Privacy Policy
Last updated: April 21, 2026
Introduction
ScrambleBoss ("the Game," "we," "us," or "our") is a daily word puzzle game operated by BOSS Software. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use ScrambleBoss at scrambleboss.com or through our iOS application. We are committed to respecting your privacy and being transparent about how your data is handled.
Information We Collect
Account Information: When you create an account, we collect your email address and a username you choose. If you sign in with Google, we receive your Google profile name and email address through Google's OAuth service. We never receive or store your Google password.
Game Data: We store your game activity including scores, words found in each puzzle, completion times, active play time, streak history, XP totals, achievement progress, perfect game counts, and challenge results. This data powers your profile, the leaderboards, the badge progression system, and the achievement system.
Push Notification Data: If you opt into daily reminders, we store your push notification subscription endpoint (for web push via the Web Push API) or your Apple Push Notification service (APNs) device token (for the iOS app). This data is used solely to send you daily puzzle reminders and is deleted when you unsubscribe.
Technical Data: Our hosting provider (Vercel) may automatically collect standard server logs including your IP address, browser type, device type, and pages visited. We do not use this data for tracking or advertising purposes.
How We Use Your Information
We use your data exclusively to operate and improve the game:
- Displaying your profile, stats, and game history to you and other players
- Powering leaderboards, challenges, and VS mode matchups
- Tracking your XP, level progression, badge tier, streaks, and achievements
- Sending daily puzzle reminders (only if you opt in)
- Processing Boss Pass subscription payments through Stripe
- Validating scores server-side to maintain fair play
- Improving the game experience based on aggregate, anonymized usage patterns
We do not sell your data to third parties. We do not use your data for targeted advertising. We do not share your personal information except with the essential service providers listed below.
Third-Party Services
We rely on the following third-party services to operate ScrambleBoss:
- Supabase — database hosting and user authentication
- Vercel — web hosting, serverless functions, and content delivery
- Stripe — payment processing for Boss Pass subscriptions (we never see or store your credit card number)
- Google AdSense — contextual advertising for free-tier users (Boss Pass members do not see ads)
- Apple — iOS app distribution and push notifications via APNs
Each of these services has their own privacy policy. We encourage you to review them if you have concerns about how they handle data.
Cookies and Local Storage
We use cookies for authentication — specifically, session cookies that keep you logged in across visits. We also use browser local storage to save your preferences (such as dark mode and sound settings), cache active play time between sessions, and store hint usage counts to prevent exploits. We do not use tracking cookies or cross-site cookies. Google AdSense may set its own cookies for ad personalization, subject to Google's privacy policy and your browser's cookie settings.
Public Information
Your username, level, badge tier, game stats (best score, average score, total games, streaks), and activity calendar are visible on your public profile page and on leaderboards. Your email address is never displayed publicly. If you prefer not to appear on leaderboards, you can contact us to request removal.
Data Security
All data is transmitted over HTTPS encryption. Our database is hosted on Supabase with row-level security (RLS) policies that ensure users can only access their own private data. Scores are validated server-side to prevent manipulation. Payment information is handled entirely by Stripe and never touches our servers.
Data Retention and Deletion
We retain your data for as long as your account is active. You can delete your account at any time from the Settings page within the game. Account deletion permanently removes your profile, all scores, game history, achievements, push notification subscriptions, and all associated data from our database. This action is irreversible. You can also request account deletion by emailing us at support@bosssoftware.dev.
Children's Privacy
ScrambleBoss is a word game suitable for all ages. However, we do not knowingly collect personal information from children under the age of 13 without verifiable parental consent, in compliance with the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has created an account without parental consent, please contact us at support@bosssoftware.dev and we will promptly delete the account and all associated data.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data; object to or restrict certain processing; and request a copy of your data in a portable format. To exercise any of these rights, contact us at support@bosssoftware.dev. We will respond within 30 days.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of ScrambleBoss after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact us at support@bosssoftware.dev.