AniGauntlet
Privacy notice
Last updated
Ayr Software LLC operates AniGauntlet from New Jersey, United States. This notice describes information we handle when you visit, play, join the launch waitlist, support the project, or contact us. It also covers optional player accounts. Every game plays without one. The temporary access gate is separate from gameplay.
Browser storage and puzzle completions
We use browser storage to remember preferences, game selections, progress, cached statistics, and a randomly generated browser identifier. The identifier persists between visits and is not your name or email address.
When you make a first guess on a daily puzzle, your browser sends that identifier and the puzzle identifier to our server. When you finish the puzzle or reveal its answer, it also sends the result and your guess count. The server hashes the browser identifier with a private server-side value and stores the resulting identifier with the record and its time. The database holds the hash, rather than the original identifier. We use these records to count each browser once per puzzle, calculate community statistics, and see how many players start, finish, or give up on each puzzle. They are pseudonymous, not necessarily anonymous, and can link records from the same browser.
Other game requests send information needed to provide a puzzle or evaluate a guess, such as puzzle and selected-answer identifiers. Our infrastructure also receives network information needed to deliver the service.
Clearing AniGauntlet's browser storage removes local progress and preferences. It may create a new browser identifier on your next visit. It does not delete information already held on our servers.
An earlier version stored a Terms acceptance date and version in your browser. We no longer read or write that record. Any existing record remains only in that browser until you or your browser clear it.
Player accounts
Accounts are optional. You can sign in with Google, with Discord, or with a passkey you added. We never receive or store a password, and we do not keep the access tokens Google or Discord issue. Sign-in methods whose verified email addresses match can join the same account without a separate step. For Gmail addresses we ignore dots and anything after a plus sign, and treat googlemail.com as gmail.com. An account holds:
- Your email address. If you sign in with Google or Discord, we also keep that service's ID for you and the name and picture it shares. Your Google name stays private. An account created with Discord starts with a shortened, screened version of your Discord name, or a random name if that one is refused. You can change it. If you show your Discord picture, we ask Discord for its current version regularly, about once a day, so it stays up to date.
- After your first sign-in, we ask you to confirm that you are 13 or older and to accept the Terms before the account saves progress or offers friends. We keep the version you accepted and when.
- Your profile: display name, optional username, picture, ring, title, a line about yourself, up to six favourite characters, the world whose art heads your profile page, how that page lays out your favourites and which of its sections show, and whether your profile is hidden.
- What the account keeps in step across your devices: preferences, playlists, lineups, your streak, the daily puzzles you finished with the guess count and result, achievements, the characters in your collection, and recent game boards, finished or not, including your guesses and revealed hints. When you sign in on a device holding guest progress, that progress joins the account. Progress that belongs to another account is replaced with yours instead.
- Friends and friend requests, and the pokes, stickers, room invites and score alerts friends send you, which appear in your Activity list.
- For each signed-in device, a session with the IP address and browser description it signed in from and when it was last used. If you add a passkey, we store its public key, credential ID, name, and details about the authenticator and its use. Your fingerprint or face never leaves your device.
- Your placement in multiplayer rooms you finish while signed in, as your device reports it.
- Reports you make about another player's name or picture, including any note you write, reports about yours, and our moderation decisions.
We use this to run your account, show your profile and friends, send the notifications you turn on, prevent abuse, and answer you. We use your email to sign you in, to match Ko-fi support to your account, and to reply to you. We do not send marketing to it. Cookies keep you signed in. Combining two profiles uses a cookie and a server record that expire after 15 minutes, and a record of the finished combine that lets an interrupted request finish within a day. Expired records stay on the server until a later combine clears them.
Friends and people who see your friend requests see your display name, username, picture, ring, title, and any Supporter badge. If you pick a username, your profile page at its link also shows your line about yourself, banner, streak, puzzles solved, achievements, room record, collection and favourite characters, apart from any of those sections you hide. We ask search engines not to index it. Anyone with the link can open it unless you hide your profile, which limits it to friends. Friends can also see your current streak, how many puzzles you solved and your total guesses today and over the last seven puzzle days, and your result on a given puzzle, including its guess count or that you gave up. They never see your guesses. In multiplayer rooms, other players see your room nickname and mascot. The nickname starts from your account, and so does the mascot if your account picture is one. Other players never see your email address.
An uploaded picture is re-encoded as a small square image, which removes location and camera data, and stored under a random name on our public media domain. Anyone with its address can view it. Cloudflare scans images on that domain for known child sexual abuse material, and we report such material as the law requires. A Google or Discord picture loads straight from that service, so when you view one, the service receives your browser's request for it. We don't send it the page you are on.
Push notifications are off until you turn them on for a device. Your browser then gives us a delivery address at its push service (Apple, Google or Mozilla, depending on the browser) and keys to encrypt messages to it. We keep those with your notification choices, the device's sign-in, and when we last sent one, and we send streak reminders and friend activity through it. Signing out of that device ends them.
If you link Discord, our bot may give your Discord account the player role in the AniGauntlet Discord server. When you unlink Discord or delete the account, we ask Discord to remove the role; this can fail if Discord is unavailable. Running the bot's /streak command posts your display name, streak, today's solves and profile link in that channel; if your profile is hidden, only you see it. In any Discord server that uses the AniGauntlet bot, members can show your profile card with /card (picture, name, title, streak, solves, collection and your first three favourite characters), and the server can give you a role for a 7- or 30-day streak. A hidden profile gets neither. When someone supports us on Ko-fi, Ko-fi sends us the email they paid with. We keep that email with the first and last support dates so an account at the same address, matched as above, shows a Supporter badge and can use the supporter lobby themes. Everyone in a lobby sees the theme a player picks. If you paid with another address, you can link it in your account: we send a code there, then keep that address with your account until you remove it or delete the account. We can also mark an account as a supporter ourselves, for example for people who helped test the site; it shows the same badge.
A browser remembers up to three accounts that signed out of it, with a display name, mascot, sign-in methods, partly hidden email, and which of them you said belong to someone else. It uses them to offer combining two profiles that belong to the same person, so other people using that browser can see those suggestions. They stop appearing after 30 days and stay in browser storage until it is cleared or they are replaced.
Access cookies and security
If you enter an access password while the gate is enabled, we set an access cookie lasting up to 30 days to remember that this browser has passed the gate. We use IP addresses and action timestamps to limit excessive requests. For waitlist signups, we also limit repeated submissions of the same email address. Rate-limit database keys can contain IP addresses or email addresses. Hosting and security providers also process request information and diagnostic logs to operate and protect the service.
Waitlist, correspondence, and support payments
The launch waitlist collects your email address, signup time, and any referral source submitted with the signup. We use these to maintain the list, prevent abuse, and send the launch notification you requested. This signup does not subscribe you to sponsor marketing. Ask us to remove you at support@anigauntlet.com.
When you contact us, we receive the information you include and use it to respond and maintain relevant correspondence. Our support address uses Cloudflare Email Routing to forward messages to a Google Gmail inbox. Rights reports may be shared with advisers, service providers, or affected contributors when needed to investigate or respond.
If you follow our Ko-fi support link, Ko-fi and its payment providers handle the information you give them under their own notices. Information made available to us can include your supporter name, email, message, and transaction details, depending on what you provide and the payment method. We use information we receive to administer support payments, answer payment questions, and keep required business records. Do not send us full payment-card details.
Usage and performance measurement
We count how the site is used in our own database, as totals. The puzzle records above tell us how many browsers started, finished, or gave up on each daily puzzle and how many guesses finishers needed. For multiplayer lobbies, our room server counts lobbies created, runs started, the number of players at the start, the games each run reached, and whether a run finished. Those lobby counts hold no room code, player name, browser identifier, or guess. The launch gate counts page views per day without any visitor identifier. We do not load a third-party analytics script or set analytics cookies.
Providers and other disclosures
Our providers include Vercel for hosting, Supabase for data storage, Cloudflare for delivery, multiplayer rooms, and email routing, and Google for support email. Cloudflare also stores uploaded pictures, Google and Discord sign you in when you choose them, and your browser's push service delivers notifications you turn on. They process information to provide their services. Information may be processed in the United States and other countries where our providers operate, subject to applicable law.
We may disclose information when required by law or reasonably necessary to address fraud, security threats, legal claims, or harm to the service or others. A business transfer remains subject to applicable law and required notice. External sites, including Ko-fi and social platforms, have their own practices when you visit them.
The current website does not run advertising-network tags or offer premium player accounts. We will update this notice and provide the disclosures and choices required by law before introducing new uses of information.
How long information stays
- Browser identifiers and preferences have no automatic expiry. They remain until you or your browser clear them. Game sessions and caches may be removed separately.
- The access cookie lasts up to 30 days unless removed sooner.
- Rate-limit events older than one day are removed by an hourly job, so one can last up to 25 hours. This does not delete provider logs or backups.
- Puzzle start, finish, and forfeit records are removed by the same hourly job once their puzzle is more than 30 days old. They prevent duplicate counting and let us correct statistics. The per-puzzle totals they add to hold no identifier and are kept as history, as are lobby and gate totals.
- Nightly database backups are kept for about 30 days. Our storage provider deletes the off-site copies on its own schedule, which can add a few days, so a removed record can remain in a backup for a little over a month. Our backup of uploaded pictures keeps a deleted or replaced picture for 30 days after the nightly backup first sees the change.
- Waitlist entries currently have no automatic expiry. We keep them while preparing and delivering the requested launch notification, unless you ask for removal sooner. After that purpose ends, we remove the list unless another lawful reason requires retention.
- We keep relevant support and rights correspondence while handling the request and as needed for related disputes or legal obligations. Transaction records may need to be kept for accounting and tax requirements.
- Account information stays until you delete the account. Deleting it removes the account's profile, sign-ins, devices, passkeys, saved progress, collection, friends, notifications and room placements. We also ask our storage to delete an uploaded picture; if that fails, or a cache still holds it, the file can stay reachable for a while, and our backup keeps it for about a month. Games and settings on the device you delete from stay in that browser until you clear them, and can join a later account. Reports about your account are removed; reports you made lose their link to you, but any note you wrote stays while the reported account exists. Ko-fi supporter records are separate and stay. A device's sign-in ends after 60 days without use or when you sign it out. A daily cleanup removes friend notifications older than 30 days. Game boards not updated for two days are removed the next time your account syncs. Supporter records and moderation decisions have no automatic expiry.
- Provider logs, analytics, and backups follow the relevant provider settings and retention practices. Copies may remain in backups until those backups expire, subject to applicable deletion requirements.
Your choices and requests
You can clear local storage, choose not to join the waitlist, and email us with a privacy request. Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, object to or restrict processing, and complain to a privacy regulator. We handle applicable requests within the periods required by law. If we deny a request, you can reply to ask for reconsideration and we will explain any further appeal rights that apply.
If you have an account, you can edit your profile, hide it, sign out other devices, download your profile, settings, playlists, puzzle history, game boards, achievements, friends and the reports you made as one file, and delete the account at any time from your account settings. Email us for anything the download leaves out.
We may need limited information to verify your request. We do not normally link completion records to an email address. Contact us before clearing your browser identifier if you want help locating those records. We will explain any verification needed privately; do not post your identifier publicly. Once the identifier is lost, we may be unable to locate or verify which completion records are yours.
Children
Our Terms require players to be at least 13, with a parent or legal guardian's agreement and supervision if below the age of legal majority. Do not submit an email or other personal information if you are under 13. A first sign-in creates the account, but it saves no game progress and offers no friends until its player confirms being 13 or older. If you believe a child has provided information that should not have been collected, contact us so we can investigate and take the steps required by applicable law.
Updates
We will update this notice when our practices change and show the date above. We will provide additional notice and obtain consent where required by law. Agreeing to the Terms is not consent to optional advertising or marketing.
Contact
For support, privacy requests, payment questions, or rights concerns, email support@anigauntlet.com. Please do not send passwords, full payment details, or unnecessary sensitive information.