Ordsnok
TermsPrivacyDeletionSupportPlay in browser
NO/EN

Last updated 12 September 2026

Privacy in Ordsnok

Strange Utvikling is the data controller for personal data in the Ordsnok apps, the browser game at play.ordsnok.app and the website ordsnok.app. This policy explains what data we use, why we use it, and the choices and rights you have.

Data controller:
Strange Utvikling · org. no. 935 912 032
Roppestadkollen 63, 3138 Skallestad
support@ordsnok.app

1. Data we process

The browser game and local storage

At play.ordsnok.app, game preferences, the sign-in session and local game data are stored in your browser. Online features use the same account system as the mobile apps. An anonymous profile is not automatically recognized in another browser. Linking Apple or Google, or using a private recovery key previously saved from Profile, lets you access the same profile again. Clearing browser data without this can lose access to the profile. Your recovery key is secret and must not be sent to support.

Account and profile

App start and local games do not create a profile. Before you use the daily word, groups or other online features, the app explains that Ordsnok can create a random player ID with no name or email. If you later link Apple or Google to that player ID, we receive a provider ID and data you choose to share, such as email and name. Linking preserves the same user ID and existing data, and lets you recover the account and sync data across devices.

Games and groups

For online games the app sends required guesses, attempts, solve time, hint use and result data to our backend for validation and sync. Results, points, streaks, statistics, group memberships and required security events are stored. Offline practice games stay on the device. Raw guesses are not sent to analytics or advertising systems.

Purchases and entitlements

For mobile purchases, we may receive a transaction ID, product type, status and time from Apple, Google and RevenueCat. Browser hint purchases are handled through Stripe Checkout. The payment is linked to the player profile, and confirmed purchase status is used to credit hints. The purchase may also be reported to RevenueCat from the server. We do not receive your full card number. We use this information to credit hints, manage mobile ad-free access and prevent double crediting.

Device, notifications and operations

Where needed we may process app version, platform, time zone, error codes and security events. When you choose push notifications we process a push token for the installation.

Analytics, diagnostics and ads

On ordsnok.app and in the iOS and Android apps, PostHog is used only after separate, explicit consent. The browser game has no active PostHog analytics in the current version. Firebase Crashlytics, Google AdMob, UMP and push notifications apply to the mobile apps and are not used by the browser game. Crashlytics requires a separate choice. AdMob and UMP process consent status and necessary advertising data. You can change choices in Settings.

2. Why we use the data

  • to deliver your account, games, groups, sync and leaderboards;
  • to process purchases and manage hints and ad-free access;
  • to send notifications you have chosen;
  • to measure and improve the product when you have consented;
  • to detect errors, misuse and invalid results;
  • to meet legal requirements and handle enquiries.

The legal basis is your agreement with us when needed for the service, consent for optional functions, and legal obligations for some transaction data.

3. Service providers

The following categories of provider may process data on our behalf for the stated purposes:

  • Supabase: database, authentication and backend functions.
  • Cloudflare: delivery and operation of the website and browser game.
  • Stripe: payment and payment confirmation for browser hint purchases.
  • Google: Crashlytics and AdMob/UMP.
  • PostHog: optional product analytics in the EU cloud after explicit consent.
  • RevenueCat, Apple and Google Play: purchases, transaction status and entitlements.

4. Analytics on ordsnok.app and in the mobile apps

On ordsnok.app and in the iOS and Android apps, we use optional product analytics from PostHog, acting as our processor with data hosted in the EU, to understand how the products are used. The legal basis is separate, explicit consent. Before you consent, PostHog is not loaded in the browser, the mobile analytics transport is not created, no analytics ID or event queue is created, and no analytics data is sent. There is also no separate Cloudflare/Supabase baseline sending PostHog data. Analytics is not connected to a player account or a server-side person profile.

  • When you consent, a random/pseudonymous browser ID is created in the browser or a random/pseudonymous consent-scoped ID on mobile. The mobile ID is replaced after withdrawal and re-consent and at account boundaries. We send only reviewed events: website page views, page leaves, app download clicks and explicitly annotated CTA clicks, plus reviewed app interactions such as sessions, screens, game flows, groups, leaderboards, purchase/ad outcomes, notifications and activation of analytics consent. A rejection or withdrawal is never sent as an analytics event.
  • Website events use only the canonical path, locale, store, placement and fixed action values, plus PostHog’s necessary random transport, browser-session and library fields. The app uses no PostHog SDK and sends only the event name, random analytics ID, public project token, person/GeoIP-off flags, and the reviewed fixed categories or bounded numbers. It sends no automatic device, platform, app-version or time-zone properties. The source IP and a generic user agent are processed transiently to receive the HTTPS request; the PostHog project discards the IP, "$geoip_disable" prevents derived location, and the IP is not retained on events. We do not send player or account IDs, names, email addresses, advertising IDs, invitation tokens, guesses, answers, transaction IDs, puzzle/session/group IDs or free text.
  • Download buttons are recorded as “app_download_click” with the selected store and fixed placement. Other reviewed CTAs use “cta_click” with a fixed action value. All invitation pages are completely excluded from analytics.
  • PostHog is configured for EU ingest and manual capture. Person profiles, autocapture, automatic lifecycle/error/screen/page-view/page-leave events, replay, errors, surveys, heatmaps and feature flags are disabled. The mobile transport sends each accepted event immediately and has no event file, offline queue or automatic retry. Only the manual website and app events described above can be sent. Production collection is enabled only after the retention setting is verified at no more than 12 months.

This section describes analytics on the website ordsnok.app and in the mobile apps. The current published version of the browser game at play.ordsnok.app is not included in this analytics collection.

StoragePurposeDuration
ordsnok.analytics-consent.v2 (local storage)Remembers your versioned choice and its timestamp so we can respect your decision.Until you change the choice or clear browser data.
ordsnok.analytics-consent-revoked.v1 (local storage)Ensures a withdrawal overrides an older grant even if browser storage temporarily cannot be updated.Until a later choice is durably stored or you clear browser data.
ph_ordsnok-web* (local storage)PostHog’s random/pseudonymous browser and session IDs and necessary temporary transport data after consent.Until you withdraw consent or clear browser data.
Mobile analytics consent, revocation marker and install anchor (local storage)Remembers the versioned choice, keeps analytics off after interrupted storage, and rejects old consent that may have survived an iOS reinstall.Until a later choice is durably stored or the app is uninstalled. An older Keychain value is rejected on a new install.
analytics.posthog_identity.v1 (secure local storage)Random/pseudonymous analytics ID created only after consent. No events are stored here.Until withdrawal, an account boundary, a new consent period or app-data deletion.
analytics.posthog_identity.revoked.v1 (secure local storage)Prevents an analytics ID invalidated at an account boundary from being reused if local storage is interrupted.Until a fresh random analytics ID is durably stored or app data is deleted.

PostHog, Inc. processes analytics data as our processor, with event data stored in its EU cloud. Network transit and some subprocessors may involve processing outside the EEA; this must be governed by the data processing agreement, Standard Contractual Clauses or a valid adequacy mechanism. PostHog does not receive names, email addresses, player IDs or advertising IDs, and the analytics account is not used for advertising. Data is deleted or anonymised after the retention period.

Read how PostHog handles privacy and consent

4b. Optional ad measurement in the iOS app

The “Ad measurement” choice covers the TikTok App Events SDK. We use it to understand whether TikTok ads lead to installations and app usage, and to measure and improve our advertising campaigns. This is a separate purpose from product analytics, crash reports and Google advertising choices.

  • TikTok is activated only after an explicit ad measurement choice and permission to track in iOS. New choices start off. During onboarding and in Settings you can accept all displayed purposes, decline all or save only your selections. You can play without consenting. An earlier analytics choice or permission for Google ads does not activate TikTok.
  • The events are installation/first measurement startup, app launch and next-day return. The SDK may also process advertising and device identifiers, IP address, app version, device model, operating system, language, time zone and technical SDK information. It may store identifiers, timestamps and temporary events on your device. We do not send names, email, player accounts, guesses, answers or manual gameplay, screen, group or purchase events to TikTok. Enhanced collection of screen content and automatic purchase measurement must be disabled.
  • TikTok receives the data through its business services and may match it with other information, including for attribution and ad optimization. TikTok is not necessarily only our processor; the parties’ roles and processing are governed by the applicable TikTok Business Products Terms and jurisdiction-specific terms. Processing and transfers outside the EEA must be covered by applicable transfer grounds and agreements.
  • The basis for optional collection and sharing is consent (GDPR Article 6(1)(a) and the rules on device storage/access). Turn off Ad measurement in Settings to withdraw. You can also withdraw iOS tracking permission in system settings. Withdrawal applies to future processing and does not make earlier lawful processing unlawful. Contact support@ordsnok.app about previously shared data, access or erasure.
  • Consent choices and their timestamps are stored locally to respect your decision until changed or app data is deleted. TikTok’s retention of received data follows the purposes, agreements and privacy rules for its business services. The PostHog retention period above does not apply. Full information about TikTok’s processing and rights is available through the link below.

TikTok business terms and privacy information

5. Storage

Detailed game data – including guesses, attempts, solve time, hint use and the individual result – is kept for 15 months from the game date. Personal aggregates, statistics, streaks and season summaries are kept for the lifetime of your account. Backups are phased out through regular rotation.

6. Disclosure

We do not sell personal data. We disclose data only to service providers where necessary and governed by contract, with your consent, or where required by law. Official season podiums may show your display name and placement while your account exists and your visibility choices allow it. When you delete your account, we anonymize the podium entry and remove its link to you. There is no permanent preseason podium.

7. Your choices and rights

You can change consent and choices in the app’s Settings. On the website you can withdraw or grant analytics consent at any time through the analytics settings button. On withdrawal, collection is closed before cleanup and a local marker prevents an older grant from becoming active again if storage is interrupted. Mobile aborts active analytics requests and deletes its analytics ID, while the browser opts PostHog out and clears PostHog storage and pending queues. Any old Google Analytics cookies are removed. Analytics history already received by the server remains subject to the applicable retention and erasure rules. This choice does not affect access to the service. You may request access, correction, deletion or data portability where the law gives you that right, and you may complain to your local data protection authority.

8. Children and age limit

Ordsnok has an age limit of 13. If we discover an account belongs to a younger child, we will delete or restrict it.

9. Changes

We will notify of significant changes in the app or elsewhere. The date at the top shows the latest version.

© 2026 Strange Utvikling · org. no. 935 912 032 · Roppestadkollen 63, 3138 Skallestad

support@ordsnok.app

Cookies

We use cookies to understand how the website is used, but only with your consent. No analytics data is sent until you allow analytics. You can change your choice at any time.

Read the privacy policy