Legal, trademarks and privacy
Updated 19 August 2026.
Who makes this
Word Night is an independent browser word game, made and run by Stefano. It is a personal project: there is no company behind it, it makes no money, and it has no relationship with Hasbro, Netflix, Zynga, Apple or GamePigeon. A contact address for corrections, rights-holder queries and anything else is being set up and will be published on this page.
How the comparisons on this site are made
Every fact about another game on this site is checked against that publisher's own pages or store listing, and carries the date it was checked. Netflix's Boggle Party was checked on Netflix's game page, help centre and launch announcement in July 2026. Zynga's Boggle With Friends and Boggle: Arcade Edition were checked on their Google Play and App Store listings in July 2026. GamePigeon's Word Hunt was checked on its App Store listing in July 2026. Where a claim comes from player reviews rather than a publisher, it is labelled as such. Where a publisher does not publish a fact, the comparison tables say so instead of guessing. Where we have not tested something ourselves, we say so rather than implying we have. If a fact here is out of date, write to the contact above and it will be corrected and re-dated.
Trademarks
BOGGLE is a registered trademark of Hasbro, Inc. Boggle Party is a game published by Netflix, Inc. under licence from Hasbro. Boggle With Friends and Boggle: Arcade Edition are published by Zynga Inc. Word Hunt is part of GamePigeon, developed by Vitalii Zlotskii. Word Blitz is published by LOTUM one GmbH. Wordament is a Microsoft product. App Store and Apple Arcade are trademarks of Apple Inc. Google Play is a trademark of Google LLC.
Word Night is not affiliated with, endorsed by, sponsored by or connected to any of these companies. Where their names appear on this site, they are used only to identify and compare those products truthfully, so readers can understand how the games differ. All product names, logos and brands remain the property of their respective owners.
If you are a rights holder and believe something here misrepresents your product, write to the contact above and it will be corrected.
Privacy
Word Night is run by Stefano, who is the data controller for everything below. To ask a question, or to have your data deleted, use the contact above — it is being set up and will be published on this page.
There is no account
You never sign up: no email, no password, no payment. The first time you open the game our server creates an anonymous guest — a random number, with no name attached — and your browser gets a cookie so the same guest is recognised next time. That is the only reason your level and coins are still there when you come back. Clear your browser's site data and you lose access to that guest for good: the next visit starts a new one, and the old progress stays on our server with no way for you or us to reach it. If you want it actually deleted, ask us before you clear it — afterwards the identifier we would need is gone.
What we store
On our server, against that random number only:
- Your progress — XP, level, coins, games played, words found, best score, win streaks and daily challenge results.
- A display name and avatar. We generate both; you can change the name, and everyone in a party room sees it.
- Party games — the room and its invite code, who was in it, and every word each player submitted, including the path traced across the grid and whether it was accepted. That is what builds the end-of-round reveal.
- Session details — when your guest session began and expires, and the user-agent string (your browser and operating system name) that your device sends with every request.
- Which days you opened the game — one row per guest per day, holding the day, the first and last time we saw you that day, and how many times the app started. It is how we know whether anyone is playing at all; it holds nothing about what you played. These rows are deleted after 400 days.
Your device also keeps your profile, settings and any finished game not yet sent to us, in your browser's own storage.
Why, and on what legal basis
All of it exists to run the game you asked to play — Article 6(1)(b) GDPR, performance of a contract. We also count connections per IP address so one device cannot exhaust the server; those counts live in memory for minutes and are never written to disk (Article 6(1)(f), legitimate interest). The measurements and error reports described under Analytics, and the record of which days you opened the game, rest on the same legitimate interest: a game we cannot see breaking is a game we cannot fix, and one nobody finishes is one we cannot improve. You can object to any of it. We do not profile you and show no advertising. We do not write your IP address to our own database; the companies that host the game and receive its error reports necessarily see it, as any server does when your browser connects to it. Who those companies are is below.
Cookies
Two, both ours, both needed to run the game: one holds your guest session for 30 days, the other lasts ten minutes while that session is created. No advertising or tracking cookies, no third-party cookies, and no identifier stored on your device for the measurements and error reports described below — which is why no banner interrupts your game. Strictly necessary cookies do not require consent, and what consent exists to protect you from is something being kept on your device to recognise you later. For analytics purposes, nothing here is.
Analytics and error reports
There is no advertising, no tracking pixel, no session recording and no profiling, and no script is downloaded from anyone else's servers. The app deliberately allows only the reports described below. Read the browser-context paragraph as part of every browser report: describing an event by the field it adds would otherwise leave you with a smaller picture than the one PostHog receives.
Until 19 August 2026 this page also said there was no page-by-page tracking. There is now, in one narrow sense, and we would rather change the sentence than let it quietly stop being true: the game reports the name of the screen you have arrived on, once per arrival, chosen from a fixed list of fourteen names — home, solo_setup, party_lobby, party_settings and the like. The name is what this report ADDS: never the address, never the invite code, never anything you typed. It is how we find out where people give up — how many open the game and never reach a round — which is the one question nothing on our server can answer, because leaving without playing leaves no trace there. It is sent when you arrive, not on every redraw, so sitting on one screen for ten minutes sends one of these and not six hundred.
Three things about the game, and exactly what each carries. That the app was opened, with the language you are playing in. That a round started: its mode (solo or party), the grid size, the length you chose in seconds, the minimum word length for that round, and the language. That a round ended: the same mode, grid size, chosen length and language, plus whether it was finished or left, why it ended (the clock ran out, or you ended it yourself), and how many seconds it actually ran. Not the words you found, not your score, not your name, not the room, not who else was in it. It exists to answer one question we cannot answer any other way: whether people are enjoying the game enough to finish a round. Correcting something this page got wrong: it said these came from Solo rounds only, and that stopped being true when Party started reporting them too.
What that means for party rounds, since it would otherwise mislead you as much as it misleads us. These reports come from your device, not from our server, so the unit is one browser client entering the view of one round — never a room, never a server-counted round, never a person. A party round viewed on five phones produces five client starts. A phone that joined after the round began and is waiting for the next one is a spectator, but its browser still sends a start when it enters that view and an ending when the results arrive, although it played none of the round. A reload that reaches the view again creates another browser-client entry. These reports carry no room code and no round identifier, so nothing marks several entries as belonging to one room or round; we deliberately do not build that group fingerprint, and therefore cannot subtract those duplicates. In the other direction, a phone closed or killed mid-round may send no ending, and an extension that blocks reporting may send nothing. The client figures are therefore duplicated on one side and incomplete on the other. The authoritative number of party rounds comes from our own server, not these reports. Correcting something this page said until 19 August 2026: it said a phone joining a round already under way reported nothing for it. That was wrong.
Which of our own pages sent you here. The links from our written pages — the Boggle and Word Hunt pages, the how-to-play page, this one — carry a short mark naming the page they are on, and the game reports that name once, with the fact that it was opened. It is a value from a fixed list of six page names, or the word direct when there is no mark. It is taken out of the address bar before anything is reported, and it is kept only in the page's memory for as long as that page is open: reload, and it is gone. It adds no identifier — nothing new is written to your device and nothing about it is sent to our server. If the mark cannot be taken out of the address bar, or if something we did not write is sitting where it goes, the game keeps working and simply reports nothing at all for that page load: we would rather lose the measurement than send you an address with our bookkeeping stapled to it. It exists so we can tell whether writing those pages is worth the time.
A report when the game breaks. A browser error adds its type, scrubbed message, scrubbed stack trace, reduced route and whether a render, window handler or rejected promise noticed it. A failed save adds its terminal status and error code. Separately, a server error adds the affected part of the service, error type, HTTP status when there is one, the first request's server request ID, and a count of occurrences. That server report uses the constant sender name server, a timestamp, a per-report insertion ID and a flag that disables person-profile processing; it does not carry a guest, round, room or group ID.
Each browser report — including a screen name or page mark — also carries the following context. $current_url and $pathname are reduced to a route such as /solo, /settings or /play/<token>, never the invite code. It carries coarse browser and version, operating system and version, device type, and viewport width and height. Its temporary transport values are distinct_id for the page load, $session_id for the reporting session, $window_id for the browser window, $insert_id for de-duplicating one report, and the report's own uuid. Its time is carried as the report timestamp and the SDK's $time. The remaining SDK context is the PostHog project token, $lib and $lib_version, plus $process_person_profile and $is_identified, which record that person processing and identification are off. The temporary IDs live only in the reporting library's memory for this page load; the project token, library labels and boolean flags are configuration, not identifiers invented for you. This context is useful for grouping reports and reproducing faults, and we do not present it as incapable of identifying or correlating a browser.
No analytics identifier is stored on your device. The reporting library is configured with memory-only persistence and no person profile, so it keeps no analytics cookie or browser-storage identifier across page loads. PostHog does receive and retain the temporary IDs and context listed above with each report, and your IP address reaches PostHog with the connection itself, as it does with every request a browser makes to another company. Those facts, together with browser, window size and time, are why we make no claim that a report is non-identifiable or cannot be correlated. What we can state is what the app does: it stores no analytics identifier on your device, asks for no analytics identity, and creates no PostHog person profile. While starting up, the library tests whether browser storage works by writing and immediately removing one throwaway key; it does not store an identifier there. If you played before 31 July 2026, an older lasting analytics identifier may have been stored; the current version deletes it the first time you open the game.
These reports go to PostHog, on their European servers in Frankfurt, acting only on our instructions under a data-processing contract. As with any request your browser makes to another company, the connection itself tells them the IP address it came from. Your name, the words you found, your scores and your invite codes are never part of a report. Error messages are checked before they are sent: your name is taken out of one that contains it, and a message containing anything shaped like an invite code — or like a name too short to remove without mangling the sentence — is withheld whole rather than trimmed and hoped about.
How long we keep it
Your guest session expires 30 days after it is created, and in any case after 180 days. Being straight with you about a detail that surprises people: today playing does not push that date back, so a guest expires 30 days after it began however often you played. When that happens the game makes a new guest for you, and the level and coins held on our server do not come across. We consider that a bug rather than a policy, we are fixing it, and this page will be updated when the fix ships.
PostHog keeps the reports and their context described above for a year on the plan we use, and then deletes them: app openings and page marks, round starts and endings, screen names, browser error reports, failed-save notices, and server failure reports. If we ever move to a plan that keeps them longer, this page changes with it. The record in our own database of which days a guest opened the game is deleted after 400 days. Beyond that we would rather be straight with you than quote a number we do not honour: the game does not yet delete old progress or finished party rounds automatically. Building that deletion is the next job on this list, and this page will state the period once it runs. In the meantime, ask us and we will delete your data by hand.
Children
Word Night is playable by anyone who can read, and nothing in it is aimed at adults. It asks for no personal details. There is no chat and no way to be matched with a stranger — you play only with people you invite by code or link. Offensive display names are rejected. Worth knowing as a parent: the display name is free text and everyone in the room sees it, so a nickname beats a real name.
Where your data is
Three companies are involved, each acting only on our instructions and none allowed to use anything for their own purposes:
- Hetzner runs the server the game itself is on, so every request — and therefore the IP address it came from — passes through their infrastructure.
- Neon hosts the database, in Germany. That is where your progress, display name and party rounds are stored.
- PostHog receives the measurements and error reports described above, on their European servers in Frankfurt.
Neon and PostHog are United States companies operating European regions, so where their staff need access for support, that happens under the European Commission's standard contractual clauses. Nobody else receives anything, and none of it is sold, shared or used for advertising.
Your rights
You can ask for a copy of your data, have it corrected or deleted, or object to how we use it. Because there is no account, the guest identity on your device is the only way we can find your records — write from the device you play on and we will tell you what to send. You can also complain to the Garante per la protezione dei dati personali.