Privacy Notice
How WordWarren handles personal information on the website, apps and multiplayer service.
Effective 23 August 2026 · Version 2026-08-23
1. Controller
Myriad Monitor Limited is the controller of personal information used to operate WordWarren, except where another organisation acts as an independent controller for its own service (for example an app store or payment provider).
Registered office: 182 Longwood Road, Huddersfield, HD3 4EJ.
Privacy enquiries and rights requests: privacy@myriadmonitor.com.
2. Information we collect
- Account data: name, email address, password hash, player handle, avatar/appearance preferences, account status and legal-acceptance records.
- Game data: games joined, board state, moves, racks held by the server, scores, results, turn timing, AI interactions and game settings.
- Multiplayer data: invitations, challenges, matchmaking entries, recent opponents, blocks, reports and game chat.
- Commercial data: Pro status, content entitlements, purchases, discounts, Warren Keys, referral records, Stripe/customer identifiers and app-store entitlement information. We do not need to store your full payment-card number when a payment provider handles it.
- Device/API data: login/session records, mobile API tokens, push-notification device tokens, app version and security-related request information.
- Technical data: IP address, browser/device information, logs, error reports and security/audit events where needed to operate, protect and diagnose the service.
- Preferences/consent: cookie choices, advertising/analytics choices and other privacy settings where offered.
3. Why we use it and our legal bases
- To provide the service and perform our contract: create accounts, run games, validate moves, provide multiplayer, deliver Pro/content you buy, process entitlement changes and provide support.
- Legitimate interests: keep the service secure, prevent cheating/fraud, improve reliability, operate basic service analytics, investigate abuse, administer the platform and understand aggregate product performance where those interests are not overridden by your rights.
- Legal obligation: accounting, tax, consumer-law records, responding to lawful requests and other obligations that apply to us.
- Consent: where required for non-essential cookies, targeted/behavioural advertising, optional analytics or other processing for which consent is the appropriate legal basis. You can withdraw consent without affecting processing already lawfully carried out.
4. Other players
Other participants may see your player name/handle, avatar, score, game result and messages you send in their game. Your rack is not intentionally disclosed to opponents during an active remote game. A block prevents future interaction/matching as implemented by the service, but information already shared in a completed game may remain in game records.
5. Payments
Website payments may be handled by Stripe. Stripe receives payment and transaction information needed to process the purchase and may act as an independent controller or processor depending on the activity. Purchases made through Apple, Google or another app marketplace are also subject to that provider's privacy practices.
6. Advertising and analytics
Free WordWarren may contain advertising. Non-essential storage/access technologies used for advertising or measurement are not activated until the required consent has been obtained. We prefer contextual or minimally intrusive advertising where practical. Profiling or personalised advertising for children must not be enabled merely because an adult user could consent to it.
See the Cookie Notice for the current categories and controls.
7. Children and age-appropriate design
WordWarren is a game and may be accessed by younger users even where they are not the primary commercial audience. We therefore design privacy and safety controls with age appropriateness in mind. This includes minimising data, using privacy-protective defaults where appropriate, restricting adult-labelled content, and avoiding targeted advertising to children unless it is demonstrably lawful and appropriate.
Where a feature creates materially different privacy risks for children, we may require age assurance, restrict that feature, or apply the child-protective setting to all users where age cannot be established appropriately.
8. Who we share information with
We share personal information only where needed for the purposes described above, including with infrastructure/hosting providers, email and notification providers, payment processors, app stores, security/monitoring suppliers, advertising/analytics providers where enabled, professional advisers, and public authorities where required by law. We do not sell personal information to advertisers.
9. International transfers
Some suppliers may process information outside the UK. Where UK data-protection law requires safeguards for an international transfer, we use an appropriate mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement/Addendum, or another lawful safeguard.
10. Retention
We keep information only for as long as reasonably needed for the purpose for which it was collected and any legal, security or dispute requirements. Typical principles are:
- active account/profile data: while the account remains active;
- game/results history: while needed for player history, rankings, fraud/abuse handling and service integrity, with deletion/anonymisation where appropriate;
- payment/accounting records: for the period required by tax/accounting law;
- security/audit records and logs: for a proportionate period based on risk;
- push tokens/API tokens: until revoked, expired or no longer associated with an active device/session.
We will maintain a more detailed internal retention schedule as individual processors and operational requirements are finalised.
11. Security
We use measures including password hashing, access controls, server-authoritative game state, rate limits, secure session/API-token handling, payment-webhook verification, logging and administrative audit controls. No internet service can promise absolute security, so we also maintain incident-response and recovery procedures.
12. Your rights
Depending on the circumstances, UK data-protection law gives you rights to access personal information, correct it, request erasure, restrict or object to processing, receive certain information in portable form, and withdraw consent. You may also have rights relating to solely automated decisions where applicable.
We may need to verify your identity before fulfilling a request. Some information cannot be deleted immediately where we have a legal obligation or a compelling lawful reason to retain it, such as transaction records or evidence needed to protect users against abuse.
13. Complaints
Please contact us first so we can try to resolve a privacy concern. You also have the right to complain to the UK Information Commissioner's Office (ICO) or, where applicable, another competent supervisory authority.
14. Changes
We update this notice when the service, suppliers or legal requirements materially change. The current version/effective date is shown at the top. Material changes may also be highlighted in-product.