SpellIt∞ is a word game built to respect you. We collect as little as possible, we never sell your data, and the features that could expose you (your location, who you are, where you play) are engineered to stay private by default. This policy explains what we handle and the rights you have over it, in plain language.
1. Who we are
SpellIt∞ ("we", "us") operates this game and its servers. For privacy questions, and to exercise any right below, contact us at the address in section 14. This policy covers the SpellIt∞ web app and native mobile apps.
2. The two-persona model
You have a PUBLIC persona (a username and avatar you choose) and a PRIVATE persona. Strangers, spectators, and leaderboards only ever see your public persona. Your friends can see your private persona only if you add them. Your word plays and game statistics are treated as public game data tied to your public persona. But WHERE you play (your play geography) is private and is never attached to you for others to browse.
3. What we collect
- Account: If you play as a guest, we create an anonymous id, with no email and no name required. If you verify an account (email magic-link, or Google / Apple / Microsoft sign-in), we store your email and which sign-in methods you linked. For social sign-in we verify the provider's signed token and never see or store your provider password.
- Public persona: The username and avatar you set, plus optional profile details you choose to make visible.
- Gameplay: Boards, moves, words, scores, coins, hints, and statistics needed to run games and leaderboards.
- Location, in Discover (only if you turn it on): Your position is rounded to an area of roughly 11 km on your device BEFORE anything is sent, so your precise coordinates never leave your phone.
- Location, in treasure hunts (only if you turn it on): Your position is sent to our server so it can work out which map square you are standing on. We do not keep it: only the square is stored, and the position itself is discarded once the square is known.
- Your own dot on the map: It is drawn by your phone from its own GPS. It is never sent to us, and no other player ever sees where you are. Location is off until you choose to use it, and a manual area entry is offered instead of device GPS.
- Device & technical: App version, platform, language, and basic logs needed for security and to keep the service running (engineering telemetry: errors and performance).
- Analytics (opt-in only): If, and only if, you opt in, we collect anonymous usage and rough demographics through Google Analytics 4 to understand what to improve. This is off by default and revocable anytime in Profile → Privacy. See section 8.
4. What we deliberately DON'T do
These are design guarantees, not just promises:
- We do not keep a reverse index from your account to the boards you've played, so no one can pull up "every place this person played."
- Live-presence counts for an area only appear when at least three players are present (k-anonymity), so a single person is never pinpointed.
- Board pins can be deliberately fuzzed, and your own device location is only ever sent as a coarse cell.
- We do not sell your personal data or share it for third-party advertising.
- We do not instrument manipulative signals (for example we don't log "streak broken" to nag you back). No FOMO, no dark patterns. That is part of our human-first charter.
5. Why we're allowed to (legal bases)
Where the GDPR / UK GDPR applies, we rely on: performing our contract with you (running the game you asked for); your consent (analytics, using your location, optional geo-leaderboards); and our legitimate interests (keeping the service secure and working). You can withdraw consent at any time without affecting play.
6. How we use what we collect
- Run games, save progress, and sync across your devices.
- Show leaderboards and, if you opt in, area-based ladders, segmented so competition stays fair.
- Keep accounts secure and prevent abuse.
- Improve the game (only with analytics you opted into).
7. Who we share it with
We use a small set of trusted providers strictly to run the service, never to sell you:
- Google, Apple, Microsoft: only to verify your sign-in if you choose social login.
- Google Analytics: only if you opt into analytics (section 8).
- OpenStreetMap: supplies map imagery in Discover; your identity is not sent with tile requests.
- Our cloud host (Microsoft Azure): stores game data to operate the service.
We may disclose data if legally required, or to protect the rights and safety of players and the service.
8. Analytics & cookies
We don't use advertising cookies. Analytics are strictly opt-in: until you say yes, Google Analytics is loaded in a consent-denied state (Google Consent Mode v2) and stores nothing. If you opt in, we send a small, curated set of anonymous events (e.g. a game started, a word played) and allow rough demographics, never your name, your messages, or where you play. Turn it off anytime in Profile → Privacy and we stop immediately.
9. Children & guardians
Account creation may ask for your birth YEAR only, never a full birthdate, and it is never shown to other players. Players under 16 can always play solo, but online multiplayer and chat stay locked until a parent or guardian approves by email. The approving guardian links their own account: they can review the child's chat messages in the app, receive a weekly summary email, delete any of the child's messages (a "deleted" mark remains), and turn online access off at any time. If you believe a child has given us personal data without consent, contact us and we will delete it.
A linked guardian can close their child's account themselves, from the Family screen, and it is erased the same way any account is.
9a. In-game chat
Table talk at a game board is visible to the players seated there and is stored with that board (it may appear in replays). On public boards only curated quick-chat phrases can be sent; free-typed messages are limited to private tables and mutual friends. Deleting a message removes its text and leaves a "deleted" mark. You can mute any player for yourself and report any message to our safety team.
10. Data retention
We keep account and game data while your account is active. A guest account is erased after 12 months without being used. Games you played at a shared table stay on those boards, with your name replaced: that board belongs to the people you played with too. When you delete your account we remove your personal data, except limited records we must keep for security, legal, or fraud-prevention reasons. One of those is a note that the account was closed, when, and which of three reasons it was: you closed it, a guardian closed it, or it went quiet for a year. The note holds no name and nothing else about you; it is what lets us tell you what happened if you come back. Anonymous, aggregated stats that cannot identify you may be retained. You can delete your account at any time from inside the app, or from our deletion page, which lists exactly what goes and what stays.
11. Your rights
Depending on where you live (including the EU/UK under GDPR and California under the CCPA/CPRA) you can:
- Access and export your data. The Games screen saves a bundle of your games, public profile, wallet and statistics; it deliberately leaves out your email address and private profile, so it is safe to share with support. For a complete copy of everything we hold about you, ask us and we will send one.
- Correct or update your details in your profile.
- Delete your account and personal data.
- Withdraw consent (analytics, location) anytime.
- Object to or restrict certain processing, and lodge a complaint with your local data-protection authority.
We will never charge you or degrade the game for exercising these rights.
12. Security
We protect data in transit with encryption (HTTPS/TLS), store session tokens rather than provider passwords, and limit access to game data. No system is perfectly secure, but we design to minimize what a breach could ever expose, which is why location and identity are kept coarse and separated by default.
13. International transfers
We may process data in countries other than yours, including the United States, using appropriate safeguards (such as standard contractual clauses) where required. Analytics data handled by Google is subject to Google's own safeguards.
14. Contact
Questions, requests, or complaints about privacy, including data access, correction, or deletion, reach the SpellIt∞ team at spellitsupport@codefromhome.com.
15. Changes to this policy
We'll update this policy as the game evolves and change the effective date above. For material changes we'll give in-app notice. Continuing to play after an update means you accept the revised policy.