This policy explains what information the Crossly web app collects, why, and what choices you have. It is written to be read, not just posted — if any part is unclear, contact us using the details at the end and we'll clarify or fix the wording.
Crossly is developed and operated by Prateek Gaur, an individual developer ("we", "us"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and similar laws, we are the data controller for the information described below.
Contact for any privacy question or request: [email protected]
Crossly is a general-audience crossword puzzle game. It is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
When you share the app or challenge a friend, Crossly builds a link that encodes your display name, a puzzle identifier, and your time — entirely in your browser. That link is never sent to or stored on any server we operate; it is decoded directly by whoever opens it. We have no record of who you challenged or who accepted.
The web app uses the following third-party services, each of which processes some data on our behalf or in its own right as described in their policies:
| Service | Purpose | What it may collect |
|---|---|---|
| Google Firebase Analytics | Understand feature usage and app performance (screen views, puzzle completions, settings changes, ad interactions) | Pseudonymous analytics identifiers, browser/OS type, coarse (city/region-level) location inferred from IP, app version, event data listed above |
| Google Firebase Remote Config | Deliver configuration values (feature toggles, ad settings) without a new deployment | A pseudonymous app-instance identifier used to resolve the config; no content you type is sent |
| Google AdSense | Serve advertising that funds free access to Crossly | Advertising cookies/local identifiers, browsing context, and (unless you've opted out per §6) data used to personalize ads |
Each provider is bound by its own privacy policy for how it independently processes data: Firebase Privacy & Security, Google Ads & AdSense, and Google's overall Privacy Policy.
We do not sell your personal information, and we do not use it for any purpose beyond the ones listed on this page.
Google AdSense may use cookies or similar local storage to show ads and measure their performance, and may personalize ads based on your activity unless you opt out. You can:
Data stored locally in your browser (progress, settings, install identifier) persists until you clear your browser's site data. Analytics and advertising data are retained by Google per their own retention schedules, which we do not control.
We do not sell personal information. We share data only with the service providers listed in §3.4, to the extent necessary for them to provide analytics and advertising services, or where required by law, to protect our legal rights, or to investigate fraud or abuse of the service.
Our third-party providers (Google) operate global infrastructure, which means data may be processed in countries other than your own, including the United States. Google maintains its own safeguards (including EU Standard Contractual Clauses where applicable) for these transfers.
You have the right to access, correct, delete, restrict, or port your personal data, and to object to its processing. Because Crossly stores gameplay data locally and keeps almost no data on our own servers, most of these rights are exercised simply by clearing your browser's site data. For anything held by our analytics/advertising providers, contact us and we will help route the request, and you may also lodge a complaint with your local data protection authority.
You have the right to know what personal information is collected, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money. To the extent ad personalization is considered "sharing" under CPRA, you can opt out using the tools in §6.
Regardless of where you live, you can always email us at [email protected] to ask what we hold about you or to request deletion, and we will respond within a reasonable time.
We rely on the security practices of the third-party providers listed above for data they process, and standard browser security (HTTPS) for data in transit to and from this site. No method of transmission or storage is 100% secure, but we do not operate a server-side database of user records that could itself be breached.
We may update this policy as the app changes. We'll update the effective date above; material changes will be reflected here before they take effect.
Questions, requests, or concerns about this policy or your data: [email protected]