Play without an account
Current deals, settings, favorites, recently played games, and personal game statistics may be stored in your browser. The site also creates a random installation identifier so records created on one device can be merged consistently. It is not your name or an advertising identifier. The browser also keeps the last signed-in Firebase user ID—not an email address or display name—so a directly opened game can select the correct local account partition while sign-in status loads. Your Analytics choice is stored separately so the site can remember it. You can remove this browser information with your browser’s site-data controls. A storage or network failure does not prevent a new game from starting.
Personal statistics can include the game and rules versions, result, start and end times, local date and time zone, active play duration, move count, hints, undos, redos, and game-specific progress metrics. A Daily Challenge attempt also records its challenge identifier, schedule and scoring versions, UTC date, and normalized final progress so the same historical result can appear on another signed-in device without being recalculated under newer scoring rules. Post-round coach move history is kept only in memory for the current page and is not added to local player records or cloud sync. A current-deal save contains the serialized card state needed to restore that deal, in-progress timing and action counters, and limited attempt lineage used to keep an ended or replaced deal from reappearing on another device. Favorites and recent-play records contain the game, installation identifier, and change or play time. This player data is not public.
Optional accounts
You may create an optional account with an email address and password or sign in with Google. Firebase Authentication processes the account’s unique user ID, email address, email-verification status, sign-in provider, account creation and sign-in metadata, and security information such as network address and user agent. For password accounts, Firebase processes the password; it is not written to the site’s local player-data records or Cloud Firestore. Google sign-in can provide Firebase with basic profile information such as your email address, name, profile image, and provider-specific identifier. The site does not copy a display name or profile image into its player-data database.
Firebase may send the account verification and password-reset messages you request. The current account feature does not use your sign-in email for newsletters or marketing.
Firebase Authentication stores session information in your browser so you can remain signed in. Google describes Firebase Authentication’s processing and retention in its Firebase privacy and security documentation. Google sign-in is also subject to the Google Privacy Policy.
If Google account deletion must continue through a redirect, the site temporarily stores the matching Firebase user ID and request time in session storage. That one-time deletion intent is removed when the redirect finishes, fails, or becomes stale; it contains no email address or game history.
Private cloud synchronization
When you sign in with an account eligible for synchronization, supported statistics, favorite changes, recent games, and current-deal saves are copied to private Cloud Firestore collections under your Firebase user ID. Email verification is required before cloud synchronization begins and before the client can create or update records. While verification is pending, a signed-in account whose user ID matches the player-data path can still read or delete its existing records, including during account deletion. It cannot access another account’s records. Authorized project operators and Google’s service processors may still access data when needed to operate, secure, or comply with legal obligations for the service; this is not end-to-end encrypted storage.
Guest data is not silently attached to an account. After either creating or signing in to an account, the site shows a separate one-time import choice when this browser has guest history that has not been added to that account. A merge keeps distinct completed attempts and favorite changes, selects the newest recent-play record, and preserves current deals while honoring records that mark a deal ended or replaced. Your guest and account-specific browser records remain separate unless you approve that import.
Deletion and retention
Local completed-attempt records remain until you clear the applicable browser data. Local saves and recent-play records remain until they are replaced or deleted, and favorite-change records remain until local data is cleared. Synced player data remains while the account exists unless a feature lets you replace or delete a record sooner. There is no separate application archive or sale of this data.
Account deletion first writes a browser deletion-protection marker and creates a small Firestore deletion guard, then removes the account’s active Cloud Firestore player documents and requests deletion of the Firebase Authentication user. The browser marker uses the Firebase user ID in its storage key and contains only a pending/deleted state and change time. It blocks old tabs from recreating account data. After successful deletion, its deleted state remains until browser site data is cleared. If deletion stops partway through, the pending state remains until you retry or explicitly resume the account after its cloud guard is gone. The cloud guard uses the Firebase user ID as its document key and stores only creation and expiration timestamps. It prevents a previously issued sign-in token from recreating player data during deletion. It expires about two hours after the request and is scheduled for automatic removal by Firestore TTL; Google says expired documents are typically deleted within 24 hours after expiration. Firebase can require you to sign in again before this security-sensitive action. The site reports a failed or incomplete deletion rather than claiming it succeeded. After deletion is confirmed, the site clears the account-specific browser player-data partition, or reports if browser storage prevents that local cleanup. Unrelated guest data remains unless you clear it with your browser’s site-data controls. See Google’s Firestore TTL documentation.
Google states that Firebase Authentication keeps logged network addresses for a few weeks and, after the associated user is deleted, removes other authentication information from live and backup systems within 180 days. Cloud Firestore, Hosting, and security-log copies may follow separate Google-managed operational retention periods, so deletion does not imply that every processor backup or security record disappears immediately. See the linked Firebase privacy documentation for the current processor details.
Necessary service processing
Account and synchronization requests use Firebase Authentication and Cloud Firestore because those services are needed to provide the optional account feature you request. Hosting also processes request metadata to deliver and protect the site. These necessary-service operations are separate from optional Analytics: changing Privacy choices does not sign you out, delete player data, or prevent account synchronization, and signing in does not enable Analytics. The site does not send account user IDs, email addresses, saved card state, or personal statistics as custom Analytics properties.
Measurement
For visitors outside regions where we apply prior-consent rules, the site enables Firebase Analytics automatically unless you have previously declined it. You can use Privacy choices in the footer to turn Analytics off or on at any time.
For visitors in the European Economic Area, United Kingdom, Switzerland, and certain related European and overseas jurisdictions, Analytics remains off until you choose Allow analytics in the privacy banner. Before that choice, the site does not load the Firebase Analytics SDK or send Analytics requests or consent-mode pings. Declining is as easy as allowing, and either choice can be changed later through Privacy choices in the footer. If the regional policy cannot be determined, the site uses this consent-first behavior.
Firebase Hosting returns a small same-site policy response selected from the request’s country. The application receives only whether prior Analytics consent is required, not the country value. Firebase Hosting still processes the network address as described under Hosting and security logs below.
When enabled, Firebase Analytics can collect coarse page categories, session activity, Core Web Vital timing values, limited runtime error categories, a pseudonymous browser identifier, approximate location derived from your network address, device and browser information, and game events such as starting, moving, undoing, or finishing. Our custom events use fixed page categories, allowlisted canonical page URLs and titles, and either a same-site canonical referrer or an external referrer’s origin. They do not add names, email addresses, card contents, deal seeds, full move histories, URL query strings or fragments, external referrer paths, error messages, or stack traces.
When Analytics is enabled, Firebase can also create core measurement events such as first visit, session start, and user engagement. Those events receive the same query-free page location, controlled title, and sanitized referrer. Enhanced Measurement interactions are disabled in the production Analytics stream. Google Signals, advertising storage, ad-user-data collection, ad personalization, and personalization storage remain disabled or denied. Analytics is not used for advertising. Google describes these default data categories in its Analytics data-collection documentation.
Hosting and security logs
Firebase Hosting and Google process request metadata whenever the site is requested. That operational and security processing is separate from Analytics and is not controlled by your Privacy choices. If CDN request logging is enabled for this project, Google Cloud Logging can retain the requested URL—including any query string sent by the browser— network address, referrer, user agent, response status, and latency under the project’s Google-managed retention settings. Avoid putting personal information in a URL. The site does not create links containing deal seeds or card state, but hosting logs can contain whatever a browser sends in a request URL.
Advertising and sales
The current site has no advertising, subscriptions, or store. Before Google publisher advertising is introduced, the site will adopt a reviewed, Google-certified consent management platform where required, including for visitors in the European Economic Area, United Kingdom, and Switzerland. The current analytics-only choice will not be treated as consent to advertising. Player data is not sold.
Questions
Until a dedicated privacy address is published, you can reach the project owner through the project owner’s GitHub profile.