Budi GamesQuiet puzzles, one at a time

Privacy policy

Budi Games is published at budigame.com by the small independent team described on the about page, and this document is the complete account of how personal data is handled here. It is written in ordinary sentences on purpose. Anything below that is unclear can be raised at [email protected], and we will both answer you and improve the wording.

1. What we do not collect

It is quicker to begin with the absences, because they cover most of what a visitor does here.

  • There is no registration, no login and no user database. We could not identify you if we tried.
  • Solving a puzzle sends nothing anywhere. Your moves, your times and your mistakes stay in the tab.
  • We run no analytics product and no cross-site measurement. There is no page-view tracker on this domain, first-party or otherwise.
  • There are no social network buttons, no embedded videos, no comment platform and no tracking pixels. Every stylesheet, script and image the puzzles need is served from budigame.com.
  • We do not fingerprint devices, we do not build profiles, and we have never sold, rented or traded personal information — a category that we also have almost none of.

Advertising, described in section 5, is the one exception to the "no third-party code" rule, and it is the reason this policy is longer than a paragraph.

2. What your browser stores for you

Each puzzle remembers a little about your own play, using the localStorage feature that browsers provide to pages. Everything we write there is namespaced under keys that begin with bg:, and the complete list of what those keys hold is:

  • your best completion time for a puzzle, recorded separately for each difficulty level, so that Sudoku on Expert keeps its own record apart from Sudoku on Easy;
  • your best move count on the puzzles where efficiency rather than speed is the interesting measure, again per puzzle and per difficulty;
  • your theme choice, meaning whether you selected the light or the dark palette;
  • your sound preference, meaning whether puzzle sounds are on or muted.

That is the entire inventory. These values are written by JavaScript running on your own machine and they are never transmitted to our server or to anyone else's. We cannot read them, we do not receive a copy, and no identifier is attached to them, so they cannot be linked back to a person even in principle.

Because the data belongs to your browser, it behaves like your browser: a record you set on a phone stays on that phone and never surfaces on a laptop, a second browser on the same machine begins from nothing, and private or incognito windows forget everything the moment they close. You are in full control of it. Clearing site data for budigame.com, or clearing your browsing history, deletes every bg: key immediately, and your browser's developer tools will show you the raw values if you are curious. We cannot restore what you delete, because we never had it.

3. What the contact form transmits

The contact form is the only place on this site that sends anything to us. When you submit it, the following is delivered to our mailbox as an email:

  • the name you typed;
  • your email address;
  • the subject you selected from the list;
  • your message;
  • the IP address the submission came from;
  • your browser's user-agent string, which names the browser and operating system;
  • the page you submitted from, taken from the referring header.

The first four items are what you chose to tell us and are used only to understand and answer your message. The last three arrive automatically and exist for two practical reasons: reproducing a bug is far easier when we know the browser it happened in, and distinguishing a real message from automated spam is far easier when we can see the pattern of submissions. None of it is used to profile you, none of it is passed to an advertiser, and you will not be added to any mailing list — we do not operate one.

Retention. A message is kept for as long as the exchange is useful, which in practice means until the question is answered or the bug it describes is fixed and released. After that the thread is deleted, and in any case we clear the contact mailbox of resolved correspondence at least once a year. Ask us to delete your message sooner and we will do it and confirm.

Two anti-spam measures run alongside the form. It contains a hidden field that a person never sees and never fills in; a submission that arrives with that field completed is discarded. And the server keeps a short-lived count of submissions per IP address, in a temporary file, to stop a script sending the same message hundreds of times. That counter holds a hashed value with a timestamp, expires within minutes, and is not used for anything else.

Please do not put passwords, payment details, identity documents or other sensitive information into the form. Email is not an encrypted channel and we have no reason to hold any of it.

4. Server logs and hosting

Like every web server, ours records a line each time a file is requested. That line holds the IP address behind the request, a timestamp, the path asked for, the HTTP status sent back, the response size, the user-agent string and whichever page referred you. Logs of this kind keep the site standing: they are how we find an error, how we notice an attack, and nothing more. They never feed a picture of an individual visitor, and they are rotated away on our host's ordinary schedule. A content delivery network may sit in front of the server, handling the same technical fields for the purpose of returning the page quickly and turning away abusive traffic.

5. How advertising works here: Google AdSense and the DART cookie

Hosting is paid for with advertising, and we intend to serve it through Google, including the Google AdSense programme. Everything in this section applies from the moment advertising is live on the site.

  • Third-party vendors, Google among them, use cookies to serve advertisements based on your earlier visits to this website or to other websites.
  • Google's use of advertising cookies — the mechanism long known as the DART cookie — allows Google and its partners to select advertisements for you based on your visits to this site and to other sites across the internet.
  • You can decline personalised advertising from Google at any time through google.com/settings/ads. Turning it off does not remove advertising from the web; it makes the advertisements you are shown less closely tailored to you.
  • Google's own description of how advertising cookies work, and of the choices available to you, is published at policies.google.com/technologies/ads.
  • To opt out of many vendors at once rather than one at a time, the industry pages at aboutads.info/choices and, for European visitors, youronlinechoices.com cover most of the market.
  • Advertising partners may receive technical data of their own: your IP address, characteristics of your device and browser, the page the advertisement appeared on, and whether you interacted with it. What they do with it is governed by their policies, not by ours. We cannot read the cookies they set and we have no access to the data they gather.

Where consent is legally required before non-essential cookies may be set — the European Economic Area, the United Kingdom and Switzerland being the clearest cases — advertising cookies are only placed on the basis of the choice you make in the consent notice shown to visitors from those regions, and that choice can be changed or withdrawn later through the same notice.

One placement rule, which we consider part of the privacy bargain: no advertisement will be rendered inside a puzzle board where it might be mistaken for a tile, a clue or a button, and none will interrupt a puzzle you are in the middle of solving.

6. Other third parties

Beyond the advertising described above, the parties that can see technical data about your visit are our hosting provider, the content delivery network in front of it, and the mail provider that carries contact messages to us. Each processes data only to provide its service. We use no third-party commenting system, no font service, no chat widget and no marketing platform, and we will not add one quietly — a change of that kind is a change to this page.

7. Legal bases and rights under the GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, the General Data Protection Regulation and its equivalents apply to you, and we act as the controller for the data described here. We rely on our legitimate interest in running a functioning, secure website for server logs and for anti-spam measures; on the necessity of processing to respond to you for the content of a contact message; and on your consent for advertising cookies.

You may ask for access to any personal data we hold about you, for a copy of it in portable form, for it to be corrected or erased, for processing to be restricted, and you may object to processing based on legitimate interest. Consent already given to advertising cookies can be withdrawn without affecting what happened before. Because the only material we hold is contact correspondence and short-lived technical logs, these requests are usually settled in days rather than weeks; write to [email protected] and we will reply inside the statutory period and never later than thirty days. You also have the right to complain to your national data protection authority.

8. California residents (CCPA/CPRA)

California residents have the right to know what categories of personal information are collected and why, to request a copy, to request deletion, to request correction, and not to be treated worse for exercising any of those rights. The categories that apply to this site are identifiers and internet activity information, limited to what sections 3 and 4 describe. We do not sell personal information and we do not share it for cross-context behavioural advertising in the sense the statute defines, which is why there is no "Do Not Sell or Share My Personal Information" link here; there would be nothing behind it. Requests go to the same address and receive the same treatment as any other.

9. Brazil (LGPD)

For visitors in Brazil, the Lei Geral de Proteção de Dados (Law No. 13.709/2018) grants rights that broadly mirror those in section 7: confirmation that processing exists, access, correction of incomplete or outdated data, anonymisation or deletion of unnecessary data, portability, information about with whom data has been shared, and revocation of consent. The legal bases we rely on are the equivalents named in Article 7 — consent for advertising cookies, and the legitimate interest of the controller for security logging and for replying to messages you initiate. Requests may be written in Portuguese and sent to [email protected].

10. Children

Budi Games addresses a general audience. It is not aimed at, marketed to or designed for children below the age of 13, and we do not knowingly gather personal information from anyone in that age group. This is consistent with the Children's Online Privacy Protection Act (COPPA) in the United States and with the equivalent rules in other countries. The puzzles themselves ask for nothing and store nothing beyond the browser keys in section 2, so the only route by which a child's data could reach us is the contact form. If you are a parent or guardian and believe that has happened, tell us and we will delete the message on receipt without needing proof of anything.

11. International transfers

The site is served from infrastructure that may sit outside your country, and requests may be routed through a content delivery network with points of presence worldwide, including in the United States. Advertising partners operate internationally by nature. Where personal data crosses a border it does so under the transfer mechanisms available to the provider handling it, such as the European Commission's standard contractual clauses.

12. Security

Every page is delivered over HTTPS. The attack surface here is small by construction: there are no accounts to compromise, no stored player records on our side, and no database of visitors to leak. The contact mailbox is protected with two-factor authentication. No system can be called perfectly secure, which is the practical reason for the request in section 3 to keep sensitive material out of the form.

13. Links to other sites

The guides occasionally link outward, to a reference or to a historical source, and advertisements link to their advertisers. Once you follow such a link you are on someone else's property, under their privacy policy and their cookie practices, neither of which we control or monitor. A link from here is not an endorsement of what sits at the other end.

14. Changes to this policy

When this policy changes the new version replaces this one on this page and the date under the title changes with it. Substantive changes — adding a category of third-party service, for example, or beginning to collect something we do not collect today — will be described in the text rather than slipped in. Re-reading the page after a change is the reliable way to see what moved.

15. Contact

Questions, access requests, deletion requests and complaints about privacy all go to [email protected], or through the contact form with "Something else" as the subject. A person reads them.

Related pages