Privacy Policy
Last updated: April 10, 2026
1. What We Collect
Protocol: Crisis Hex ("the Game") collects the following data:
- Email address— provided when you create an account. Used for authentication only.
- Anonymous browser identifier— an identifier generated by your browser using FingerprintJS (open-source edition). We may use this identifier to help recognize anonymous visitors, support abuse prevention, and associate a stable device snapshot with the current browser.
- Technical browser and device information— such as IP address, device type, language, and time zone. Used for service analytics, abuse prevention, and product improvement.
- Gameplay data and statistics— such as solve time, hint usage, wrong attempts, and completion data. Used to power gameplay features, personal stats, and service analysis.
2. How We Use Your Data
- Authentication — to let you sign in and access your account.
- Abuse prevention — to rate-limit requests, detect unusual traffic, and protect the Game from automated abuse.
- Game experience — to show your personal statistics and streaks.
- Service analytics and improvement — to understand how the Game is used across device types and improve reliability.
- Debugging and reliability — to trace individual requests in server logs when investigating errors.
We do not use your data for advertising, profiling, or tracking across websites.
3. Third-Party Services
- Supabase— hosts our database and handles authentication. Your email, gameplay data, and limited device metadata are stored in Supabase's infrastructure. Supabase Privacy Policy
- FingerprintJS (open-source)— runs entirely in your browser. No data is sent to FingerprintJS servers by this library itself.
4. Cookies & Local Storage
We do not use cookies for tracking. Authentication tokens are stored in your browser's localStorage and are used solely to keep you signed in.
We also store limited local data to preserve gameplay state and to avoid repeatedly registering the same device snapshot when nothing has changed.
5. Data Retention
Your account data and gameplay statistics are retained as long as your account exists. We may also retain limited technical device metadata and anonymous identifiers for abuse prevention, analytics, and service operations.
6. Your Rights
You may at any time:
- Request a copy of your personal data.
- Request deletion of your account and all associated data.
To exercise these rights, email us at privacy@crisishex.com.
7. Children's Privacy
The Game is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
8. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Game after changes constitutes acceptance.
9. Contact
Questions about this policy? Reach us at privacy@crisishex.com.