Privacy Policy

Topo Puzzles is a daily map puzzle at topopuzzles.io. This policy explains what we collect when you use the site or sign up for email, why, how long we keep it, and what you can do about it. We collect as little as we can. There are no accounts, no ads, no analytics and no third-party trackers.

In this policy, "Topo Puzzles", "we" and "us" mean the people who run topopuzzles.io. For privacy laws such as the GDPR, we are the "controller" of your personal data.

Contact: privacy@topopuzzles.io. Write to us about anything in this policy, or to use any of the rights in section 7.

1. The short version

2. What we collect and why

When you play

What Why Legal basis (GDPR)
A random player ID, created the first time you play. It's kept in your browser's local storage. Our server keeps only a scrambled (hashed) copy. Links your answers to you so your progress survives a reload, and so each level takes only one final answer. Legitimate interests: running the game fairly.
Your answers for each level, the number of tries, your points and when you answered. To score your answers, show your results and history, and stop extra tries. Legitimate interests: running the game.
The date your player ID was created and the date it was last used (date only, no time). To delete play data that hasn't been used in 24 months. Legitimate interests: keeping only what we need.

We don't know who a player ID belongs to. We don't link it to your email address, your device or your IP address.

When you sign up for email

What Why Legal basis (GDPR)
Your email address. To send you the emails you asked for. Your consent.
A consent record: when you signed up, which form you used, the exact wording you agreed to, and the version of this policy at the time. To show you agreed, as privacy and anti-spam laws require. Legal obligation and legitimate interests (proving consent).
Whether you passed the age check (yes only). To show we only sign up people 13 or older. Legal obligation.
Whether you confirmed your address, and when. Double opt-in: we send nothing else until you tap the link in our confirmation email. Your consent.
Scrambled one-time codes for your confirmation and unsubscribe links. So the links work, and only for you. Legitimate interests: security.

We ask for your birth month and year when you sign up. We use them only to check that you're 13 or older. We don't store them. If you're under 13, we store nothing from the form, and your browser remembers (in local storage) that sign-up isn't available.

Technical data

What we don't collect

No names, accounts, passwords, phone numbers, birth dates, precise location, contacts, device fingerprints, ad IDs or analytics. We don't use advertising, tracking pixels, social media widgets or third-party fonts or scripts.

3. Email

If you sign up, we'll email you the daily puzzle email, a short note when each day's new map goes up at 7:00 AM Mountain Time, plus occasional updates and announcements, which may arrive on the same day as the puzzle email. You can unsubscribe anytime. Every email, including the confirmation email, says who it's from and includes an unsubscribe link and our postal address. Mail apps that support it also show a one-click unsubscribe button. Unsubscribing takes effect right away.

When you unsubscribe, we delete your email address and consent record. We keep only a scrambled (hashed) version of your address on a do-not-email list, so it isn't added back by mistake. If you sign up again later and confirm, it comes off that list.

We send email through Amazon Simple Email Service (Amazon SES), run by Amazon Web Services, Inc. (AWS) in the United States. SES receives your email address and the content of each email only to deliver it for us, under the AWS Data Processing Addendum, which includes the EU Standard Contractual Clauses. AWS keeps delivery records (such as the address, time and delivery result) for a limited time to run and secure the service.

If an email to you bounces, or you mark one of our emails as spam, SES tells us and adds your address to a do-not-email list. We then stop emailing you and keep only a scrambled (hashed) note of your address, so it isn't added back.

Our emails have no tracking pixels and no tracked links. We don't record whether you open an email or click a link in it.

4. How long we keep data

Data How long
Play data (player ID, answers, scores) Until you delete it, or 24 months after the player ID was last used
Unconfirmed email sign-ups 7 days, then deleted if not confirmed
Confirmed email list members Until you unsubscribe or ask us to delete it
Do-not-email list (hashed address) As long as we send email, so we honor your choice
IP addresses for rate limiting Up to 1 hour, in memory only
Web server logs (no IP addresses) Up to 7 days
Backups Encrypted, kept up to 30 days, then deleted. Data you delete leaves our backups within 30 days.

5. Who else handles your data

We don't sell, rent or share your personal information with anyone for their own use. We use a small number of service providers ("processors") who handle data only to run the site for us:

We may disclose information if the law requires it, to protect people's safety, or to protect the site from fraud or abuse. If Topo Puzzles is ever sold or transferred, this data would go to the new owner under the same promises, and we'd tell email subscribers first.

If you tap "Share" or "Post on X" on the results page, you choose to send your score text to that app or site. Their own privacy policies apply. Your score text and share card never include answers or personal information.

6. Where your data is stored

Our servers are in the United States. If you use the site from outside the US, your data is transferred to the US. Where the law requires it, we use safeguards such as the European Commission's Standard Contractual Clauses with our providers.

7. Your rights

Wherever you live, you can:

If you're in the EU, UK or EEA, you also have the right to object to our use of your data, to restrict it, to data portability, and to withdraw consent at any time (this doesn't affect what we did before). You can complain to your local data protection authority, but please contact us first so we can try to fix it.

If you're in California or another US state with a privacy law, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing. We don't sell or share personal information, or use it for targeted advertising, so there's nothing to opt out of. That also covers opt-out signals such as Global Privacy Control: the opt-out already applies to everyone. We won't treat you differently for using any of these rights. You can use an authorized agent to make a request.

How we handle requests. We reply within 30 days (45 days where a US state law allows it, and we'll tell you if we need the extra time). Because we don't know who a player ID belongs to, the self-serve page is the way to reach play data. For email data, we'll confirm the request by writing to that address. Requests are free.

8. Children

Topo Puzzles is for a general audience. It isn't aimed at children under 13, and we don't knowingly collect personal information from them. Anyone under 13 can't sign up for email: the sign-up form asks for a birth month and year and stops if the person is under 13, without storing anything. The random player ID used for play is used only to run the game, not to identify, contact or advertise to anyone.

If you're 13 or older but under the age of digital consent where you live (up to 16 in some countries), ask a parent or guardian before signing up for email.

If you think a child under 13 has given us personal information, write to privacy@topopuzzles.io and we'll delete it. When we learn we've collected a child's information, we delete it.

9. Security

We use HTTPS everywhere, store player IDs and link codes only in scrambled (hashed) form, keep answers and personal data off the public web server, limit request rates, keep the server updated, and encrypt backups. No system is perfectly secure. If a breach puts your data at risk, we'll tell you and the authorities as the law requires (within 72 hours for regulators under the GDPR).

10. Changes to this policy

When we change this policy, we'll update the version and effective date at the top. If a change materially affects how we use your email address, we'll email subscribers before it takes effect. The policy version you agreed to is saved with your consent record.

11. Contact

Questions, requests or complaints: privacy@topopuzzles.io.