Privacy

Clear by design.

Aura Party games are designed to work without an account. Game progress generally stays in your browser. Information leaves your device only when a feature clearly asks you to submit it, such as sending feedback, sharing research data, or opting into basic game statistics.

What this notice covers

This notice covers the Aura Party game collection and the shared feedback and telemetry services used by participating games. Individual games may also explain a specific data choice at the point where information is requested. The collection landing page does not currently send game telemetry.

Data kept on your device

Game progress, preferences, daily-challenge history, and similar save data may be stored locally by your browser. That local data is not automatically sent to Aura Party. Clearing site data in your browser may erase it.

Data you choose to submit

When you submit feedback, the report may include:

The feedback service adds a report identifier and server timestamp. Page query strings and fragments are excluded. Please do not include passwords or other sensitive information in a report.

Optional basic game statistics

Participating games may ask whether you want to share basic game statistics. Telemetry is off unless you choose Allow statistics for that game. Saying no does not limit the game. Your choice is stored locally under a key specific to that game, is not shared with other games, and can be changed or cleared from the game's Settings.

After you allow it, the game may send only:

The telemetry payload does not include your name, contact information, page URL, browser or device details, puzzle ID, seed, difficulty, moves, duration, puzzle state, feedback text, or an identifier shared across games. Counts describe approximate game sessions, not unique people.

How submitted data is used

Reports are used to reproduce problems, improve accessibility and game design, evaluate puzzle names and difficulty, and respond when you ask for a reply. Opted-in telemetry is used only to estimate current activity and daily game-session and puzzle-completion totals. These data are not sold, used for advertising, or combined into a profile across games.

Who can access it

Submitted feedback is available only to the maintainers who operate Aura Party and to project-scoped automation used to organize and analyze reports. Access keys are separated by project and purpose so a public game cannot read stored reports. Telemetry administrators can view current and daily aggregate statistics through a Tailnet-restricted dashboard; it does not expose individual session details.

Retention and deletion

Reports are retained while they remain useful for maintaining and improving the games, or until deletion is requested. Copies may remain in routine backups until those backups rotate. There is currently no fixed automatic deletion period.

To request access to or deletion of a report, submit an Other feedback report from a participating game with “Privacy request” in the summary. Include the report identifier you received when possible. Contact information is optional unless you want a response.

Telemetry replaces the short-lived game-session ID with a project-specific HMAC before storage. Active-session hashes expire after about three minutes, temporary session rows are removed after aggregation, and completion event IDs are retained for seven days to prevent duplicate counting. Daily totals for sessions seen and puzzles completed are retained without session identifiers. Withdrawing permission stops future telemetry, but an existing aggregate cannot be connected back to you or selectively removed because the service does not retain an account or cross-game identity.

Service and network records

Aura Party does not intentionally store a stable device fingerprint with feedback reports or telemetry. Like any web request, telemetry infrastructure receives a connection address. The telemetry application uses a temporary in-memory HMAC of that address for rate limiting, but does not write the raw address to its database or application request logs. Reverse-proxy security logs may temporarily contain basic network information such as an IP address, request time, and requested path.

For game and feedback traffic analytics, IPv4 addresses are masked to /24 and IPv6 addresses to /48 before storage. Query strings, request and response headers, remote ports, cookies, authorization values, referrers, authenticated user identifiers, and raw user-agent strings are not stored. Before the user-agent header is discarded, it is classified as browser, bot, or unknown; browser traffic may also be classified as desktop, mobile, tablet, or unknown. Country and continent codes are derived locally from the masked network prefix.

Aggregate traffic metrics containing only the game or service name, these coarse categories, request counts, response-byte totals, and duration distributions may be retained for up to two years, subject to a fixed storage cap. Requests to privacy pages are excluded from these aggregate metrics. The metrics cannot be used to follow an individual request or visitor.

Last updated August 2, 2026