth month and year and stops if the person is under 13, without storing anything. The random player ID used for play is used only to run the game, not to identify, contact or advertise to anyone.
If you're 13 or older but under the age of digital consent where you live (up to 16 in some countries), ask a parent or guardian before signing up for email.
If you think a child under 13 has given us personal information, write to privacy@topopuzzles.io and we'll delete it. When we learn we've collected a child's information, we delete it.
9. Security
We use HTTPS everywhere, store player IDs and link codes only in scrambled (hashed) form, keep answers and personal data off the public web server, limit request rates, keep the server updated, and encrypt backups. No system is perfectly secure. If a breach puts your data at risk, we'll tell you and the authorities as the law requires (within 72 hours for regulators under the GDPR).
10. Changes to this policy
When we change this policy, we'll update the version and effective date at the top. If a change materially affects how we use your email address, we'll email subscribers before it takes effect. The policy version you agreed to is saved with your consent record.
11. Contact
Questions, requests or complaints: privacy@topopuzzles.io.