Back to today
Privacy

What is kept, and why

Last updated 22 August 2026

The short version

The daily puzzle is worked out in your browser from the date, so the whole game runs without an account. Sign in and a handful of rows are kept so a streak can follow you between devices. That is the entire purpose of the data described here.

Playing without an account

No account is needed. The board, the clock, your streak and your practice results are written to this browser and stay there.

One exception, stated plainly: when you finish the daily, the app posts the result to the server without first checking whether you are signed in — the play pages are served from a CDN and the sign-in cookie is deliberately unreadable by page scripts, so the page genuinely cannot tell. If you are signed out, the server refuses that request and keeps nothing from it.

Practice works the same way, and does it far more often than once a day: every practice board you finish is posted as you finish it, blind, for exactly the same reason. Play ten practice boards signed out and ten such requests are sent. The server refuses each one and keeps nothing from any of them, the same as it does for the daily.

Who is responsible, and how to reach them

This policy covers Onsday, the site at onsday.com. For anything on this page — a copy of your data, an erasure, a correction, or a question about how any of it works — write to contact@onsday.com. That address is the controller’s contact point for privacy requests, and it is read by a person.

You can exercise the copy and erasure rights yourself, immediately, in account settings — you do not need to write to anyone first, and doing it yourself is faster. The address is there for everything the controls do not cover.

If you think this site has handled your data wrongly, you have the right to complain to your national data protection authority, and you can do that without contacting us first.

What the server keeps once you sign in

What other players can see

Your display name and your time, but only for a ranked solve. The daily board shows the fastest ranked solves for today, and a row on it carries the name you have chosen, your finishing time, your position, and whether the solve claimed a hint. Anyone can read it, signed in or not.

An ordinary daily solve never appears there. Only a ranked attempt does — one you started deliberately, which the server timed from beginning to end and replayed move by move to check. If you have never played a ranked attempt, you are not on any board.

The season ladder shows your display name beside a running total — every point you have earned this season, and how many ranked solves earned it, summed across every game you rank in. It reads from the same ranked solves as the daily board, so the same rule applies: a solve the server timed and replayed, never one your device merely reported. If you have never played ranked, you have no season and no row on the ladder.

A friend can see your ranked standing even when a board would not show you. Both the daily board and the season ladder can be filtered to just the people you have added as friends, and that filtered view is not limited to the global top 100 — so a friend sees your ranked time and position on a day you placed too far down for the public board. It is the same kind of information the boards already publish, a display name beside a verified time; what a friendship adds is being seen when the global cut-off would leave you off.

You become someone’s friend by opening an invite link they chose to give you — there is no friend request to accept and, as everywhere else here, no way to look a person up by name or email. A link works once and expires after seven days. Removing a friend, from your friends page, takes that visibility away again.

Your team is treated the same way. If you are in a team, both boards can be filtered to just its members, and — like the friends view — that view is not limited to the global top 100, so a teammate sees your ranked time and position even on a day you placed too far down for the public board. You join a team by its invite link, the same as the roster and chat you already share with them; leaving the team ends this visibility.

Whoever you duel — a friend, or a stranger from the matchmaking queue — sees your time on that one board. Queuing needs no friendship and pairs you with whoever else is waiting for the same game and difficulty; either way the match shows only a display name and a time on one unranked board, nothing else. Erasing your account removes every duel, however it started.

A friend or teammate can see whether you were recently active — a dot beside your name, on or off: whether you loaded any page signed in within roughly five minutes. No live feed, and it goes stale rather than announcing when you sign off.

Your profile — pronouns, country and a short bio — is yours to share or not. You fill these in, if you want to, in account settings, and a visibility setting decides who may open your profile page: private (the default) means only you, friends means the people you have added, public means any signed-in player; a signed-out visitor is shown nothing, so a profile is never an open-web page. The only way to reach one is a link beside a name on a roster or friends list, and erasing your account removes these fields with everything else.

Nothing else about your account is visible to anyone else: not your email, not your Google name unless you chose it as your display name, not your streak, and not your practice times. There is still no way for one account to look up another.

Because that name is published beside a time and, now, a season total, which name shows is the player’s choice to make — the generated pseudonym, your Google name, or a name you type, in account settings. You can also choose to compete anonymously: you keep your rank, your times and your points, and every board shows you as “Anonymous” instead of any name.

Signing in after playing as a guest

If you played on this browser without an account and then sign in, the daily history saved here is offered to your account once: up to the last thirty solves plus the streak counters. Anything a browser reports is marked as such, and marked rows may add a day the account lacks or raise a streak, never overwrite a day already recorded — nor will they ever count towards a ranked board. A browser’s history belongs to one account only, so if somebody else signs in on the same browser nothing is offered.

A practice best time set on this browser, if faster than what your account already has, is offered the same way, per difficulty — merging can only lower a stored practice time, never raise it. How many practice solves your account has recorded is never touched by this: it is not sent by this merge, and grows only from practice played while signed in.

What stays on this device

These live in this browser’s local storage, under keys beginning game:v1:. Two things under that prefix are exceptions to “never leaves the device”: the daily history in the section above, offered to your account at sign-in, and your practice best time per difficulty. Finish a practice board while signed in and two things are sent — how long that board took, and the fact that it was solved. Your solve count itself is never sent, by this or by the merge: the server keeps its own tally of the practice solves that reached it, which is why the two numbers can differ. See “What the server keeps once you sign in” above. Everything else in this list is not, and never leaves the device:

Clearing this site’s data in your browser removes all of it, including the daily history and this browser’s own copy of your practice statistics — the server’s copy, if you were signed in when it was set, is untouched.

Analytics

Visits are counted with Vercel Web Analytics, which is cookieless: it stores nothing on your device, and it cannot recognise you on any other site.

It is not merely a tally, and it would be an understatement to call it one. Vercel documents that each page view records which page was opened and which site referred you, alongside facts read off the request itself — country, operating system, browser and device type. Returning visits within a day are recognised through a hash Vercel computes on its own servers from the request and a salt it changes daily, so nothing is written to your device and one day’s figures cannot be joined to the next.

It runs unless you switch it off. The switch is here, and the same one is in account settings. The preference belongs to this browser rather than to an account, and it is honoured whether or not you are signed in, so you do not need one to use it.

Analytics

Using it reloads the page. That is the point rather than an inconvenience: switching it off has to stop the script loading at all rather than load it and ask it to stay quiet, and a script already on a page cannot be taken back off it.

Two further, optional cookie categories go beyond a cookieless tally, and unlike Vercel Web Analytics neither runs by default: a dialog asks the first time you visit, and each runs only if you accept it. Accepting one does not accept the other — they are independent answers, and the two switches below reflect and change them separately. The same choice is also one tap away, wherever you are on the site:

Analytics cookies

PostHog — which pages and features are actually used. Keeps its identifier in this browser’s local storage rather than a cookie.

Marketing cookies

Google Analytics — the measurement this site would use for any future advertising or campaign tracking. Sets the two cookies listed below.

Both reload the page too, and for the same reason as the switch above. Declining, or never accepting, means that category’s script never loads on this browser.

Marketing email

We may occasionally send email about new games, features, or events. This is opt-in: it reaches you only if you have explicitly turned it on, and it is off until you do. You can turn it off again at any time in account settings, and doing so takes effect for every future send.

This is separate from service email — messages about your own account or the service itself, such as a security notice or a change to these terms. Those are not marketing and are sent whether or not you have opted in, because they concern the service you are using rather than anything we are promoting.

Marketing email, when sent, is delivered through Resend (see “Who else is involved”). We record that a message was sent, to how many recipients, and which audience it was aimed at — never the content of your inbox or whether you opened it.

Asking never to be emailed again

Any invite or notification email we send includes a way to ask never to receive one again — no account or sign-in required, because this needs to work for someone who was invited and has no account at all.

The request is stored as a one-way hash of the address, never the address itself, in a row with no link to any account. This is one of only two things the system keeps on purpose after you delete your account — the other is a record of any moderation action taken on or by an account, described in “Erasing your account” below. Both survive for the same reason: erasing your account cannot also erase the record that you do not want to be emailed, or the erasure itself would be the way to start receiving mail again. (A beta-access request, described in “Requesting beta access” below, is also not removed automatically — but unlike these two it is removed whenever you ask.)

The hash cannot be turned back into your address, and the row is used for exactly one thing: refusing to send. It is checked before every email this site sends — marketing and service notices and invite email alike.

Invite emails, when sent, go through Resend — see “Who else is involved”.

Requesting beta access

While Onsday is in early testing, accounts are invite-only — you can still play the daily puzzle without one. If you ask for access on the beta page, the email address you enter is stored so we can put you on the waiting list and email you an invitation once you are approved.

Unlike the “never email me again” list, this is stored as the address itself, not a hash — we need to be able to write to it, and to recognise it when you later sign in. Alongside it we keep whether the request is pending, approved, invited or declined, when it was made and decided, which staff member decided it, and an optional internal note.

This entry is keyed by your email address and is not linked to any account — you can be on the list without ever creating one. Because it is not linked to an account, it is not part of “Download your data”, which covers account rows only, and deleting an account does not remove it. To have a beta-list entry erased, write to contact@onsday.com and we will remove it.

When you sign in with Google during the beta, the email on your Google account is checked against this list — and against existing accounts — to decide whether you may sign in. The invitation email, when sent, goes through Resend and is subject to the “never email me again” list above; see “Who else is involved”.

Cookies

A visitor who never goes near sign-in, and never accepts marketing cookies in the dialog, is given none at all. Signing in involves four, and every one of them is strictly necessary to sign you in or to protect the sign-in from abuse; all four are unreadable by page scripts and are sent only to this site.

On the live site the first three reach you with a __Host- or __Secure- prefix, which is a browser-enforced restriction on how they may be sent.

Two more are set only if you accept marketing cookies in the cookie dialog, and only by Google Analytics — accepting analytics cookies (PostHog) sets no cookie at all, because PostHog is configured to keep its identifier in this browser’s local storage instead.

Declining, or never answering, marketing cookies in the cookie dialog means neither is ever set. Withdrawing consent afterwards in the switch above stops new events but does not itself delete a cookie already on your device — clearing this site’s data in your browser does.

Taking a copy of everything

“Download your data” in account settings gives you a JSON file containing everything the server holds about you: your profile, the linked Google account, every solve, every streak, and every practice best recorded on the account. Two things are left out deliberately — the sign-in and session tokens, which are secrets rather than facts about you, and anything from the device list above, which never reached the server in the first place.

Erasing your account

The delete control in account settings removes the account row and, by cascade, the linked Google account, every session, every solve, streak, practice best and notification. It is one statement, it takes effect immediately, and it cannot be undone or recovered. You are signed out as part of it. Anything still in this browser is yours to clear.

Messages you posted in a team, and direct messages you sent or received, go with the account. They are not kept, not anonymised and not replaced with a placeholder — a note saying somebody removed said something is still a record of them, and the surviving half of a conversation is exactly what erasure is for. Teammates, and anyone you messaged, see gaps.

One thing survives it. If a moderator has ever taken action on an account, or if the account belongs to someone who moderates, the record of what was done and why is kept — with the account identifier still on it, which after erasure points at nothing. Everything else about the account is gone. This record is not used to contact anyone or to rebuild a profile; it exists so a decision can be reviewed, appealed and answered for. A moderation log that the subject of the decision can erase is not a record of anything, and neither is one a moderator can erase.

A second thing survives it, only for a banned account. Deleting a banned account keeps a one-way hash of the Google account identity it was signed in with — never the identity itself, never anything else about the account — so signing in with that same Google account again is refused rather than starting fresh. This is what stops a ban from being undone by deleting and rejoining; an account in good standing that is deleted keeps nothing at all. The hash cannot be reversed into a Google account, is checked for exactly one thing, and is never used to contact anyone.

Your display name is your choice, changeable at any time in account settings — the generated pseudonym, your Google name, or one you type. Switching back to the generated name returns the one you started with, not a new one.

How long it is kept

Server rows are kept until the account is erased — solves, streaks and practice bests have no automatic expiry. A streak needs to carry forward indefinitely to mean anything; solves and practice bests are kept for as long, with no separate rule that clears them sooner. A sign-in session lapses after twenty-four hours without a visit, and signing out ends it at once. What is on this device lasts until you clear it.

Who else is involved

That is the whole list. Nothing is sold, and nothing is shared with advertisers or data brokers.

If any of this changes, the date at the top changes with it.