Wordlink ← Back to the game
Your words stay yours

Privacy Policy

Wordlink is a solo and multiplayer word game for up to four players. This policy explains what information the service processes, why it is needed, how long it is kept, and the choices available to you.

Last updated: July 22, 2026

1. Scope and operator

This policy applies to the Wordlink website at wordlink-88525.web.app. Wordlink is an independently maintained project. References to “Wordlink,” “we,” or “us” mean the maintainer of this service.

Wordlink does not currently sell personal information, serve advertising, or use Google Analytics for advertising or personalization.

2. Information we process

CategoryExamplesWhen it is processed
Guest and account identifiersA Firebase user ID; if you choose to link an account, your email address, display name, profile image, authentication provider, and provider identifier.A guest identifier is created automatically. Additional details are received only when you choose Facebook, Google, or email-link sign-in.
Friends and presenceYour private unique handle, rotating friend code, accepted relationships, pending friend and live-game invitations, shared-chain completion and aggregate match counts, blocked accounts, reports, “appear offline” choice, and short-lived online, available, or playing state.Only after you create an account and choose a handle. Exact handle and friend-code lookups are processed by Cloud Functions and are not available as a public directory. Presence and saved-chain access are shared only with accepted friends. Live-game invitations contain the room code and expire with the room.
Game and room informationYour chosen player name, room membership and role, room code, timestamps, word-chain entries, guesses, match confirmations, typing presence, round settings, word-list version and next-word cursor for each language, and connection state.When you create, join, or play in a room. Your invited partner can see the information required to play the round and avoid seed words either of you has already seen.
Saved and shared chainsThe chain owner’s Firebase user ID, language, seed cursor, words, order, author identifier, timing, correction counts, created and updated dates, and Free Play chains deliberately saved for friends.Zen chains are saved automatically in the browser as you add each link. After you link an account, they are synced to Firestore and become playable by accepted friends. Free Play chains are shared only when you select the save option or enable autosave. Chain words are not sent to Google Analytics.
Dictionary and semantic processingAn eligible normalized one- or two-word guess or linked word, language, dictionary provenance and review flags, derived embeddings, hashed term and pair identifiers, similarity score, decision, model version, short-lived PingPong theme labels and highlights, and aggregate usage counts.Eligible gameplay terms are added to a permanent shared dictionary without a room code or player identifier. Words may be sent to OpenAI when semantic catches are enabled or when a player opens PingPong’s optional advanced round statistics.
StatisticsRounds and matches, streaks, aggregate guess counts, best average speed, personal PingPong return records, last-played date, and locally stored favorite-word frequencies, per-partner chemistry and best-together records, and bounded PingPong theme summaries.As you complete rounds. Aggregate statistics are synced to the cloud only after you link an account; favorite words, per-partner records, and profile theme summaries remain on this device.
Security and operationsUser agent, App Check and reCAPTCHA signals or tokens, request timestamps, authentication events, error information, and per-account rate-limit counters. Where Wordlink has configured a trusted network edge, the network address is also processed transiently into a daily rotating salted hash. Wordlink does not store the raw network address in its application database or application logs.Automatically when your browser connects to Firebase Hosting and backend services. Firebase and Google infrastructure may process the source IP under their own policies.
Optional product analyticsFunnel steps such as start, invite, play, finish, replay and share; round outcome; aggregate timing and count fields; approximate location; browser and device information; and a pseudonymous Analytics client ID.Only after you select “Accept analytics.” Names, email addresses, room codes, seed words, chain words, and guesses are not sent to Google Analytics.

Information stored in your browser

Wordlink uses local browser storage for your player name, UI and word-language choices, the versioned Free Play word-list cache and next-word cursor for each language, saved Zen chains, local statistics and partner history, analytics choice, and an email address used to complete email-link sign-in. The current Free Play room code stays in the page URL so a refresh can rejoin the same game; PingPong also keeps a short-lived room recovery record in session storage. Wordlink clears recovery data after a deliberate exit, sign-out, account switch, account deletion, or when it becomes stale. The sign-in email remains on the device until it is replaced or you clear the site’s browser data. Firebase Authentication may also use browser storage to keep you signed in.

Sharing a room or result uses your browser’s clipboard only when you press a copy or share control. Wordlink does not read unrelated clipboard contents.

3. How we use information

Where applicable law requires a legal basis, service and security processing is performed to provide the service you request and for legitimate interests in operating and protecting Wordlink. Optional Analytics processing is based on your consent, which you may withdraw at any time.

4. When information is shared

We do not sell your personal information. Information is disclosed only in these circumstances:

Firebase and the other providers may process information in the United States and other locations where they operate. Their contractual and legal transfer safeguards apply to their processing.

5. Cookies, Analytics, and reCAPTCHA

Analytics storage is denied by default. If you accept, Google Analytics uses first-party cookies such as _ga to distinguish pseudonymous browsers and sessions. Wordlink configures Analytics cookies to expire after up to 180 days, disables ad personalization and Google Signals, and sends only the site origin and path rather than room or referral query parameters.

You can change this choice from Analytics settings in the game. Declining or withdrawing consent disables further Analytics collection, prevents the Analytics script from loading in future use, and removes Wordlink’s accessible Analytics cookies from the current site.

Wordlink uses reCAPTCHA v3 through Firebase App Check to distinguish legitimate requests from abuse. reCAPTCHA may set the necessary _GRECAPTCHA cookie and process device and interaction signals for risk analysis. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

6. Retention

7. Your choices and rights

We may need to verify that you control the relevant account before acting on a request. Some requests may be limited where retaining information is required for security, fraud prevention, legal compliance, or the rights of others.

8. Account and data deletion instructions

Permanent instructions URL: https://wordlink-88525.web.app/data-deletion.html.

Registered users can delete their Wordlink account directly in the game:

  1. Sign in to the account you want to delete.
  2. Open Save your stats from the account control.
  3. Select Delete account and data and confirm.
  4. If prompted, sign in again. This recent-authentication check helps prevent someone with temporary access to an unlocked browser from deleting the account.

This deletes the Firebase Authentication account, cloud statistics, saved Zen chains, friend-chain completion scores created by or tied to the account, friend profile, handle and code reservations, friendships, requests, blocks, reports, presence, account rate-limit records, locally stored game statistics and Zen chains, sign-in email, and the account’s data in its current room. Other players’ reciprocal friendship records are also removed. If the user owns the current room, the entire room is removed; otherwise their membership, typed gameplay records, control events, and typing presence are removed. When a trusted network limiter is enabled, its short-lived rotating record cannot be tied back to or deleted for one account and expires automatically; other room data expires within 12 hours. Permanent shared dictionary, semantic-pair, and aggregate-usage records contain no player UID or room code and cannot be isolated to one account, so they are not removed automatically by account deletion. Deleting a Wordlink account does not delete the separate Facebook or Google account.

Other browser-only preferences, including the local player name, language, and Analytics choice, can be removed through the browser’s site-data controls for wordlinkapp.com, wordlink-88525.web.app, and wordlink-88525.firebaseapp.com.

If the in-app control is unavailable, do not post your email address, Firebase user ID, room code, or authentication tokens in a public GitHub issue. Open a privacy request containing only the sentence “I need a private channel for a Wordlink account deletion request.” The maintainer will arrange a non-public ownership-verification method.

9. Children’s privacy

Wordlink is a general-audience service and is not directed to children under 13. We do not knowingly request that children provide personal information. If you believe a child has provided account information, contact us so it can be reviewed and deleted as appropriate.

10. Security

Wordlink uses encrypted HTTPS connections, Firebase Authentication, App Check, access-control rules, bounded data schemas, short room retention, and rate limiting. No internet service can guarantee absolute security, so avoid entering sensitive personal information as a player name, word, or guess.

11. Changes to this policy

This policy may be updated when Wordlink’s features, providers, or legal obligations change. The revised date will appear at the top. Material changes may also be highlighted in the product where appropriate.

12. Contact

For privacy questions, contact the Wordlink maintainer through the Wordlink GitHub repository. Do not include personal information in a public issue; request a private contact channel instead.

This policy describes the service’s current implementation. Provider practices may change independently; consult the linked provider policies for their latest terms.