Privacy Policy
Last updated
This is a plain-English template. It should be reviewed by a legal professional before you rely on it.
Chrono-Shift is a daily history timeline puzzle run by Chrono-Shift ("we", "us"). This policy explains what we collect when you play, why we collect it and what you can do about it. We keep it short because we collect very little.
Who is responsible for your data
Chrono-Shift is the controller of the personal data described here. You can reach us at [contact email].
What we collect
If you create an account
- Your name and email address.
- Your password, which is stored only as a one-way hash. We can never see it.
- Whether and when you verified your email address.
- Your game results: which daily puzzles you played, your guesses, whether you solved them and how long you took. We use these for your streak and stats.
- If you subscribe to Chrono-Shift+, your Stripe customer ID and the status of your subscription. We never see or store your card details (see "Payments" below).
When you play, with or without an account
- A visitor log of puzzle visits: which puzzle was opened, your attempts, whether you finished, and when. For guests the visit is linked to an anonymous random token created by your browser. We store only a hash of that token, never the token itself.
- Your results in the Eras and Higher or Lower modes, linked to your account or, for guests, to the anonymous player cookie described below.
- Your IP address, which we use briefly to limit how often one network can submit answers or log in, to protect the game from abuse. Our session store also records your IP address and browser type next to your session until it expires.
Cookies and local storage
We only use cookies and storage that the game needs to work. We do not use advertising or tracking cookies, and we do not sell your data.
- Session cookie: keeps you logged in and remembers your session while you browse.
- CSRF cookie (
XSRF-TOKEN): a security token that protects forms from being submitted by other websites. chrono_player: for guests, an anonymous random ID so your Eras and Higher or Lower games survive a page reload. It lasts up to two years.chrono_level: remembers the difficulty you last picked.- Local storage in your browser: your daily game progress and stats, the anonymous player token used for the visitor log, whether you have seen the how-to-play guide, and your theme (light or dark) and motion preferences. This stays on your device; clearing your browser data removes it.
Analytics
To see how many people visit and which pages are useful, the site measures page views itself. It uses no third-party analytics scripts, sets no extra cookies, and nothing is sent to anyone else. For each page you view we record:
- the page address (the path only, without any query string) and which part of the site it belongs to;
- the website that linked you here, reduced to its domain name (for example
google.com), and only if it is another site; - your screen size class: mobile, tablet or desktop;
- how many seconds the page was visible on your screen (time in a background tab is not counted);
- whether this is your first visit, and the date and time;
- a visitor ID: a one-way hash of the anonymous player token kept in your browser's local storage, or your account ID if you are logged in.
We do not store your IP address or your browser's user agent with these records. To opt out, turn on Do Not Track or Global Privacy Control in your browser; when either is on, no page views are sent at all.
Why we use your data
- To run the game and your account: saving your results, streaks and stats, and letting you log in. This is necessary to provide the service you asked for (contract).
- To take payments for Chrono-Shift+ through Stripe (contract).
- To send account emails, such as email verification and password resets (contract).
- To keep the game fair and secure, including rate limiting and spotting abuse (our legitimate interests).
- To understand how the puzzles are played, using the visitor log to see how many people open and finish each puzzle (our legitimate interests).
- To meet legal duties, such as keeping payment records for tax (legal obligation).
Who we share it with
- Stripe handles all payments. When you subscribe, you enter your card details on Stripe's checkout page, not ours, and Stripe processes them under its own privacy policy. We never store card numbers.
- Our email provider delivers account emails such as verification links and password resets, so it receives your email address.
- Our hosting provider stores the database and runs the site on our behalf.
- Anyone we are legally required to share data with, such as a court or regulator.
Some of these providers may process data outside your country. Where that happens, we rely on appropriate safeguards such as standard contractual clauses.
How long we keep it
- Account data and game results: until you delete your account.
- Sessions: until they expire, usually within a few hours of inactivity.
- Visitor log entries: as long as they are useful for puzzle statistics. If you delete your account, they are detached from it.
- Payment records: as long as tax and accounting law requires, which Stripe also keeps.
Deleting your account
You can delete your account at any time under Settings. This permanently deletes your account and saved game results and cancels any active subscription. Visitor log and arcade entries are detached from your account and kept only as anonymous statistics. Data you keep in your browser's local storage stays on your device until you clear it.
Children
Accounts are for people aged 13 and over. Younger players are welcome to play as guests, which needs no personal details. If you believe a child under 13 has created an account, contact us and we will delete it.
Your rights (UK and EU GDPR)
If you are in the UK, the EU or the EEA, you have the right to:
- access the personal data we hold about you;
- correct data that is wrong (you can change your name and email in Settings);
- delete your data (you can delete your account in Settings);
- restrict or object to how we use your data, including uses based on our legitimate interests;
- port your data, receiving it in a common, machine-readable format.
To use any of these rights, email us. We will reply within one month. You can also complain to your local data protection authority, such as the Information Commissioner's Office (ICO) in the UK, though we would appreciate the chance to help first.
California residents (CCPA)
If you live in California, you have the right to know what personal information we collect and how we use it, to ask us to delete it, to correct it, and not to be treated differently for using these rights. We do not sell or share your personal information for cross-context behavioural advertising. The categories we collect are identifiers (name, email, anonymous IDs), commercial information (subscription status) and internet activity (game play and puzzle visits), for the purposes described above.
Security
We use HTTPS, hash passwords and anonymous tokens, and limit who can access the database. No system is perfectly secure, so please use a strong, unique password.
Changes to this policy
If we change this policy, we will update the date at the top. For significant changes we will let account holders know by email or on the site.
Contact
Questions about privacy? Email [contact email]. See also our Terms of Service and Refund Policy.