Privacy Policy
Wordlink is a solo and multiplayer word game for up to four players. This policy explains what information the service processes, why it is needed, how long it is kept, and the choices available to you.
1. Scope and operator
This policy applies to the Wordlink website at wordlink-88525.web.app. Wordlink is an independently maintained project. References to “Wordlink,” “we,” or “us” mean the maintainer of this service.
Wordlink does not currently sell personal information, serve advertising, or use Google Analytics for advertising or personalization.
2. Information we process
| Category | Examples | When it is processed |
|---|---|---|
| Guest and account identifiers | A Firebase user ID; if you choose to link an account, your email address, display name, profile image, authentication provider, and provider identifier. | A guest identifier is created automatically. Additional details are received only when you choose Facebook, Google, or email-link sign-in. |
| Friends and presence | Your private unique handle, rotating friend code, accepted relationships, pending friend and live-game invitations, shared-chain completion and aggregate match counts, blocked accounts, reports, “appear offline” choice, and short-lived online, available, or playing state. | Only after you create an account and choose a handle. Exact handle and friend-code lookups are processed by Cloud Functions and are not available as a public directory. Presence and saved-chain access are shared only with accepted friends. Live-game invitations contain the room code and expire with the room. |
| Game and room information | Your chosen player name, room membership and role, room code, timestamps, word-chain entries, guesses, match confirmations, typing presence, round settings, word-list version and next-word cursor for each language, and connection state. | When you create, join, or play in a room. Your invited partner can see the information required to play the round and avoid seed words either of you has already seen. |
| Saved and shared chains | The chain owner’s Firebase user ID, language, seed cursor, words, order, author identifier, timing, correction counts, created and updated dates, and Free Play chains deliberately saved for friends. | Zen chains are saved automatically in the browser as you add each link. After you link an account, they are synced to Firestore and become playable by accepted friends. Free Play chains are shared only when you select the save option or enable autosave. Chain words are not sent to Google Analytics. |
| Dictionary and semantic processing | An eligible normalized one- or two-word guess or linked word, language, dictionary provenance and review flags, derived embeddings, hashed term and pair identifiers, similarity score, decision, model version, short-lived PingPong theme labels and highlights, and aggregate usage counts. | Eligible gameplay terms are added to a permanent shared dictionary without a room code or player identifier. Words may be sent to OpenAI when semantic catches are enabled or when a player opens PingPong’s optional advanced round statistics. |
| Statistics | Rounds and matches, streaks, aggregate guess counts, best average speed, personal PingPong return records, last-played date, and locally stored favorite-word frequencies, per-partner chemistry and best-together records, and bounded PingPong theme summaries. | As you complete rounds. Aggregate statistics are synced to the cloud only after you link an account; favorite words, per-partner records, and profile theme summaries remain on this device. |
| Security and operations | User agent, App Check and reCAPTCHA signals or tokens, request timestamps, authentication events, error information, and per-account rate-limit counters. Where Wordlink has configured a trusted network edge, the network address is also processed transiently into a daily rotating salted hash. Wordlink does not store the raw network address in its application database or application logs. | Automatically when your browser connects to Firebase Hosting and backend services. Firebase and Google infrastructure may process the source IP under their own policies. |
| Optional product analytics | Funnel steps such as start, invite, play, finish, replay and share; round outcome; aggregate timing and count fields; approximate location; browser and device information; and a pseudonymous Analytics client ID. | Only after you select “Accept analytics.” Names, email addresses, room codes, seed words, chain words, and guesses are not sent to Google Analytics. |
Information stored in your browser
Wordlink uses local browser storage for your player name, UI and word-language choices, the versioned Free Play word-list cache and next-word cursor for each language, saved Zen chains, local statistics and partner history, analytics choice, and an email address used to complete email-link sign-in. The current Free Play room code stays in the page URL so a refresh can rejoin the same game; PingPong also keeps a short-lived room recovery record in session storage. Wordlink clears recovery data after a deliberate exit, sign-out, account switch, account deletion, or when it becomes stale. The sign-in email remains on the device until it is replaced or you clear the site’s browser data. Firebase Authentication may also use browser storage to keep you signed in.
Sharing a room or result uses your browser’s clipboard only when you press a copy or share control. Wordlink does not read unrelated clipboard contents.
3. How we use information
- Provide guest sessions, rooms, multiplayer synchronization, Free Play words, results, saved Zen chains, and optional cross-device statistics.
- Build a reusable multilingual dictionary from normalized gameplay terms, while keeping player-observed terms ineligible for Free Play seeds unless separately reviewed.
- Compare eligible non-identical word pairs through the shared semantic dictionary, return a consistent match decision, and reuse cached decisions to reduce repeat processing.
- When requested, compare the completed PingPong round’s semantic patterns and generate short theme labels shared with both room players.
- Authenticate users and link a guest session to a provider selected by the user.
- Enforce security rules, detect automated abuse, apply hourly usage limits, diagnose errors, and protect service availability.
- Remember local preferences and statistics on the device.
- With consent, understand the anonymous start-to-finish product funnel and improve the game.
- Comply with applicable law and protect users, the service, and the rights of others.
Where applicable law requires a legal basis, service and security processing is performed to provide the service you request and for legitimate interests in operating and protecting Wordlink. Optional Analytics processing is based on your consent, which you may withdraw at any time.
6. Retention
- Room data: rooms, word/guess messages, and shared PingPong advanced-stat reports expire after 12 hours and are removed by an hourly cleanup process.
- Dictionary and semantic scoring: eligible normalized terms, their hashes, provenance and review flags, and any derived vectors are retained as a permanent shared dictionary. Hashed pair identifiers, scores, version metadata, and override audit history are also retained so repeated pairs stay consistent. Dictionary and pair records contain no player UID or room code, but normalized terms can still contain personal information a player chose to type and are not treated as anonymous.
- Typing presence: removed after inactivity or disconnection.
- Rate-limit records: general hourly per-account counters, and network counters when a trusted network edge is enabled, are retained for up to about three hours after their hourly window starts. Friend-request per-account counters, and their network counterparts when enabled, are retained through the end of their UTC day plus two days (up to about three days), then removed by scheduled cleanup. Wordlink does not store raw network addresses in these records.
- Free Play word list: the canonical versioned language list is a public static game asset and contains no player identifiers.
- Guest authentication: anonymous Firebase accounts more than 30 days old are eligible for automatic deletion. Firebase may retain authentication security logs, including IP addresses, for its own shorter operational periods.
- Linked accounts and cloud statistics: retained until the account is deleted or a valid deletion request is completed, subject to limited backup, security, fraud-prevention, and legal retention.
- Deletion safety markers: while account deletion is running, Wordlink keeps a server-only marker containing the Firebase user ID and, when supplied, the current room code, creation time, and mode. After the Authentication account is deleted, the marker remains for at least two hours so already-issued sign-in tokens cannot recreate data, then scheduled cleanup removes it. If the completion update is interrupted, cleanup first confirms that the Authentication account no longer exists; a marker for an existing account remains until deletion is safely retried.
- Saved Zen chains: linked-account copies are retained until the owning account is deleted. Guest chains stay only in the browser and are removed when you clear the site’s browser data. A friend-chain completion and its aggregate score remain until the player’s account or the chain owner’s account is deleted.
- Friends: profiles, relationships, blocks, and pending friend requests are retained until removed or the account is deleted. Live-game invitations expire with their room, within 12 hours. Online presence is short lived and removed on disconnect. Friend and room-invite abuse counters expire automatically.
- Local browser data: retained until you clear it, the browser removes it, or you use a different browser profile.
- Analytics: retained according to the configured Google Analytics retention settings and Google’s policies. Analytics cookies on the device are configured for up to 180 days.
7. Your choices and rights
- Play without linking Facebook, Google, or an email address.
- Decline optional Analytics or change your choice later through Analytics settings.
- Clear locally stored names, preferences, word-list progress, statistics, and authentication state through your browser’s site-data controls.
- Manage Wordlink’s connection from your Facebook or Google account settings. Revoking provider access does not by itself delete the separate Firebase account or already stored Wordlink statistics.
- Request access, correction, deletion, restriction, or a portable copy where required by applicable law.
- Object to certain processing or withdraw consent without affecting processing that occurred before withdrawal.
- Complain to the privacy or data-protection authority in your jurisdiction.
We may need to verify that you control the relevant account before acting on a request. Some requests may be limited where retaining information is required for security, fraud prevention, legal compliance, or the rights of others.
8. Account and data deletion instructions
Permanent instructions URL: https://wordlink-88525.web.app/data-deletion.html.
Registered users can delete their Wordlink account directly in the game:
- Sign in to the account you want to delete.
- Open Save your stats from the account control.
- Select Delete account and data and confirm.
- If prompted, sign in again. This recent-authentication check helps prevent someone with temporary access to an unlocked browser from deleting the account.
This deletes the Firebase Authentication account, cloud statistics, saved Zen chains, friend-chain completion scores created by or tied to the account, friend profile, handle and code reservations, friendships, requests, blocks, reports, presence, account rate-limit records, locally stored game statistics and Zen chains, sign-in email, and the account’s data in its current room. Other players’ reciprocal friendship records are also removed. If the user owns the current room, the entire room is removed; otherwise their membership, typed gameplay records, control events, and typing presence are removed. When a trusted network limiter is enabled, its short-lived rotating record cannot be tied back to or deleted for one account and expires automatically; other room data expires within 12 hours. Permanent shared dictionary, semantic-pair, and aggregate-usage records contain no player UID or room code and cannot be isolated to one account, so they are not removed automatically by account deletion. Deleting a Wordlink account does not delete the separate Facebook or Google account.
Other browser-only preferences, including the local player name, language, and Analytics choice, can be removed through the browser’s site-data controls for wordlinkapp.com, wordlink-88525.web.app, and wordlink-88525.firebaseapp.com.
9. Children’s privacy
Wordlink is a general-audience service and is not directed to children under 13. We do not knowingly request that children provide personal information. If you believe a child has provided account information, contact us so it can be reviewed and deleted as appropriate.
10. Security
Wordlink uses encrypted HTTPS connections, Firebase Authentication, App Check, access-control rules, bounded data schemas, short room retention, and rate limiting. No internet service can guarantee absolute security, so avoid entering sensitive personal information as a player name, word, or guess.
11. Changes to this policy
This policy may be updated when Wordlink’s features, providers, or legal obligations change. The revised date will appear at the top. Material changes may also be highlighted in the product where appropriate.
12. Contact
For privacy questions, contact the Wordlink maintainer through the Wordlink GitHub repository. Do not include personal information in a public issue; request a private contact channel instead.
This policy describes the service’s current implementation. Provider practices may change independently; consult the linked provider policies for their latest terms.