Privacy policy
Dailies stores the puzzle results you choose to log and the account details needed to keep them yours. This page lists exactly what that is, who can see it, and how to get rid of it.
The short version
- Dailies is run by Helvetica Labs, Inc. There are no ads, no tracking pixels, and nothing about you is sold or rented to anyone. Page views are counted with Vercel Web Analytics: anonymous aggregated stats, no cookies, not tied to your account. Addresses that could sign somebody in are stripped before a view is recorded.
- Most people sign in with a phone number. We store that number, the account details you give us, the share texts you paste or send in, and the scores read from them.
- A new account starts on a waitlist. We store who invited you, and we text you once when you are let in.
- Your profile page is private. You can see it, and so can people in a group with you. It becomes a public page only if you publish a game. Your results are also visible to people in your groups on the group page itself. A group’s text thread is a real Messages group, so the people in it see your number and what you write.
- Email is used for confirming your address, recovering the account, and telling you that you are off the waitlist. Never for marketing.
- Delete the account under Settings, or write to info@dailies.world.
What we store
Account. Your email address (or a stand-in address if you signed in with a phone and have not added one), username, display name, whether the email has been confirmed, and the dates the account was created and last changed. A password, if you set one, is stored as a salted hash and never in plain text. The time zone your browser reports is saved so server-rendered pages know which day is “today” for you. The visual skin you last chose, and any rare skins you unlocked by pasting their phrase, sit on the account. Each device keeps its own skin, so every pick is logged with the device it was made on: a random device identifier, whether it was the website or an app, and the device type, operating system and browser family. Nothing more specific about the device is kept. So does whether you have been shown the welcome dialog, and until when Today should hide the set-up checklist.
Phone. The number you sign in with, in E.164, and whether it has been confirmed — by a code we texted, or by you texting us first from that number. A number belongs to one account.
Waitlist and invites. Whether the account is still waiting or has been let in, when it joined the queue and when it came off, who invited it, how many invites it has left, the short code on its own invite links, and, if it signed up from a group invite while still waiting, which group it will land in. When the “you’re in” text has gone out is recorded so it is not sent twice.
Sign-in sessions. Each sign-in creates a session record with a random token, the IP address and browser identifier it was made from, and an expiry. A session lasts seven days and is extended while you keep using it. Signing out or changing your password ends sessions.
Rate limiting. Requests to the sign-in, password reset and email confirmation endpoints are counted per IP address so they cannot be flooded. The counters hold the address, the endpoint and a count.
Results. For every result you log: the game, the puzzle number and date, whether you solved it, the score, the emoji grid, when it was logged, and how it arrived (paste, by hand, or reported by a game). The share text itself is kept alongside, so a result can be re-read if a parser improves. Results logged by hand carry no share text.
Statistics. Per game we keep the totals shown on your Stats page: games played, wins, current and best streak, score averages and the guess distribution. They are recomputed from your results and hold nothing that is not already in them.
Your lineup. Which games you play, and in what order, so Today knows what to show.
Plays of games on Dailies. When you finish a game that runs on Dailies itself, such as Landmarkr or a game built in the editor, we record the game, the puzzle day, whether it was solved, the score and, for games that report it, which of its questions were answered correctly, so each day’s results chart counts everyone who played. A play while signed in is recorded under your account and deleted with it. A play while signed out is recorded under a random identifier from a cookie, which is not linked to anything else about you. The game’s creators see these plays only as totals. For Landmarkr we also keep an in-progress game (your guesses, whether hints are on, whether you have finished) so you can pick it up later; that row is yours and goes with the account.
Visits to games built on Dailies. When someone opens a published game built in the editor, we record the time, the country our hosting provider places the request in, whether it came from a desktop, phone or tablet, the browser and operating system, and the domain of the site that linked to it. No address, cookie or other identifier is kept with it. The game’s creators see these visits only as totals.
Groups. A group’s name, slug, who owns it, who is in it and since when, which games it plays, and the invite code and when it expires. When an owner removes someone, that is recorded so the invite link no longer admits them. Morning-text cadence for the group is stored on the group.
API tokens. Tokens you create under Settings for the extension, the phone app or your own scripts are stored as a hash together with the name you gave them, their first few characters, when they were created, when they were last used, and when they expire. The token itself is shown once and cannot be recovered by us.
Unrecognised share texts. When a paste is not recognised, the box offers to send it in so a parser can be written. Only if you press that button is the text stored, together with your account, so abuse can be traced. Nothing is sent in on its own.
Games you create. If you add a game to Dailies, its name, description, scoring rule, look, address, allowed origins and, for a game built in the editor, its code and each day’s puzzle content are stored under your account. Other people you invite as editors are stored too, with whether they have accepted and whether the invite has been texted.
AI edits. Building a game from a description, or changing one from the editor chat, is counted against the week’s allowance. We store that it happened, which game, and when — not the prompt — so the meter under Settings is honest.
Billing. If you open checkout, we keep Stripe’s customer id for your account, the current subscription status, the price you are on, when the period ends, and which paid features Stripe says you hold. Card numbers never reach us. An operator can also grant a feature by hand; that list sits on the account, separate from Stripe.
Push notifications. If you allow them on the iPhone app, we store the device token Apple issued, which of Apple’s two gateways it belongs to, and a name for the install.
Operator logs. People who run Dailies keep a record of admin actions (who did what to which account or game — a username or a slug, never an email or a number) and of whether scheduled jobs ran (counts and a one-line status, no payloads). Those are not shown to other users.
Cookies and what stays on your device
Dailies sets these cookies, all first-party and none for advertising:
- A session cookie that keeps you signed in.
- A
dailies_playercookie holding a random identifier, set when you finish a game on Dailies while signed out, so the same play is not counted twice. - A
tzcookie holding your time zone, so pages rendered on the server show the right day. - A
dailies_join_linkcookie, set only on invite pages, holding the id of a join that started by text. It lasts a week and never leaves/join. The id is moved out of the address bar before the page is drawn, so a sign-in link is not sitting in history or in analytics. dailies-skinanddailies-device-skincookies holding the skin picked on this device, so a page opens in it without a flash, and adailies-devicecookie holding a random identifier for the device, set the first time you pick a skin signed in. They last a year (the identifier two).- A short
dailies-bootedcookie after a rare skin’s start-up animation, so it does not play again in that browser session. - Short-lived cookies during a Google or Apple sign-in that protect the hand-off from being forged. They are gone once you are signed in.
The browser’s own storage remembers two things that never leave it: which set-up steps you have ticked off on the Today page, and whether clipboard auto-capture is switched on.
Fonts are bundled with the site and served from the same place as everything else, so no font provider sees your visit. The only extra script is Vercel Web Analytics, served from this site; it does not set cookies.
Clipboard, extension and phone app
Each way of getting a result in touches a different amount of your device. In every case only puzzle share text reaches Dailies.
Paste. Only what you paste is read.
Clipboard auto-capture. Off unless you switch it on under the paste box. When on, each time the Today tab comes back into view the page reads the clipboard once, in your browser. Text that does not parse as a game result is discarded on the spot and never sent anywhere. Turn it off with the same switch, or by revoking the clipboard permission in the browser.
Browser extension. It runs only on the game sites listed in its manifest. On those pages it sees the text a game hands to the clipboard or the share sheet, and forwards only text that begins with a share header it knows to your Dailies address using your token. It does not read anything else on the page, your browsing history, or other sites. Your address, token, a queue of results that could not be sent yet and a short log of recent captures live in the extension’s local storage on that computer, never synced. Connecting it works by a short code: the extension asks us for one, you approve it here while signed in, and the token it collects is the same kind you can create and revoke under Settings. The code and the secret that goes with it are kept for ten minutes at most and deleted the moment the token is collected. Once a day the extension also asks us for the current list of games and game sites it should watch; that request carries no token and nothing about you, and the answer only ever narrows what the extension sends. When that list names a site the extension does not yet cover, it asks you before running there. The extension’s use of what it collects is limited to logging your puzzle results; it is not used for anything else and not shared with anyone else.
iPhone app. The app shows the website and adds Dailies to the share sheet. Its token is kept in the device keychain. The share extension sends the text you share, and nothing else, to your account. The native app and share extension contain no analytics or advertising code of their own; the website they show uses the same Vercel Web Analytics as the rest of Dailies.
Android share sheet and shortcuts. These send the text you chose to share, and nothing else.
Texts
The program itself — what we send, how you opt in, STOP / START / HELP — is in the SMS terms. This section is only what we keep.
Group text threads. A group can have a text thread with Dailies in it, which starts as your own conversation with us and becomes a group chat as members join. For one we keep the thread’s identifier, the number it is on, whether it is iMessage, RCS or SMS, when it started, and when each member first texted us, joined it, or walked out of it in Messages. So that a reply makes sense in context, the most recent messages in the thread are kept — about two dozen, after which the older ones are deleted — and they are sent to Anthropic, which writes the reply and does not train on them. When the thread outgrows what it can read, a short summary is kept for the model only and is never sent to anyone. Nothing is kept from a thread on a deployment with no assistant configured.
Morning texts and reminders. Whether a group wants a morning text in its group chat daily, weekly or off, and the local date of the last one, so a retry cannot send it twice. A reminder you asked the assistant to send later is stored with the chat, the number, what to say and when; it is marked sent so it goes once, and it is never sent to a number that has since asked us to stop.
Joining by text. Texting an invite code from a number we do not know yet is stored as a short-lived claim: the number, the group, and the conversation it arrived in. The link we text back names that claim. Once you finish joining, or after a week, it is gone.
Numbers nobody claims. If someone is added to a group chat from Messages and has no Dailies account, we keep that number on the group so the page can say who is in the chat but not on the board, and so the nudge to sign up is said once.
Games built over text. Asking the assistant to make or change a game writes down the request, the chat it came from, and how far the build got, so it can finish after the reply has already gone out.
Opting out. If you ask us to stop texting you, your number is recorded so that we do not, and you are taken out of the threads you were in. The list is by number, not by account: someone who deletes the account, or never finished signing up, still must not be messaged. The message that opted you out is kept so a dispute can be answered.
Who can see what
Your profile is private unless you publish a game. Until then only you and people in a group with you can open it. Anyone else, signed in or not, is told the page does not exist. Publishing a game on Dailies makes the profile a public page: anyone can see your name, the games you play, how many times you have played each, your solve rate and streaks, and your most recent results. Unpublishing the last one takes it private again. Use a name you are happy to be seen by.
Groups. Members of a group see each other’s results for the games it plays. A score shows on the site as soon as it is logged, including for games you have not played yet; a score posted in the group’s text thread is posted to everyone in it. Group pages are only visible to members. An invite link, though, shows the group’s name and its members to whoever opens it, signed in or not, so share it with care.
Group chats. A group thread is a Messages group. Everyone in it, including people with no Dailies account who were added from Messages, can see the numbers and the messages. That is how group chats work; it is not something Dailies can hide.
Nobody else. Your email address, IP address and share texts are never shown to other users. We do not sell, rent or trade personal data, and we do not share it with advertisers.
Services we rely on
These companies process data on our behalf, each only as far as its job requires:
- Vercel hosts the site and serves every request, so it sees the IP address and headers of each visit as any web host does. It also runs Web Analytics, which records anonymized page views (path, referrer, country, browser and device type) without cookies or a link to your account. Query parameters that could sign somebody in are stripped before a view is sent. Vercel’s privacy policy.
- Turso stores the database. Turso’s privacy policy.
- Resend delivers confirmation, password-reset and waitlist emails, and therefore sees your address and the contents of those messages. Resend’s privacy policy.
- Linq carries the text messages: a group’s thread, a sign-in code, the “you’re in” text, morning reminders, and anything you send us. It therefore sees your number and what is written in the thread, as any messaging carrier does. Linq’s privacy policy.
- Twilio sends the sign-in code on deployments that use it instead of Linq for that one text. It sees the number and the code. Twilio’s privacy policy.
- Anthropic writes Dailies's replies in a thread, and helps build or change a game when you ask in the editor or over text. It receives the recent messages in that thread (or the build request) and the first names of the people in it, and returns the reply. It does not train its models on what we send. Anthropic’s privacy policy.
- Stripe processes Pro payments if you choose to pay. It sees the email and payment method you give it at checkout; we see only the customer and subscription identifiers described above. Stripe’s privacy policy.
- Google and Apple are involved only if you sign in with them, as described below. Apple also delivers push notifications if you allow them on the iPhone app.
Most games are not part of Dailies. When you follow a Play link to one of them you are on that publisher’s site under its own privacy policy. Dailies never fetches puzzles, answers or your play history from them; it only reads the share text you bring back. A game made by Helvetica Labs, Inc., such as Landmarkr, or created by someone on Dailies, can instead run in a frame inside Dailies and report your result to it directly. The game itself still runs on its own site; what it reports to Dailies is stored as a result, as described above.
Signing in with Google or Apple
If you sign in with Google, we ask for your name, email address and profile picture and nothing more. They are used only to create your account, find it again on later sign-ins, and pre-fill your username, which you can change under Settings. The picture address is stored but not currently displayed. We keep the sign-in tokens Google issues so the link between the accounts keeps working; we never use them to read anything else from your Google account. Our use of information received from Google APIs is limited to providing and improving Dailies and follows the Google API Services User Data Policy, including its Limited Use requirements. You can cut the link at any time from your Google account permissions; set a password first if that is your only way in.
Sign in with Apple works the same way with your name and email. If you choose to hide your email, we receive the relay address Apple creates and our messages reach you through it. Apple sends your name only on the first sign-in.
How long we keep it
- Account details, results, statistics, group memberships, lineup, billing identifiers and tokens stay until you delete them or ask us to.
- A result can be removed from its game page at any time; its statistics are recalculated straight away.
- Sessions expire seven days after last use. Password reset links last an hour and email confirmation links a day, after which they are useless. A sign-in code expires in five minutes.
- An expired session record is deleted the next time it is presented. Rate-limit counters are kept so the limits hold across restarts; they contain only an address, an endpoint and a count.
- Unrecognised share texts you sent in are kept until a parser exists for them, or until you ask for them to be removed.
- Recent thread messages are pruned to about two dozen. The summary that replaces the older ones stays until the thread or the account is gone.
- A join-by-text claim lasts a week, or until it is used.
- A number on the opt-out list stays there so we do not text it again, including after the account is deleted, until you text START or ask us to take it off.
Deleting your account
Delete it under Settings, or write to info@dailies.world from the email or number on the account and say which account. We delete it within 30 days, together with every result, statistic, session, token, lineup entry, push token and group membership attached to it. A group you own passes to whoever has been in it longest; a group with nobody else in it is deleted.
Games you created are deleted, unless other people have logged results for them: those stay, with no owner. Unrecognised share texts you sent in lose their link to you rather than being deleted, since they are needed to write parsers and hold nothing personal; say so if you want them gone too.
A number that asked us to stop texting stays on the opt-out list after the account is gone, so we do not message it again. Stripe keeps whatever payment records the law requires it to; we delete our copy of the customer link with the account.
You can remove individual results from the game’s page, turn morning texts off, reply STOP, and revoke API tokens under Settings without asking anyone.
Your rights
Wherever you live you can ask us what we hold about you, have it corrected, receive a copy of it in a usable form, or have it deleted. Your email address, name, username, phone number and morning-text cadence can be changed under Settings; for everything else write to us. If you are in the European Economic Area, the United Kingdom or another place with a data protection authority, you can also complain to it.
Dailies is not aimed at children under 13 and we do not knowingly keep an account for anyone that young. If you think we have, tell us and we will remove it.
Changes to this policy
When this page changes, the date at the top changes with it. If a change means we would collect something new or show it to more people, we say so on the site before it takes effect.
Contact
Helvetica Labs, Inc. runs Dailies. For anything about your data, write to info@dailies.world. The rules for using the service, including texts, are in the terms of use.