xflag (“we”, “us”) operates xflag.ai and its games and applications. The data controller is [[LEGAL NAME / ENTITY]], [[ADDRESS]]. Contact us any time at hello@xflag.ai.
| Data | Why | Where it lives |
|---|---|---|
| Account holder’s email address and sign-in identifier | To create and secure the account, and to contact you about the service | Clerk (our identity provider) and our database |
| Profile nickname and year of birth | To show each profile games appropriate to their age | Our database (Cloudflare D1) |
| An essential session cookie | To keep you signed in and to check which games a profile may open | Your browser |
| Standard server logs (IP address, user agent, timestamps) | Security, abuse prevention and diagnosing faults | Cloudflare, retained briefly |
Parts of xflag are designed for children. We have built the service so that we collect as little information about a child as we practically can.
We aim to operate consistently with the U.S. Children’s Online Privacy Protection Act (COPPA) and, where it applies, the UK Age Appropriate Design Code. [[CONFIRM WITH COUNSEL BEFORE PUBLIC LAUNCH.]] If you believe a child has provided us with personal information beyond a nickname and year of birth, email hello@xflag.ai and we will delete it.
We use strictly necessary cookies only. There is no advertising or analytics cookie on this service today.
__Secure-xf_sess — keeps you signed in and records which profile is
selected. It expires after 7 days. Without it the service cannot work.Some games also save your progress in your browser’s local storage, so that a half-finished puzzle is still there when you come back. That information stays on your own device, is never sent to us, and is cleared when you clear your browser data.
If we later add analytics, we will update this policy and ask for your consent first where the law requires it.
Where the UK or EU GDPR applies, our lawful bases are:
We do not sell personal information. We share it only with:
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict how we use it, and to complain to a data protection authority. Californian residents have rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information for cross-context behavioural advertising.
To exercise any of these, email hello@xflag.ai. We will respond within the time the law allows. We will not treat you differently for asking.
All traffic is encrypted in transit. Session cookies are signed, marked HttpOnly and Secure, and cannot be read by scripts in your browser. We hold no passwords to lose. No system is perfectly secure, but we take the protection of a service used by children seriously, and we will tell affected users promptly if a breach occurs that is likely to put them at risk.
Our providers operate globally, so your information may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as the European Commission’s standard contractual clauses. [[CONFIRM WITH COUNSEL.]]
If we change this policy we will update the version above and, for material changes, tell the account holder by email before the change takes effect.