LEGAL / PRIVACY
Privacy Policy
Effective September 9, 2026 · Version 4
In plain language
You can play Nerds Wordle without an account. Anonymous game progress stays in your browser. If you choose to sign in, your progress can be synced so it follows you across devices.
Information we handle
- Anonymous play: submitted puzzle state, preferences, and statistics are stored locally on your device. Letters typed before submission stay only in the open page and are discarded on refresh.
- Signed-in play: Clerk provides a stable user ID and authentication status. Validated puzzle progress and sync timestamps are stored in Neon Postgres.
- Verified play: The optional verified API temporarily stores submitted guesses, canonical tile results, hint usage, completion state, and a random session identifier in Neon. Session tokens are stored only as one-way hashes. Expired sessions are removed by scheduled maintenance.
- Abuse prevention: When distributed rate limiting is enabled, a keyed one-way hash of the network address supplied by the hosting layer is stored briefly with a request counter. Raw IP addresses are not placed in the rate-limit table.
- Analytics: PostHog receives events such as page navigation, mode selection, submitted game actions, completion, sharing, sync health, performance, and errors. Successful guess and hint actions are counted by the server even when browser analytics are blocked. Signed-in gameplay events use the Clerk user ID for unique-player metrics; anonymous gameplay actions are aggregate-only and receive no persistent analytics identifier.
The application does not copy Clerk profile fields into analytics events. PostHog’s Clerk connector may synchronize user, organization, membership, and invitation records directly from Clerk. Authorized administrators can view Clerk names and usernames joined to aggregate gameplay activity in the private admin report. We do not send typed drafts, guess text, puzzle answers, hint text, synced progress, credentials, or IP addresses as PostHog event properties. Replay capture masks inputs and excludes the game board, results, and Clerk account interface.
Services we use
Clerk provides authentication, including optional Rocket.Chat and email/password sign-in. Neon stores signed-in progress, short-lived verified sessions, and rate-limit counters. PostHog provides privacy-limited product analytics. Vercel hosts and delivers the application and may temporarily queue analytics events for reliable delivery. Each provider may process technical information under its own privacy terms.
Offline play and local storage
The app uses browser storage and a service worker so anonymous Daily games can continue offline. Eligible actions may be queued on your device and retried after you reconnect. Clearing browser data removes local progress and queued actions.
Control and deletion
You may play anonymously, clear browser storage at any time, or delete synced game data from the account page. Deleting your account also triggers removal of its synced progress. Some short-lived operational logs or backups may remain until they expire.
Changes
We may update this policy as the game changes. Material updates will be reflected by a new effective date or version on this page.