Privacy

Privacy Policy

This privacy notice explains the lightweight information Puzzle Hint Lab may collect.

Information we collect

Core hint pages and word tools do not require an account. The public puzzle pages can be read without signing in.

If you contact us, the server receives your name, email address, topic, puzzle type, puzzle date, and message so the request can be reviewed and answered.

Cookies and analytics

The public hint pages do not require tracking cookies to work.

Google Analytics loads only when a GA4 measurement ID is configured in admin settings. Plausible loads only when a Plausible domain is configured in admin settings.

Cloudflare may process standard request logs and security signals as part of hosting, caching, abuse prevention, and delivery of puzzlehintlab.com.

Authentication and admin areas may use necessary cookies if those areas are enabled, but reading the public hint pages and using the word finder does not require an account.

Contact form handling

The contact form submits to the /api/contact endpoint, which validates the fields, rate-limits repeated submissions, and returns a reference id.

Correction requests must include the puzzle type and puzzle date so the relevant record can be checked.

Puzzle Hint Lab does not use Turnstile on the contact form yet; the current anti-abuse controls are a honeypot field, validation, and a minimum interval rate limit.

Retention and deletion

Contact messages are kept only as long as needed to respond, investigate corrections, and prevent abuse. Operational logs should be rotated according to the hosting provider settings.

To request deletion of a contact message, email hello@puzzlehintlab.com with the address used in the original message.

Effective date

This privacy notice is effective July 2, 2026 and should be updated whenever analytics, contact handling, or data storage changes.