Privacy Policy

Version 2026-09-06 · Effective [[LAUNCH DATE]]

The short version. One adult holds the account. Children get profiles, not accounts — they have no email address, no password, and no login here. We ask for a nickname and a year of birth, and nothing more. We do not show advertising, we do not track anyone across other websites, and we do not sell personal information.

1. Who we are

xflag (“we”, “us”) operates xflag.ai and its games and applications. The data controller is [[LEGAL NAME / ENTITY]], [[ADDRESS]]. Contact us any time at hello@xflag.ai.

2. What we collect

DataWhyWhere it lives
Account holder’s email address and sign-in identifier To create and secure the account, and to contact you about the service Clerk (our identity provider) and our database
Profile nickname and year of birth To show each profile games appropriate to their age Our database (Cloudflare D1)
An essential session cookie To keep you signed in and to check which games a profile may open Your browser
Standard server logs (IP address, user agent, timestamps) Security, abuse prevention and diagnosing faults Cloudflare, retained briefly

What we deliberately do not collect

3. Children’s privacy

Parts of xflag are designed for children. We have built the service so that we collect as little information about a child as we practically can.

We aim to operate consistently with the U.S. Children’s Online Privacy Protection Act (COPPA) and, where it applies, the UK Age Appropriate Design Code. [[CONFIRM WITH COUNSEL BEFORE PUBLIC LAUNCH.]] If you believe a child has provided us with personal information beyond a nickname and year of birth, email hello@xflag.ai and we will delete it.

4. Cookies

We use strictly necessary cookies only. There is no advertising or analytics cookie on this service today.

Some games also save your progress in your browser’s local storage, so that a half-finished puzzle is still there when you come back. That information stays on your own device, is never sent to us, and is cleared when you clear your browser data.

If we later add analytics, we will update this policy and ask for your consent first where the law requires it.

5. Why we are allowed to process this data

Where the UK or EU GDPR applies, our lawful bases are:

6. Who we share it with

We do not sell personal information. We share it only with:

7. How long we keep it

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict how we use it, and to complain to a data protection authority. Californian residents have rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information for cross-context behavioural advertising.

To exercise any of these, email hello@xflag.ai. We will respond within the time the law allows. We will not treat you differently for asking.

9. Security

All traffic is encrypted in transit. Session cookies are signed, marked HttpOnly and Secure, and cannot be read by scripts in your browser. We hold no passwords to lose. No system is perfectly secure, but we take the protection of a service used by children seriously, and we will tell affected users promptly if a breach occurs that is likely to put them at risk.

10. International transfers

Our providers operate globally, so your information may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as the European Commission’s standard contractual clauses. [[CONFIRM WITH COUNSEL.]]

11. Changes

If we change this policy we will update the version above and, for material changes, tell the account holder by email before the change takes effect.

Terms of Service Contact Home