Privacy
Effective August 30, 2026
The game is designed for short sessions without an account. There is no sign-up, no password, and no email address on file. Do not enter sensitive personal information in codenames, chat, evidence, questions, or feedback.
Who is responsible
Why'd You Say That? is operated by a sole trader based in Antigua and Barbuda, trading as Why'd You Say That?. For any privacy question or request, write to support@whydyousaythat.com.
What is processed during a game
During a room, the server temporarily processes codenames, chat and gameplay actions, room settings, scores, and technical connection data needed to run the match and prevent abuse. Rooms are held in memory only: they expire after inactivity or a server restart, and nothing from the conversation is written to a database. Security logs record connection and rate-limit events and avoid submitted conversation text.
Your IP address is never stored as written. It is turned into a one-way hash and used for rate limiting, and — if a host bans you from their room — that hash is held in that room's ban list so the ban is not defeated by clearing browser storage. The ban list lives in memory and disappears with the room.
Room voice
When integrated room voice is available, the game asks for microphone permission only after you choose Join voice. Audio is carried as encrypted WebRTC media through Cloudflare Realtime. The game does not record, transcribe, or write voice audio to storage. Cloudflare relays the encrypted media and processes the IP addresses, ports, session timing, and other network metadata needed to operate that connection.
You can mute, deafen, or leave voice at any time. A host can mute or remove a participant. People watching a round do not receive its voice audio; voice opens for them only after they are promoted into an active seat.
What your browser stores
The following is kept in your own browser, on your device, and is not an account:
- A random player ID, created the first time you load the game. It is a random value with no name attached, it identifies your browser rather than you, and it is the identifier attached to analytics events and sent to Paddle with a purchase so the collection can unlock in this browser. Clearing this site's storage erases it and a new one is created.
- Your room credential for the room you are in, your settings preferences, and your agent's appearance.
- Recent crews you have played with — up to twenty past line-ups, each holding the codenames shown at that table and the final scores. This never leaves your browser and is never sent to the server.
- Any saved purchase access receipt, so a bought collection unlocks again without re-entering your Paddle receipt.
Analytics
Privacy-conscious product events may be sent to PostHog when configured, using the random player ID above. Events are sent from the server, no profile is built for you, and PostHog sets no cookie of its own. Events record what happened in a round — phases reached, settings used, counts and ratings — not what was said. Conversation text, guesses, private missions, and written feedback are not included in analytics events.
Purchases
Paddle processes checkout, payment, tax, receipts, and refunds under its own privacy terms, as merchant of record. Card details are never sent to or stored by the game server.
During this prelaunch period, Paddle is the purchase record used to verify access. The game temporarily caches transaction and customer IDs, the purchased price, payment status, refund or chargeback information, and webhook event IDs in server memory. This cache is bounded and is lost when the server restarts; the game does not currently keep its own permanent purchase or device-activation history.
Your browser stores a signed access receipt and transaction ID. Access is periodically rechecked with Paddle and can be restored after a server restart. The checkout email you enter for restoration is processed to check that it matches the purchase, but is not saved in the game's purchase cache. Paddle retains its own payment records under its privacy terms.
Sharing
The read-only broadcast view is off for every room until the host turns it on. Once on, it shows the connected codenames, scores, the current prompt, and recent public chat to anyone holding the broadcast link — never private missions, guesses, or controls. In an invite-only room, the broadcast link also carries the room's invite key. The host can switch it off at any time from the safety console, which disconnects anyone watching. Invite links share only the room they point at.
Data is not sold, and is not shared with anyone beyond the processors named on this page: Cloudflare for optional room voice and site delivery, PostHog for configured product analytics, and Paddle for purchases.
Reporting a player
Any player can report another from the room menu. A report records who reported whom, the reason chosen, an optional line you write, the phase it happened in, and the last twelve public chat messages in that room so the host can see the context. Private missions, guesses, private questions, and voice audio are never included.
Reports are visible to the room host and to any trusted moderator the host has invited, and to nobody else. The captured messages are deleted as soon as the report is marked handled, and every report disappears with the room.
Your choices and requests
You can clear this site's browser storage at any time to remove local preferences, your crew history, your room credential, and your random player ID. This also clears your saved purchase access. A purchase itself is never lost: it can be restored with the transaction ID and email from your Paddle receipt, so keep that receipt.
You can avoid analytics using your browser's privacy controls.
To ask what the game holds about a purchase, to have it corrected, to receive a copy of it, or to request erasure, write to support@whydyousaythat.com with the transaction ID from your Paddle receipt. Requests are answered within 30 days. Clearing the game's temporary cache does not erase Paddle's records or cancel the purchase; a later restoration can verify it with Paddle again. Requests about payment, invoicing, or your Paddle account are handled by Paddle through the support link on your receipt.
Children
The game is not directed at children. It is not intended for anyone under 13, or under 16 in the United Kingdom, the European Economic Area, and other countries whose law sets that higher age. Information from children under those ages is not knowingly collected. If you believe a child has used the game and left information behind, write to support@whydyousaythat.com and it will be removed.
Changes to this policy
This policy may be updated as the game changes. The effective date at the top of this page always shows the current version, and a material change is announced in the game before it takes effect.