DROPPEDBIT // DATA PRACTICES

Privacy Policy

DroppedBit is a technical puzzle game. This page explains the small amount of information needed to provide weekly puzzles and to sell, deliver, and remember a game session.

Information we use

We use the email address supplied at demo start, dashboard sign-in, or checkout to create and recover a player profile, connect purchases to the correct run, and deliver game emails.

A game session stores internal identifiers and private access credentials, whether it is a demo or paid game, progress and level-visit timestamps, requested hints, creation and completion times, whether the completion email was sent, and completion status. If you choose to prepare a leaderboard entry, the session also stores the handle and participant type you select.

A weekly-puzzle attempt stores the puzzle slug, a random attempt identifier, start and completion timestamps, completion status, and the attempt's first-come solve position. Weekly attempts do not require an email address and are not connected to a player profile.

For purchases, DroppedBit receives the checkout email, payment status, and Stripe checkout and event identifiers needed to provision access and prevent duplicate processing. Payment-card details are collected and handled by Stripe; DroppedBit does not store full card numbers.

Support messages contain the information you choose to send. Operational logs may contain request paths, status and timing information, request IDs, account email addresses, and internal game or provider identifiers when needed to operate and troubleshoot the service.

Why we use it

We use this information to provide the weekly puzzles, demo, and complete game; assign each completed weekly attempt one solve position; preserve and restore progress; verify sequential access; deliver sign-in and game emails; prevent duplicate purchases from creating duplicate runs; maintain security and reliability; respond to support requests; and keep completion records.

Public leaderboard

Completed runs are private unless you deliberately publish one from the leaderboard management page. Before publishing, DroppedBit shows the fields that will become public: your chosen handle, participant type, solve duration, and completion time. Your email address is not included in the public entry. You can update or unpublish the entry later.

Providers, cookies, and browser storage

DroppedBit uses Stripe for hosted checkout and refunds, and Amazon Web Services for hosting, game records, operational logs, and email delivery. Public pages also load fonts through the Google Fonts Web API, so your browser sends Google the technical information needed to return those files, including your IP address, the font URL, browser headers, and referrer information your browser allows. See the Stripe Privacy Center, AWS Privacy Notice, and Google Fonts privacy FAQ for their practices.

The site uses a signed, HTTP-only, same-site session cookie after dashboard sign-in or demo start. A passwordless dashboard session can last up to 30 days; the demo-start session is shorter. Opening an active weekly puzzle creates a separate signed, HTTP-only, same-site cookie scoped to that issue. It contains an opaque attempt identifier, not an email address, and can remain valid until 30 days after the issue closes so that the browser can reopen its completion screen. Checkout confirmation uses temporary session storage only to limit automatic status refreshes. DroppedBit does not use advertising cookies or analytics trackers.

Game links contain opaque private access credentials. You may privately send the invitation envelope image to the friend you want to play the game. This gives them access to play; the run remains attached to your checkout email, and dashboard access and leaderboard publishing stay with you. Do not publish the invitation or game links, or share your dashboard sign-in links.

Retention and requests

Demo access credentials and puzzle route links are configured for 30 days from creation. Completion links do not expire once the game is completed. A complete-game purchase refreshes them for 30 days from purchase. Stripe webhook-processing records are also configured to expire after 30 days, and application logs are configured for 14-day retention. Provider deletion processes may not remove an expired record immediately.

Player, purchase-linked game, and completion records may be retained longer so we can restore a dashboard, support a purchase, prevent abuse, maintain completion history, and meet legal or accounting obligations. A published leaderboard entry remains public until you unpublish it or ask us to remove it.

Anonymous weekly-attempt records and per-puzzle solve counters may be retained to preserve solve order, seasonal results, and abuse controls. They are not linked to an email address. Clearing the issue cookie removes the browser's ability to reopen that guest completion record but does not automatically delete the anonymous server record.

Email support@droppedbit.com to request access to, correction of, or deletion of your information. We will verify the request using the email connected to the account and may retain limited records where required for security, transaction records, or law.

Questions or access problems? Email support@droppedbit.com.