Privacy Policy
Last updated: 2026-09-28
GregSweeper is a free browser-based puzzle game made by Christopher Wells. This page explains what data the game stores, how it is used, who else can see it, and how to delete it.
What we collect
- Anonymous device ID. A random identifier issued by Firebase Anonymous Auth when you first load the game. It links your plays together so streaks, handicaps, and personal history work. On its own it is not tied to any real-world identity.
- A Google account or email address, only if you choose to sign in. Signing in is how you take your progress to another device. If you sign in with Google, Firebase Authentication stores details from your Google account, including its identifier, your name, and your email address; with an email link, it stores the email address you had the sign-in link sent to. Either way, these are attached to the anonymous ID above.
- Optional display name. If you put a name on a leaderboard it is shown publicly, and it is also stored in a public name list so other players see it beside your times. Use a handle, not your real name.
- Completion times and per-game telemetry. When you finish a daily, weekly, or Challenge board, the game submits your time, any mine strikes and where on the board they happened, and the board's feature counts. This feeds the par-time model that scores your future runs.
- Repeat attempts at the weekly board. The weekly allows one attempt a day on the same board. Each attempt after the first records how long since your previous one and how many other boards you played in between, for a study of how quickly people forget a board. These rows are not used to score you.
- Progress synced to your account. Streaks, checkpoints, power-ups, insurance days, weekly completions, and your daily history are written to the database under your anonymous ID, so they survive a reinstall and reach your other devices when you sign in. If you first opened the game from a poster or flyer link, the short tag on that link (such as
poster1) is stored with the account created on that visit, once and never changed afterwards, so we can count the new accounts from each link. The first such tag a device is given is also kept on that device. The tag is cleared from the device when you use Delete my data in Settings; if your account is removed any other way, the next account created on that device is given the tag kept there. - Which Challenge boards you have already played. The game keeps a list of the boards it has dealt you, so it can deal you fresh ones instead of repeating itself. The list stores each board's identifier and the time you first met it, never how you played it. A count of the boards you have finished is kept beside it, per device, under a random ID created in this browser, so the counts from your devices can be added together.
- Multiplayer data, if you play a Challenge run with someone. A match record contains each player's name, per-board times, and a timestamp refreshed while you are actively playing so opponents can see who is at the board right now. Invitations you send or receive are stored under the recipient's account. Friend codes and your friend list are stored under yours.
- Push token and chosen reminder hour. Only if you opt in via Settings. The token is managed by Firebase Cloud Messaging and is required to deliver the notification you asked for.
- Local play state. Theme choice, in-progress games, seen-message flags, and display preferences are stored in your browser's
localStorageand stay on your device. - Error reports. If the game hits an error it writes a diagnostic record under your anonymous ID, readable only by you and the game owner.
- Standard server-side logs. Firebase records your IP address and user agent when the game contacts its servers. Google retains these for approximately 30 days under their own policies.
How it's used
- To render leaderboards and, in a Challenge run, to show opponents the standings.
- To fit the par-time model nightly, so each board can be given a predicted time and each player a handicap. Individual times enter the fit; the published model is the aggregate.
- To draw one population map: a past daily shaded by where players hit mines. It is built only from strike coordinates, and it stays hidden until at least 30 people have finished that board, so no cell can be traced to one person.
- To send the reminder you requested, if any.
- To investigate crashes you trigger.
We do not sell your data, use it for advertising, or share it for purposes outside running the game.
What other players can see
- Your display name and times appear on the leaderboards you submit to, and the name list is public.
- In a Challenge run, everyone in that run sees your name, your time on each board, and whether you are at the board right now. Anyone signed in who has the run's code can read the run.
- Your anonymous ID is not shown to other players anywhere in the game.
- Nothing else is public. Your progress, streaks, history, settings, friends, and error reports are readable only by you and the game owner.
Who we share with
- Google / Firebase. Hosting (Realtime Database), authentication, push delivery (Firebase Cloud Messaging), and access logs. See Google's privacy policy at policies.google.com/privacy.
- Google reCAPTCHA Enterprise. To keep automated traffic from draining the database, every request is accompanied by a token from Firebase App Check, which uses reCAPTCHA Enterprise. It runs in your browser and assesses whether the request comes from a real browser rather than a script. Google receives the signals it uses to make that judgment, including your IP address.
- Google Fonts. Two web fonts (Orbitron, Fredoka) are loaded from
fonts.gstatic.com, so Google sees your IP when you load the game. - GitHub Pages. The game's static files are served from GitHub Pages. GitHub may log your IP for abuse prevention; see GitHub's privacy statement at docs.github.com/site-policy.
No analytics services, tracking pixels, or advertising networks are loaded.
Why we are allowed to hold it
For players in the UK and EU, the lawful basis under GDPR is as follows. Everything needed to run a game you asked to play, meaning your anonymous ID, your times, your progress, and a Challenge run you joined, is processed to perform that service. Notifications and signing in rest on your consent, given when you opt in. You can withdraw it for notifications by turning them off. For signing in, you withdraw it by deleting your data, and with it the whole account; if you only sign out, the sign-in details stay on the account. Keeping automated traffic off the database, which is what reCAPTCHA Enterprise does, rests on legitimate interest in keeping the game affordable to run and available to real players.
The database and the servers are Google's and are located in the United States, so using the game involves an international transfer of the data described above.
Children
GregSweeper is not directed at children under 13, and we do not knowingly collect their information. If you are a parent or guardian and believe a child under 13 has played and left data here, email the address below and it will be removed; the same request from a child themselves is honored the same way.
Your rights and deletion
You can see your anonymous device ID, start over with a new one, and have your account erased.
- Delete my data, from inside the game. You can remove your account with a control in Settings, without emailing anyone or waiting on a person. Your profile, progress, entry in the public name list, and local data are deleted immediately. Within a day, the sweep described below deletes your anonymous ID from Firebase Authentication, along with any Google account details or email address you signed in with. If your account holds a link tag, the tag is kept until that sweep, which counts it for its link and then deletes it. The same sweep anonymizes your past times, taking your name off the leaderboards. Your completion times themselves stay, with the link to you removed; the Retention section below says exactly what that means.
- See your anonymous ID: open Settings, or load
?debug=1for diagnostics. - Get a new anonymous ID: you get one automatically when you delete your data, so anything you play afterwards belongs to a new account. To change ID without deleting anything, clear your browser's site data for this domain (Settings → Privacy & security in Chrome, or Develop → Empty Caches in Safari). You get a fresh ID on next load. Nothing is deleted that way, so use the delete control above first if you want the old records gone.
- By email: christopher.wells.23@gmail.com, with your anonymous device ID. Requests are handled within 30 days.
EU and California residents have additional rights under GDPR and CCPA, including access, correction, and portability. Those are honored through the same email contact. We do not sell personal information as CCPA defines it.
Retention
Your account is swept automatically if you have not opened the game for 24 months, or if you ask for it to be removed. If no play, leaderboard name, friend, or reminder is recorded on it, it is swept sooner, once two days have passed since you last opened the game. Play is recorded when you finish the daily, start the weekly or a Challenge board, or win a level of the Climb. Sweeping means the same thing in all three cases:
- Your identity is deleted. Your anonymous ID is deleted from Firebase Authentication, along with any Google account details or email address you signed in with. The profile, the display name, the public name entry, the error log, and your friend list are deleted, and so is every copy of you held elsewhere: your entry in other players' friend lists, any invitation you sent, and any friend code you still had open. A name left on a Challenge record is dropped.
- Your times stay, detached. Completion times are still used to fit the par model, with your anonymous ID replaced by a single shared marker used for every removed account. Nothing in a remaining row distinguishes one removed player from another. The exception is Challenge runs: in the record of every run you played, your results stay under your old anonymous ID, with your name removed, so the other players' standings are unchanged.
- Poster totals stay. If a poster or flyer tag was stored with your account, that link's count of accounts still includes yours, as one number per link.
Two things run on their own clocks. Firebase access logs are retained about 30 days under Google's policy. Your push token is removed the moment you turn notifications off.
Contact
Data controller: Christopher Wells, christopher.wells.23@gmail.com.
If we change this policy materially, the "Last updated" date above is bumped and the change is summarized in the in-game "What's New" modal.
Monetization disclosure
GregSweeper is currently free to play in your browser, with no ads, no tracking pixels, and no paid features. We may add voluntary donations (e.g. GitHub Sponsors, Buy Me a Coffee) and may eventually ship a paid native app wrapper on app stores while the browser version stays free. We will never sell your data or run third-party ad scripts. Any monetization change is summarized in the in-game "What's New" modal before it ships.