Wherestan

Privacy Policy

This policy covers the Wherestan website at wherestan.com and its API. Wherestan is operated by Burak Ozdemir, a self-employed trader (autónomo) established in Spain, at Calle Puerto 14, 5th floor, 29016 Málaga, Spain. The operator ("we") is the data controller for the information below. Contact us at [email protected] about your information or this policy.

What we collect

  • Playing without an account. To score a guess, your browser sends our server the date, the country that you guessed and the countries that you already guessed that day. When you lose, it sends the date and your six guesses, so that the server can show the answer. The server sends back the result. When you are not signed in, the server does not save your guesses. Your game history stays in your browser (see "Your games in this browser").
  • Technical information. When you open a page, our server keeps a session record. It holds a random session ID, your IP address, the user agent that your browser sends (the browser and device type), a security token, the address of a page that you opened, the time of your last request and, during a Google sign-in, a random check value, the page language and the selected game. When you are signed in, it also holds your account ID, how you signed in and a check value made from your password hash. When a form shows an error, it also holds what you typed in that form, apart from passwords, until your next request. Requests can also include error or security details, which our server and Cloudflare process.
  • Abuse protection. Our server counts the requests from each IP address, or from each account when you are signed in, to limit how many it accepts. It stores these counts under a hash of the IP address or the account ID. To stop password guessing, it also counts failed sign-ins for each email address and IP address, and it stores these counts under a hash of the email address and the IP address. All these counts expire after one minute.
  • Accounts. Your email address, your username, a hash of your password, a random token for the sign-in cookie, and the times when the account was created and last changed. We never store the password itself. When you choose a password, we check it against passwords known from data leaks with the Have I Been Pwned service. Only the first five characters of a SHA-1 hash of the password leave our server; the password itself never does. Accounts have no name field: we do not ask for your real name, and we do not store it. If you sign in with Google, Google sends us your Google account ID and your email address, and we store them to link your Google account. We do not ask Google for your name or profile photo, and we do not store them. We never receive your Google password. An account made with Google gets a random password that nobody knows ("Forgot password?" sets a new one) and a generated username, which you can change one time. A username that you choose when you sign up with email cannot be changed.
  • Your games on an account. While you are signed in, our server records each game that you begin: the date, each guessed country in order, whether it was correct, the time of each guess, the result, the number of guesses and whether the game can count for the leaderboard. Countries also records the distance of each guess from the answer and the total distance of wrong guesses. Flags records each guess's match percentage and the flag artwork and scoring versions. A game that you began while signed out is not recorded. We use the recorded games for each game's leaderboard and best ranked streak, which is the most days in a row with a recorded win. The Countries best ranked streak is also stored with your account. Your day records (see "Your games in this browser") are copied to your account as your browser keeps them, so that you can see them on other devices.
  • Pro Unlimited. If you play Unlimited rounds, which need Pro, our server records each Unlimited round that you begin: the game, the hidden country, each guessed country in order with its result, the state of the round and its times. It also keeps the result of each request, so that a repeated request gets the same answer. If you get Pro, our server stores a record of it: the product, the store and its purchase reference, its state and its end dates. Each account has a random purchase ID that links an App Store purchase to the account.
  • Payments for Pro. On the website, you buy Pro from Paddle.com, our online reseller and the merchant of record, which takes the payment. Paddle and we are independent controllers: each of us decides how it uses your information. Paddle's Privacy Notice covers the payment details that you give Paddle, such as your card and your billing address; we never receive your full card number. When you continue to payment, our server sends Paddle your email address and your account ID, so that the purchase reaches your account. Paddle's checkout can show an optional box for marketing emails; Wherestan sends no marketing email. Paddle then sends us notifications about your purchases. Our server stores each notification in encrypted form, without the payment method details; a notification can hold what Paddle holds about you as a customer, such as your email address, your name if you give it, your country and your postal code. Our server also keeps your Paddle customer ID with your account ID, and a record of each transaction: its status, product, amounts, tax, refunds, currency and dates, and the state and dates of a subscription. Before you pay, you tick a box to agree to the Terms and the Refund Policy and to ask for Pro to start at once; our server keeps a record of it: your account, the product, the version of the text, the time and the Paddle transaction. If you switch from a subscription to the one-time purchase, our server creates a one-use discount in Paddle for the unused time of your plan, and keeps a record of the switch: the subscription that it replaces, the credit, the currency and the Paddle transaction. In the Wherestan iPhone app, you buy Pro through Apple's App Store. RevenueCat receives the purchase from Apple with your random purchase ID. Our server reads your purchases from RevenueCat with that ID, and stores RevenueCat's notifications about them in encrypted form.
  • Sign-in through our API. Our API lets an app make an account, or sign in to your account, with an email address and password. For each device that signs in, our server stores a hash of an access token, the device name that the app sends, and the times when the token was made and last used. The token is not an advertising identifier.
  • What we do not collect. We do not need your location, contacts, photos or advertising identifier. The distance and direction of each guess are measured between two countries, not from where you are. Our pages tell your browser to block camera, microphone, location and payment access.

Your games in this browser

Wherestan saves your games in your browser's local storage, not in cookies:

  • wherestan:day:YYYY-MM-DD: one Countries record for each day that you play. It holds the date, each guess in order with its clue tiles, distance and direction, the result, and the answer after the game ends.
  • wherestan:flags:day:YYYY-MM-DD: one Flags record for each day that you play. It holds the date, each guess and its match percentage, the accumulated revealed pixels and percentage, the artwork and scoring versions, the result, and the answer after the game ends.
  • wherestan:theme: your theme choice (light, dark or system).
  • wherestan:seenHowToPlay: shows that you closed Countries How to play, so that it does not open by itself again.
  • wherestan:flags:seenHowToPlay: the separate How to play choice for Flags.

Your statistics (games played, win rate, streaks and guess distribution) are calculated from the day records. Wherestan never deletes these records. It changes a record only to add to it, for example a new guess or the answer. The records stay until you clear your browser data. After that we cannot restore them, unless your account has a copy. If your browser blocks local storage (some private windows do), you can still play, but nothing is kept in this browser after the visit.

When you are not signed in, our server does not receive these records. When you are signed in, the day records in this browser are copied to your account, and the day records of your account are copied to this browser. This happens when a page loads, when you sign in and after each guess. A saved day is never replaced by a record that does not add to it. Signing out removes nothing from this browser: the days of the account stay here, count in the statistics that this browser shows when nobody is signed in, and are copied to the next account that signs in on this browser. On a shared browser, days played with one account can therefore join another account.

Cookies

The website sets these cookies:

  • wherestan-session: connects your requests to your session record (see "What we collect"). It expires 2 hours after your last request.
  • XSRF-TOKEN: a security token that protects the site against cross-site request forgery. It expires 2 hours after your last request.
  • remember_web_…: keeps you signed in on this browser after the session ends. It holds, in encrypted form, your account ID, the random token for the sign-in cookie and a check value made from your password hash. It is set each time you sign in, and it expires after 400 days. Signing out removes it.

These are session, sign-in and security cookies. The website sets no advertising cookies and no analytics cookies. Cloudflare, which delivers the website, can set its own security cookies, such as __cf_bm when its bot protection is on.

Analytics

The production website loads Ahrefs Web Analytics to measure visits in total. Ahrefs describes this service as using no cookies or persistent identifiers, while processing IP address and browser information to measure visits. Ahrefs lists the data that it collects as the page address, the referring page, the user agent, the location (country and city) and the language, together with page views, link clicks and form submissions. The script does not load on the password-reset page, because the address of that page holds your reset link.

Why we use information

  • To run the game that you ask for: to score your guesses, show the answer after a loss and keep your settings.
  • To run your account: to sign you in, keep your games on your account and send the password-reset mail that you ask for.
  • To sell Pro and give it to your account: to take payments through Paddle or the App Store, to check which purchases your account has, to answer questions about a purchase, to prevent fraud, and to keep records of purchases, consents and refunds as proof of purchase and for accounting and tax duties. We need this information for our contract with you and for our legal duties.
  • To show the public leaderboard (see "Sharing and the leaderboard").
  • To keep the site secure and reliable, which is our legitimate interest: session records, security tokens, request limits and server logs.
  • To count visits in total (see "Analytics").

We do not use your information for advertising, and we do not sell it. The site shows no ads.

Service providers

We use service providers for hosting, storage, delivery, email, security and payments:

  • Our hosting provider runs the server and its database, and our backup storage provider keeps the database backups; both hold the information above.
  • Cloudflare delivers the website and protects it against attacks. Every request goes through Cloudflare, which processes your IP address and the request details.
  • Resend sends the password-reset mail. It receives your email address and the content of the mail, which holds your reset link.
  • Google handles "Continue with Google". Google's own privacy policy applies to your Google account.
  • Ahrefs provides the analytics described above.
  • Paddle.com sells Pro on the website as the merchant of record and takes the payment. It receives your email address and your account ID from us, and the payment details that you give it. Paddle's Privacy Notice applies to that information. Paddle's companies in the UK, the US, Ireland and Canada can process it, under standard contractual clauses.
  • RevenueCat processes App Store purchases for us. It receives your random purchase ID and the purchases that Apple reports for it.
  • Apple takes the payment for a purchase in the App Store. Apple's own privacy policy applies to it.

Apart from the Ahrefs script and Paddle's checkout, your browser loads the website only from wherestan.com. Otherwise we do not load fonts, images or scripts from other companies. When you continue to payment, or open a payment link from a Paddle email, your browser loads Paddle's checkout from Paddle. Manage Pro opens Paddle's customer portal. These providers can process information outside your country. Applicable data-protection requirements apply to such transfers.

Sharing and the leaderboard

The Share button opens your device's share menu or copies a text. The text has the day number, your score and the game's Wherestan address. An Unlimited round's text has the game and the word Unlimited instead of the day number. Countries includes a grid of squares and circles; Flags includes the match percentage for each guess. It does not include the answer or any account details. It goes only where you send it.

Each game has a public leaderboard. In Countries, the daily board shows your username, your number of guesses, the total distance of your wrong guesses and the time between your first and last guess. The Flags daily board shows your username, your number of guesses and the time between your first and last guess. The all-time board shows your username, your best ranked streak and your number of ranked wins. These figures are separate for each game. The leaderboard never shows your email address or account ID. Only wins that our server recorded while you were signed in count. We can hide a player from the leaderboard; the account and its data stay. A hidden player can take up to 5 minutes to leave the leaderboard. Choose a username that you are happy to show in public.

Retention and deletion

  • Data in your browser stays there until you clear it. Wherestan never deletes it.
  • Session records are deleted automatically after 2 hours without activity. The cleanup runs on about 2 in 100 requests, so a record can stay longer.
  • Request counts expire after one minute.
  • We do not store the guesses of players who are not signed in, so we hold no game history for them.
  • We keep your account data while your account exists.
  • A password-reset link works for 60 minutes. When you ask for a link for your account, we store your email address, a hash of the link's token and the time. This record stays until you use the link, ask for a new one or delete your account. The mail waits in our server's queue, in encrypted form, until it is sent. A mail that cannot be sent stays on our server, in encrypted form, until we remove it. Its error text is kept with it; that text is not encrypted and can name your email address.
  • An API access token stops working 180 days after it was made. Its record is deleted when the app signs out on that device or on all devices, when a device with the same name signs in again, when you reset your password or when you delete your account.
  • We keep Pro records, the link between your account and your Paddle customer, transaction and consent records, records of switches to the one-time purchase and the notifications from Paddle and RevenueCat as proof of purchase and for accounting and tax duties. They stay after you delete your account.
  • Other technical records, such as server logs, and backups have separate operational retention needs, including security, recovery and any applicable legal obligations.

You can delete your account in Account, or through our API. To confirm, you type your username. This deletes your account (email address, username and password hash), your Google link, the copies of your days on your account, the games and guesses that our server recorded (so you leave the leaderboard), your Unlimited rounds, your API access tokens, all your sign-in sessions and a password-reset request that you did not use. You cannot undo this. A Pro record stays without your account, as proof of the purchase. Your Paddle customer link, your transaction and consent records, your switch records and the payment notifications stay too. Deleting your account does not cancel a Pro subscription: cancel it first in Manage Pro, or on your iPhone in Settings. The leaderboard can still show your username for up to 5 minutes. Backup copies may remain until those backups are replaced. The days saved in each browser stay there; you can remove them in your browser settings. Signing out does not delete your account.

Your rights

Depending on the law that applies, you can request access to your information, and its correction, deletion, restriction or portability, or object to how we use it. Contact [email protected]; we may need to verify the requester's identity. You can also complain to your local data-protection authority, including Spain's AEPD.

You can play without an account. You can clear the site's data in your browser settings at any time. This deletes your game history in that browser.

Accounts are not intended for children under 13 or a higher minimum age required where they live; contact us if such a child has provided account information.

Changes

We update this policy when what we collect, or how we use it, changes. The date below shows the last change.

Last updated: 2026-10-09