MorphMove
Privacy
Last updated 19 August 2026
Gameplay analytics
The web and installable web versions of MorphMove record first-party product events to understand how the game is used and improve it. These events can include app sessions and returns, page and instruction opens, game starts, moves, blocked or abandoned move attempts, bounded AI reliability outcomes, results, ratings, restarts, review actions, control changes, sharing and multiplayer actions, notification-prompt outcomes, and interactions with the physical-edition prompt.
What the event stream contains
Events use random browser-installation, session, game, and event identifiers. They may include bounded details such as move method, move count, outcome, duration, difficulty tier, runtime category, fixed failure reason or latency bucket, selected setting, anonymous invitation or share identifiers, campaign labels, and the hostname of an external referring site. A coarse country, device type, operating-system family, and browser family may be derived when events are uploaded. Country may reflect a VPN, Private Relay, or the place where offline events were later uploaded.
Names, email addresses, room access tokens, full user-agent strings, full referring URLs, and free-form text are not saved in the gameplay event stream. Hosting providers may still process ordinary connection data, including IP addresses, as needed to deliver the service securely and prevent abuse.
Local history
Up to the most recent 50,000 detailed analytics events may be kept in this browser’s IndexedDB so MorphMove can retain local statistics. Compact lifetime totals may remain available even as older detailed events rotate out. Pending events are also held locally while offline. Clearing MorphMove’s browser data removes that local analytics history and creates a new anonymous installation identifier.
Multiplayer rooms
Multiplayer games use an eight-character room code, random participant credentials, game state, scores, presence timestamps, and anonymous room and match identifiers so the game can synchronize between players. Participant credentials are sent only to the relevant player; server-side credentials are stored in hashed form. Rooms are temporary and expire after about 24 hours unless renewed by activity.
Daily Puzzle progress
Detailed Daily Puzzle attempts, moves, solved dates, and streaks are stored only in this browser. They are not linked to your rating or synchronized across devices. Clearing MorphMove’s browser data removes that progress.
Notifications
If you enable notifications from either Daily or multiplayer, the browser creates a push subscription containing a provider endpoint and encryption keys. MorphMove uses it for recurring 18:00 local-time Daily reminders when that day’s puzzle has not been played and, when you host a room, to tell you when the other player joins. The Daily registration also stores an anonymous management token, your current IANA time zone, the next reminder time, and the latest Daily date played or reminded on this installation; room alerts are separately linked to an anonymous room-owner token. Room registrations expire after 30 days without refresh. Registrations are removed when the push provider reports that they are no longer valid. You can stop all alerts at any time in your browser settings; this stops delivery on that device but does not necessarily delete the Daily reminder registration from MorphMove’s server.
Physical-edition email
If you voluntarily register interest in a tabletop edition, MorphMove stores the email address you provide, a normalized copy used to avoid duplicates, the signup source, and the consent version. The address is used only for meaningful news about a physical MorphMove edition and administration of that list. It is not added to gameplay analytics or used for advertising profiles. You can ask for removal at any time.
Security and abuse prevention
MorphMove applies rate limits and other request protections to reduce spam and abuse. Hosting and infrastructure providers may process short-lived technical identifiers derived from connection data for those purposes and for ordinary service security.
Purpose, retention, and providers
Data is used only to operate, secure, understand, and improve MorphMove, provide multiplayer and notifications, and manage the optional physical-edition mailing list. It is not sold and is not used to create advertising profiles. Web analytics retention maintenance removes live events older than 360 days; provider recovery systems may retain deleted records for up to 30 additional days. Temporary multiplayer rooms and join-notification registrations expire as described above. Daily reminder registrations have a rolling ten-year expiry, renewed when the registration is refreshed or a reminder is successfully sent; invalid registrations are removed sooner. You can request deletion at admin@morphmove.com. Email signup records are kept while the physical-edition list remains relevant or until deletion is requested. Hosting, database, email, and push notification providers may process the minimum data needed to provide their respective services.
Your choices and rights
You can decline notification permission, clear locally stored web data, and avoid the optional physical-edition signup. For access, correction, deletion, objection, or other privacy questions, email admin@morphmove.com. Because web analytics identifiers are random and contain no account identity, you may need to provide the relevant identifier when asking about a specific analytics history. You may also lodge a complaint with your applicable data-protection authority, including Portugal’s CNPD.
Back to MorphMove