← Back to Game

Privacy Policy

Last updated: March 25, 2026. This policy explains what data The 2048 League collects, why we collect it, and how we protect it.

What We Collect

Account Information

When you create an account, we collect your email address and an optional username. We use your email to send a one-time verification code for sign-in. We do not collect passwords because we use a passwordless authentication system.

Game Data

We store your scores, grid size, and the date each score was submitted. In multiplayer, we also track your ELO rating, wins, losses, ties, and total games played. This data powers the leaderboard, your stats page, and ranked matchmaking.

Session Data

When you sign in, we create a session that includes your IP address and browser user agent. This is used to maintain your login state and protect against unauthorized access. Sessions expire automatically.

Local Storage

We store some data locally in your browser, including your theme preference, personal best scores, and recent game history. This data never leaves your device unless you are signed in and submit a score.

What We Do Not Collect

  • We do not use analytics or tracking scripts (no Google Analytics, no Meta Pixel, no third-party trackers).
  • We do not sell, rent, or share your personal data with advertisers.
  • We do not collect payment information. The game is free.
  • We do not store passwords. Sign-in is handled via one-time email codes.

How We Use Your Data

  • Authentication: Your email is used to send sign-in codes and verify your identity.
  • Leaderboards: Your username and scores are displayed publicly on the leaderboard.
  • Matchmaking: Your ELO rating is used to pair you with opponents of similar skill in ranked multiplayer.
  • Stats: Your game history is used to calculate and display your personal statistics.

Third-Party Services

We use the following third-party services to operate The 2048 League:

  • Supabase for database hosting and authentication infrastructure. Your account and game data is stored in a Supabase-hosted PostgreSQL database.
  • Resend for email delivery. When you sign in, Resend sends the verification code to your email address. We do not use email for marketing.
  • PartyKit for real-time multiplayer connections. During a multiplayer match, your game state is transmitted via WebSocket to coordinate gameplay with your opponent.
  • Google Fonts for loading typefaces used on the site. Google may collect basic request data (IP address) when fonts are loaded.

Cookies

We use HTTP-only session cookies to keep you signed in. These cookies contain a session token and are not used for tracking or advertising. They expire when your session ends or after a set period of inactivity.

Data Security

All database tables use Row Level Security (RLS) policies, which means users can only read and write their own data. Scores and usernames on the leaderboard are publicly visible by design. All connections to our services use HTTPS encryption.

Playing as a Guest

You can play single-player and friendly multiplayer matches without creating an account. Guest players do not have any data stored on our servers. All game data for guests is kept locally in the browser and is never transmitted.

Your Rights

You can request deletion of your account and all associated data at any time by contacting us. Once deleted, your scores will be removed from the leaderboard and your account data will be permanently erased from our database.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated date at the top. Continued use of The 2048 League after changes are posted means you accept the updated policy.

Questions?

If you have questions about this policy or your data, reach out to us.

📱

Please rotate your device to portrait mode