Last updated: February 17, 2026
Introduction
Today's Word Is ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use our word game service. You can play with or without an account; creating an account is optional and allows us to save your game history and show you your stats and ranking.
Information We Collect
Information You Provide (Optional Account)
If you choose to create an account, we collect:
- Email address: Used to identify your account and to send you a password reset link if you request one.
- Password: Stored in a hashed form only; we cannot see your actual password.
- Game results linked to your account: For each game you complete while logged in (or that we attach when you sign up), we store the date, whether you won or lost, how many guesses you used, and (for wins) how many nudges you used. We use this to show you your stats (e.g. streaks, averages) and to compute your ranking against other players.
We do not share your account or game data with third parties for their marketing or any other purpose. We do not sell your information.
We will not bombard you with emails. We may occasionally send you messages (for example to let you know about updates to the game or other game-related news). You can expect these to be infrequent. Transactional emails, such as password reset links, are sent only when you request them.
You can use the game without an account. If you do not sign up, we do not collect your email or link your gameplay to you personally.
Automatically Collected Information
When you use our service, we automatically collect the following:
- Session ID: An anonymous, randomly generated identifier stored locally in your browser to track your game session. If you are not logged in, this is not linked to your personal identity.
- Timezone: Your browser's timezone setting (e.g. "America/New_York") to determine which daily word puzzle you see. This is automatically provided by your browser and does not reveal your exact location.
- Game activity (anonymous): When you play, we record events such as games played, won, or lost; guess counts; invalid word guesses (the words themselves, not who guessed them). If you are logged in, we also link these to your account for your stats and ranking.
- Share interactions: If you share your results, we track anonymous statistics about share clicks, visits to shared pages, and conversions (when someone plays after clicking a share).
- Page views: When you visit the homepage, we record an anonymous page view event.
Information We Do NOT Collect
- Your name or phone number (unless you choose to provide them elsewhere)
- Precise location data (GPS coordinates, street address)
- IP addresses (we do not log or store IP addresses)
- Browsing history or activity on other websites
How We Use Your Information
We use the collected information for the following purposes:
- Game functionality: To provide you with the correct daily word puzzle based on your timezone
- Your account and stats: If you have an account, to keep you logged in, to store your game results, and to show you your stats (e.g. streaks, averages) and your ranking against other players. We only show your ranking percentile once a minimum number of players have joined.
- Password reset: If you request a password reset, we use your email address to send you a secure reset link via our email provider
- Analytics: To understand how users interact with the game, improve the user experience, and identify technical issues
- Statistics: To generate aggregate statistics about game performance (e.g. win rates, average guesses). Ranked players are included in these calculations; we do not sell or share your personal data
- Word validation: Invalid word guesses are checked against a dictionary API to improve word validation
We do not use your information for advertising, marketing, or selling to third parties.
Data Storage and Security
Local Storage (Your Browser)
We use your browser's local storage to:
- Store your session ID (anonymous identifier)
- Save your game progress locally so you can continue playing if you refresh the page
- Temporarily queue analytics events in IndexedDB before sending them to our server (for reliability)
- Remember which daily puzzles you've already seen
All local storage data remains on your device and can be cleared at any time through your browser settings.
Server Storage
Data is stored on our servers (hosted by Netlify). We use:
- Analytics storage: Anonymous session IDs, timezone, game events (plays, wins, losses), invalid word guesses (for dictionary validation), and share interaction statistics. This data is used for analytics and does not identify you unless you have an account and we have linked some events to it.
- Account and game results (Postgres): If you have an account, we store your email address, a hashed version of your password, and your game results (date, outcome, guess count, nudge count) so we can show you your stats and ranking. This data is held for as long as your account exists.
We do not sell or share your personal data with third parties for their own purposes.
Third-Party Services
We use the following third-party services:
Dictionary API (dictionaryapi.dev)
When you enter a word that isn't in our local word list, we check it against a public dictionary API to verify if it's a valid word. The word you entered is sent to this service, but no other information about you is shared.
Netlify (Hosting and Storage)
Our service is hosted on Netlify. Analytics data and account data (including your email and game results) are stored using Netlify's infrastructure (e.g. Postgres). Netlify's privacy policy applies to their handling of infrastructure. We do not share your data with Netlify for their own purposes.
Resend (Email)
If you request a password reset, we send the reset link by email using Resend. Your email address is shared with Resend only for that purpose. Resend's privacy policy applies to their processing of that data.
Cookies and Tracking Technologies
We use:
- Session cookie: If you log in, we set a secure, HTTP-only cookie so we can keep you logged in. This cookie does not contain your password or email; it only identifies your session. You can log out at any time to clear it.
- localStorage: To store your anonymous session ID and game state locally in your browser
- IndexedDB: To temporarily queue analytics events before sending them to our server
- sessionStorage: For temporary data (e.g. when signing up after a game, so we can attach that game to your new account). Also used by the analytics editor (admin access).
We do not use cookies or storage for advertising or cross-site tracking. You can clear cookies and local storage at any time through your browser settings; logging out will remove the session cookie.
Data Sharing and Disclosure
We do not sell, trade, or rent your information to third parties. We may show aggregated statistics (e.g. "You're in the top X% of players") which use your game results for ranking but do not expose your identity to other users. We share your email address only with our email provider (Resend) when sending you a password reset link.
We may disclose data when required by law or to protect our rights.
Your Rights and Choices
You have the following rights regarding your data:
- Use without an account: You can play without signing up. We will not collect your email or link your gameplay to you personally.
- Log out: You can log out at any time from the stats card. This clears your session cookie; we will no longer treat your browser as logged in.
- Clear local data: You can clear cookies and local storage at any time through your browser settings. This will reset your anonymous session and local game state.
- Account deletion: If you have an account and want your email and game data deleted, please contact us. We will remove your account and associated data.
- No advertising tracking: We do not use your data for advertising or cross-site tracking.
Children's Privacy
Our service is suitable for all ages. We do not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction). If you are under 13, please do not create an account without a parent or guardian's consent. You can still play without an account; we will not collect your email or link your gameplay to you.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates when changes were last made. Your continued use of the service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us through the appropriate channels for this service.
This privacy policy is designed to be transparent about what we collect. We only collect what is necessary to provide the game, optional account and stats, and to improve the experience. You can play without an account and we will not collect your email or link your gameplay to you.