Privacy
Dailiverse is a daily puzzle site. It is paid for by nobody, sells nothing about you, and carries no advertising — so this notice is short, and everything in it is something the site actually does. It explains what is stored, why, on what legal basis, who else can see it, and what you can ask for.
There are no advertising or analytics trackers, no third-party scripts, no browser fingerprinting, no precise location, and no card details on our side. Nothing you do here is sold or shared with data brokers.
Who is responsible
Dailiverse is run from Hungary by an independent developer, who is the data controller for everything described below. The site is hosted in the European Union.
A published contact address for privacy requests is being set up. In the meantime, signed-in players can download or delete everything themselves from the account page.
What is stored, and why
Playing without an account. A random identifier in a cookie ties your results to your browser, and the games you play, the puzzle date, your guesses, the outcome, the score and the timestamps are stored against it. No name, no email, no account. This is what makes a streak, an archive and a statistics page possible — the legal basis is our legitimate interest in providing the game you asked to play.
With an account. An email address, a display name, an optional username, country and avatar, which authentication methods you use, and — for password accounts — a hash of your password, never the password itself. Google sign-in adds the Google account identifier, and the name, email address and picture Google returns for the openid email profile scopes. The legal basis is performance of a contract: you asked for an account, and it cannot exist without these.
Keeping the site working. Your IP address is used to limit how fast one address can create accounts, sign in or mint anonymous players. It is not stored: the rate-limit table holds only a SHA-256 hash of the key and a counter, and the rows expire. Our hosting provider keeps its own short-lived request logs, which contain IP addresses, as every web host does. Legal basis: our legitimate interest in stopping abuse.
Product events. A small set of first-party events — a page view, a game started, a guess submitted, a game finished, a share tapped — is written to our own database so we can tell whether the games work. It is never sent to a third-party analytics service. Legal basis: legitimate interest in a site that functions.
Leaderboards are off by default. A board shows nothing about you until you switch visibility on, and then it publishes only your display name or username, the number your result ranked on, and — on the streak board — your current and best streak for that game. You can switch it off again at any time in your account.
You are never required to give us any of this. Play anonymously and the only identifier involved is a random one your own browser holds.
Cookies and local storage
Every cookie here is strictly necessary — the site cannot deliver a saved game or a signed-in session without one — so there is no consent banner to click, and no cookie is used for advertising or cross-site tracking.
daily_player— the signed anonymous player identifier that restores your progress. Two years.daily_session— your sign-in session. Thirty days, and deleting it is a real sign-out: the matching row is removed on the server too.daily_oauth_state,daily_oauth_verifier— ten minutes each, only during a Google sign-in, to prove the response came back from the request you started.
All of them are HttpOnly, SameSite=Lax and sent only over HTTPS in production, so no script on any page can read them. Separately, your browser keeps a short local history of which game you opened after finishing another one, so the post-game panel can suggest something you like. It lives in localStorage, it never leaves your device, and clearing site data removes it.
Who else processes it
Only the services the site is built on, each under a data processing agreement, and none of them for their own purposes:
- Vercel — hosting. This site's functions run in Frankfurt (
fra1). - Neon — the PostgreSQL database, in AWS
eu-central-1. - Google — only if you choose Google sign-in, and only to authenticate you.
- Resend — sends the confirmation and password-reset emails, when email is enabled.
- Stripe — payments, if and when a paid plan is offered. Card details go to Stripe and never reach us.
Your data is stored in the EU. Vercel, Neon, Google, Resend and Stripe are US companies, so support and administration can involve access from outside the EEA; those transfers rely on the European Commission's Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified. We disclose data to anyone else only where the law compels it.
How long it is kept
- Account and gameplay data — for as long as the account exists. Delete the account and it goes.
- Anonymous gameplay — kept while the results are reachable, which is as long as your browser keeps its cookie. Clearing it ends the link to those rows; ask us and we will remove them.
- Sign-in sessions and email tokens — expire on their own (thirty days; reset and confirmation links, far sooner) and are then deleted.
- Rate-limit counters — hashed, and pruned by a daily job.
- Payment records — where a payment is ever taken, kept as long as tax and accounting law requires.
Deleting your account removes your profile, your sign-in methods and your private product events. Finished game results are anonymised rather than erased — severed from you, kept only as a number in the aggregate statistics for that day's puzzle, which nobody can trace back.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, have it deleted, ask us to restrict or stop a particular use, object to anything we do on the basis of legitimate interest, and take your data elsewhere in a machine-readable form.
Two of those need no request at all: the account page downloads everything we hold about you as JSON and deletes your account outright.
If you think we have got this wrong, you can complain to your national data protection authority. In Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), naih.hu; if you live elsewhere in the EEA or the UK, your own authority will do.
Children
Dailiverse is not intended for children under 13, and accounts are not knowingly created for them. In Hungary a child under 16 needs a parent's involvement for online services of this kind. There is nothing here but word and number puzzles, and we do not verify anyone's age — if you believe a child's data is here, tell us and it will be removed.
Automated decisions
None. Nothing here profiles you or makes a decision about you automatically. The game your post-game panel suggests is chosen on your own device from history that never leaves it.
Changes
If this notice changes in a way that matters, the date below changes with it, and a material change to how your data is used will be announced on the site before it takes effect.
Last updated 14 August 2026.