What is kept, and why
Last updated 22 August 2026The short version
The daily puzzle is worked out in your browser from the date, so the whole game runs without an account. Sign in and a handful of rows are kept so a streak can follow you between devices. That is the entire purpose of the data described here.
Playing without an account
No account is needed. The board, the clock, your streak and your practice results are written to this browser and stay there.
One exception, stated plainly: when you finish the daily, the app posts the result to the server without first checking whether you are signed in — the play pages are served from a CDN and the sign-in cookie is deliberately unreadable by page scripts, so the page genuinely cannot tell. If you are signed out, the server refuses that request and keeps nothing from it.
Practice works the same way, and does it far more often than once a day: every practice board you finish is posted as you finish it, blind, for exactly the same reason. Play ten practice boards signed out and ten such requests are sent. The server refuses each one and keeps nothing from any of them, the same as it does for the daily.
Who is responsible, and how to reach them
This policy covers Onsday, the site at onsday.com. For anything on this page — a copy of your data, an erasure, a correction, or a question about how any of it works — write to contact@onsday.com. That address is the controller’s contact point for privacy requests, and it is read by a person.
You can exercise the copy and erasure rights yourself, immediately, in account settings — you do not need to write to anyone first, and doing it yourself is faster. The address is there for everything the controls do not cover.
If you think this site has handled your data wrongly, you have the right to complain to your national data protection authority, and you can do that without contacting us first.
What the server keeps once you sign in
- Your email address as Google reports it, and whether Google says it is verified. It has one job: recognising which account is yours the next time you sign in. It is never displayed to anyone, and no email is ever sent to it.
- Your display name — the one name the product actually shows. It starts as the generated pseudonym below, but account settings lets you switch it to your Google name or to one you type; which of the three you are currently using is stored alongside it, so settings can show the right option selected.
- The pseudonym generated for you when the account was created — two words and a number, in the shape of SwiftHeron42. It is kept even after you switch to a different name, so switching back returns the name you started with rather than a new one.
- The name and profile-picture address Google returns with the sign-in, which the sign-in library records on the account row. Both are shown — the name as your display name, the picture on your account page — if and only if you choose your Google name in settings; otherwise neither appears anywhere in the product. They appear in your data export regardless, because they are held whether or not they are in use.
- The Google account identifier and the sign-in tokens that come with it, which are what let a session be established without asking you to sign in again.
- One row per live sign-in session: an opaque token, which account it belongs to, and when it expires. The cookie in your browser carries that token and nothing else.
- One row for every daily puzzle you solve: which game, which day in UTC, which difficulty, how long the solve took, how the row reached the server, and when it was written. At most one row per game per day. A solve you played ranked also records how many moves you made, how many hints you used, and which ranked attempt it belonged to.
- For Cascade and Open Cells specifically: the full sequence of moves behind a ranked solve, kept — not just replayed and discarded, unlike every other ranked game — so we can compute your own experimental Play Profile, shown on your account page and clearly marked provisional and not yet validated against anything beyond your own play history. It is included in your data export and removed the moment its ranked attempt is, which happens automatically when your account is erased.
- If you opt in to the Play Profile validation study: your consent, and your answers to a short questionnaire, kept separately from your gameplay data and used only to check whether the Play Profile’s measurements hold up against an established scale. Included in your data export. Withdrawing — from Settings — deletes both immediately.
- One row for every ranked attempt you start: which game, day and difficulty, the moment the server opened it, the moment your solve arrived, and what became of it. The two timestamps are the server’s own clock, because a ranked time has to be one we measured rather than one your device reported. The moves you made are replayed to check the solve and are not stored — only the count survives.
- Your current and longest streak for each game, and the last day you solved.
- Your running point total for the current season and how many ranked solves it came from. Computed once, when a ranked solve is verified, from that difficulty’s base points, how it compared to the day’s median time, and your streak — and never recomputed afterwards, so a later day’s median cannot rewrite an earlier day’s score.
- Your fastest recorded practice time and how many practice solves have reached the server, per difficulty per game. Practice stays unranked regardless of what is stored here — a board regenerates on demand, so an unlimited supply of attempts always stands behind any practice time.
- If you turn on streak reminders, one row per device you allowed them on: the browser push address the reminder is sent to, the keys that let only us deliver to it, and when you granted it — plus your time zone, so a reminder lands in your evening rather than at 4am. A notification is only ever sent with permission you granted, and never contains anyone else’s data. Your data export lists the devices by their push address; the delivery keys are left out, because they secure the channel rather than describe you. Removing the account, or turning reminders off for a device, deletes these.
- The date the account was created.
- Your current membership tier, and one row per tier you have ever chosen at /upgrade — which tier, which billing cycle, when it started, when a later choice replaced it, and the price at that moment (net, VAT, and the total), viewable as a billing history at /me/billing. No card number or payment detail is ever asked for or stored — there is no payment provider behind this yet, and choosing a tier there changes this row for real without charging anything. When a real provider exists, this section will say so and name it.
- Your Rating — one number estimating how fast you solve, shared across every game rather than kept separately per game — and how confident that estimate currently is. Computed only from ranked solves, the same ones the daily board and season ladder read, never from an ordinary daily solve. Every time it changes, the change itself is kept: the day, the game, and the number before and after. This is what lets “why is my Rating what it is” have an answer rather than only a current figure.
- Your shell layout — which panels you have moved where, and how wide you like them — as a backup copy of what is normally kept only on this device. Sent up automatically when you rearrange it while signed in, and read by nothing else: signing in on a different device shows that device’s own arrangement, never this one, so a phone never inherits a desktop’s layout.
- A photo, if you upload one in account settings — JPEG, PNG or WebP, up to 4 MB, stored with Vercel Blob and shown beside your display name. Only one file type check happens on the way in: what the file actually is, compared exactly against that short list, never against what its name or extension claims. Replacing or removing a photo deletes the previous file rather than leaving it behind, and erasing your account deletes it too, before the account row itself is removed.
- Which achievement badges you have unlocked, and when — evaluated automatically from the activity already listed here (streaks, solves, practice, season standing). Unlocking one never removes or changes anything else stored about your account.
- The last time your session was read — updated on any page load while signed in, roughly five-minute resolution, never more precise than that. It is what a friend or teammate’s online dot reads; see below for who that reaches.
What other players can see
Your display name and your time, but only for a ranked solve. The daily board shows the fastest ranked solves for today, and a row on it carries the name you have chosen, your finishing time, your position, and whether the solve claimed a hint. Anyone can read it, signed in or not.
An ordinary daily solve never appears there. Only a ranked attempt does — one you started deliberately, which the server timed from beginning to end and replayed move by move to check. If you have never played a ranked attempt, you are not on any board.
The season ladder shows your display name beside a running total — every point you have earned this season, and how many ranked solves earned it, summed across every game you rank in. It reads from the same ranked solves as the daily board, so the same rule applies: a solve the server timed and replayed, never one your device merely reported. If you have never played ranked, you have no season and no row on the ladder.
A friend can see your ranked standing even when a board would not show you. Both the daily board and the season ladder can be filtered to just the people you have added as friends, and that filtered view is not limited to the global top 100 — so a friend sees your ranked time and position on a day you placed too far down for the public board. It is the same kind of information the boards already publish, a display name beside a verified time; what a friendship adds is being seen when the global cut-off would leave you off.
You become someone’s friend by opening an invite link they chose to give you — there is no friend request to accept and, as everywhere else here, no way to look a person up by name or email. A link works once and expires after seven days. Removing a friend, from your friends page, takes that visibility away again.
Your team is treated the same way. If you are in a team, both boards can be filtered to just its members, and — like the friends view — that view is not limited to the global top 100, so a teammate sees your ranked time and position even on a day you placed too far down for the public board. You join a team by its invite link, the same as the roster and chat you already share with them; leaving the team ends this visibility.
Whoever you duel — a friend, or a stranger from the matchmaking queue — sees your time on that one board. Queuing needs no friendship and pairs you with whoever else is waiting for the same game and difficulty; either way the match shows only a display name and a time on one unranked board, nothing else. Erasing your account removes every duel, however it started.
A friend or teammate can see whether you were recently active — a dot beside your name, on or off: whether you loaded any page signed in within roughly five minutes. No live feed, and it goes stale rather than announcing when you sign off.
Your profile — pronouns, country and a short bio — is yours to share or not. You fill these in, if you want to, in account settings, and a visibility setting decides who may open your profile page: private (the default) means only you, friends means the people you have added, public means any signed-in player; a signed-out visitor is shown nothing, so a profile is never an open-web page. The only way to reach one is a link beside a name on a roster or friends list, and erasing your account removes these fields with everything else.
Nothing else about your account is visible to anyone else: not your email, not your Google name unless you chose it as your display name, not your streak, and not your practice times. There is still no way for one account to look up another.
Because that name is published beside a time and, now, a season total, which name shows is the player’s choice to make — the generated pseudonym, your Google name, or a name you type, in account settings. You can also choose to compete anonymously: you keep your rank, your times and your points, and every board shows you as “Anonymous” instead of any name.
Signing in after playing as a guest
If you played on this browser without an account and then sign in, the daily history saved here is offered to your account once: up to the last thirty solves plus the streak counters. Anything a browser reports is marked as such, and marked rows may add a day the account lacks or raise a streak, never overwrite a day already recorded — nor will they ever count towards a ranked board. A browser’s history belongs to one account only, so if somebody else signs in on the same browser nothing is offered.
A practice best time set on this browser, if faster than what your account already has, is offered the same way, per difficulty — merging can only lower a stored practice time, never raise it. How many practice solves your account has recorded is never touched by this: it is not sent by this merge, and grows only from practice played while signed in.
What stays on this device
These live in this browser’s local storage, under keys beginning game:v1:. Two things under that prefix are exceptions to “never leaves the device”: the daily history in the section above, offered to your account at sign-in, and your practice best time per difficulty. Finish a practice board while signed in and two things are sent — how long that board took, and the fact that it was solved. Your solve count itself is never sent, by this or by the merge: the server keeps its own tally of the practice solves that reached it, which is why the two numbers can differ. See “What the server keeps once you sign in” above. Everything else in this list is not, and never leaves the device:
- Unfinished daily boards — the puzzle you are part-way through, and its clock.
- The practice run in progress — its board, moves and clock.
- The difficulty you last chose, for each game.
- Your light or dark theme choice.
- Your analytics preference.
- Whether you accepted analytics cookies (PostHog) and, separately, marketing cookies (Google Analytics) — and, if you accepted analytics cookies, PostHog’s own identifier for this browser.
Clearing this site’s data in your browser removes all of it, including the daily history and this browser’s own copy of your practice statistics — the server’s copy, if you were signed in when it was set, is untouched.
Analytics
Visits are counted with Vercel Web Analytics, which is cookieless: it stores nothing on your device, and it cannot recognise you on any other site.
It is not merely a tally, and it would be an understatement to call it one. Vercel documents that each page view records which page was opened and which site referred you, alongside facts read off the request itself — country, operating system, browser and device type. Returning visits within a day are recognised through a hash Vercel computes on its own servers from the request and a salt it changes daily, so nothing is written to your device and one day’s figures cannot be joined to the next.
It runs unless you switch it off. The switch is here, and the same one is in account settings. The preference belongs to this browser rather than to an account, and it is honoured whether or not you are signed in, so you do not need one to use it.
Using it reloads the page. That is the point rather than an inconvenience: switching it off has to stop the script loading at all rather than load it and ask it to stay quiet, and a script already on a page cannot be taken back off it.
Two further, optional cookie categories go beyond a cookieless tally, and unlike Vercel Web Analytics neither runs by default: a dialog asks the first time you visit, and each runs only if you accept it. Accepting one does not accept the other — they are independent answers, and the two switches below reflect and change them separately. The same choice is also one tap away, wherever you are on the site:
PostHog — which pages and features are actually used. Keeps its identifier in this browser’s local storage rather than a cookie.
Google Analytics — the measurement this site would use for any future advertising or campaign tracking. Sets the two cookies listed below.
Both reload the page too, and for the same reason as the switch above. Declining, or never accepting, means that category’s script never loads on this browser.
Marketing email
We may occasionally send email about new games, features, or events. This is opt-in: it reaches you only if you have explicitly turned it on, and it is off until you do. You can turn it off again at any time in account settings, and doing so takes effect for every future send.
This is separate from service email — messages about your own account or the service itself, such as a security notice or a change to these terms. Those are not marketing and are sent whether or not you have opted in, because they concern the service you are using rather than anything we are promoting.
Marketing email, when sent, is delivered through Resend (see “Who else is involved”). We record that a message was sent, to how many recipients, and which audience it was aimed at — never the content of your inbox or whether you opened it.
Asking never to be emailed again
Any invite or notification email we send includes a way to ask never to receive one again — no account or sign-in required, because this needs to work for someone who was invited and has no account at all.
The request is stored as a one-way hash of the address, never the address itself, in a row with no link to any account. This is one of only two things the system keeps on purpose after you delete your account — the other is a record of any moderation action taken on or by an account, described in “Erasing your account” below. Both survive for the same reason: erasing your account cannot also erase the record that you do not want to be emailed, or the erasure itself would be the way to start receiving mail again. (A beta-access request, described in “Requesting beta access” below, is also not removed automatically — but unlike these two it is removed whenever you ask.)
The hash cannot be turned back into your address, and the row is used for exactly one thing: refusing to send. It is checked before every email this site sends — marketing and service notices and invite email alike.
Invite emails, when sent, go through Resend — see “Who else is involved”.
Requesting beta access
While Onsday is in early testing, accounts are invite-only — you can still play the daily puzzle without one. If you ask for access on the beta page, the email address you enter is stored so we can put you on the waiting list and email you an invitation once you are approved.
Unlike the “never email me again” list, this is stored as the address itself, not a hash — we need to be able to write to it, and to recognise it when you later sign in. Alongside it we keep whether the request is pending, approved, invited or declined, when it was made and decided, which staff member decided it, and an optional internal note.
This entry is keyed by your email address and is not linked to any account — you can be on the list without ever creating one. Because it is not linked to an account, it is not part of “Download your data”, which covers account rows only, and deleting an account does not remove it. To have a beta-list entry erased, write to contact@onsday.com and we will remove it.
When you sign in with Google during the beta, the email on your Google account is checked against this list — and against existing accounts — to decide whether you may sign in. The invitation email, when sent, goes through Resend and is subject to the “never email me again” list above; see “Who else is involved”.
Taking a copy of everything
“Download your data” in account settings gives you a JSON file containing everything the server holds about you: your profile, the linked Google account, every solve, every streak, and every practice best recorded on the account. Two things are left out deliberately — the sign-in and session tokens, which are secrets rather than facts about you, and anything from the device list above, which never reached the server in the first place.
Erasing your account
The delete control in account settings removes the account row and, by cascade, the linked Google account, every session, every solve, streak, practice best and notification. It is one statement, it takes effect immediately, and it cannot be undone or recovered. You are signed out as part of it. Anything still in this browser is yours to clear.
Messages you posted in a team, and direct messages you sent or received, go with the account. They are not kept, not anonymised and not replaced with a placeholder — a note saying somebody removed said something is still a record of them, and the surviving half of a conversation is exactly what erasure is for. Teammates, and anyone you messaged, see gaps.
One thing survives it. If a moderator has ever taken action on an account, or if the account belongs to someone who moderates, the record of what was done and why is kept — with the account identifier still on it, which after erasure points at nothing. Everything else about the account is gone. This record is not used to contact anyone or to rebuild a profile; it exists so a decision can be reviewed, appealed and answered for. A moderation log that the subject of the decision can erase is not a record of anything, and neither is one a moderator can erase.
A second thing survives it, only for a banned account. Deleting a banned account keeps a one-way hash of the Google account identity it was signed in with — never the identity itself, never anything else about the account — so signing in with that same Google account again is refused rather than starting fresh. This is what stops a ban from being undone by deleting and rejoining; an account in good standing that is deleted keeps nothing at all. The hash cannot be reversed into a Google account, is checked for exactly one thing, and is never used to contact anyone.
Your display name is your choice, changeable at any time in account settings — the generated pseudonym, your Google name, or one you type. Switching back to the generated name returns the one you started with, not a new one.
How long it is kept
Server rows are kept until the account is erased — solves, streaks and practice bests have no automatic expiry. A streak needs to carry forward indefinitely to mean anything; solves and practice bests are kept for as long, with no separate rule that clears them sooner. A sign-in session lapses after twenty-four hours without a visit, and signing out ends it at once. What is on this device lasts until you clear it.
Who else is involved
- Google — sign-in only. Google tells this site who you are; this site tells Google nothing about your play.
- Neon — the hosted PostgreSQL database the rows above live in.
- Vercel — hosting, delivery, the analytics described above, and Blob storage for a profile photo if you upload one. Serving a page necessarily means Vercel handles the connection it arrives on, including your IP address.
- Resend — delivers team-invite email and, once approved, marketing email. It sees the recipient’s address, the message text, and nothing else about your account or your play.
- PostHog — usage analytics, and only if you accept analytics cookies in the banner described in Analytics above. Not used for advertising.
- Google Analytics — the measurement this site would use for any future advertising or campaign tracking, and only if you accept marketing cookies in the same banner, independently of the PostHog answer.
That is the whole list. Nothing is sold, and nothing is shared with advertisers or data brokers.
If any of this changes, the date at the top changes with it.