Playable Gift

Privacy

The short version: no ads, no third-party analytics or tracking scripts, and nobody needs an account to play a gift. Here is what the code actually does.

What gets stored

Gifts live in a Cloudflare D1 database: the title, concept or brief, recipient and sender names, your note, the game's HTML, an optional reserved name and, where a flow asks for it, a recipient email address. Each gift keeps its latest five revisions; older snapshots are discarded as new ones arrive. Exports leave out the email address, private link tokens and payment data. Gift content is never committed to a public code repository.

Every gift has private links: a management link for the creator, a read-only preview link and, after a test payment, a recipient link. Anyone holding a link can open it, so share them deliberately. Reserved names are guessable and aren't secret.

Quotas and traffic limits

To enforce daily draft and build allowances, the app stores a SHA-256 hash of your IP address combined with the current UTC day, not the raw address. Cloudflare's rate limiters count requests per IP address to slow abuse. The Worker's own logs are sampled (about one request in ten) with query strings redacted, and error diagnostics record a stage and error category, never your brief.

Cookies and browser storage

pg_creator is an HttpOnly cookie set when the site saves a gift you made in that browser, or when you claim one. It holds a random token, stored only as a hash on our side, so the My gifts page can list the gifts made in that browser. It lasts a year, isn't an email login and doesn't follow you to another device. pg_operator is an HttpOnly session cookie for the site operator only, valid for 12 hours. The homepage also keeps the key of an in-progress build in your tab's session storage so a reload can recover it.

Who else processes data

Inside the games

Games run in a sandboxed frame with network access blocked, so a game can't send what you type or do anywhere.

Operator access and retention

The site operator can sign in to an operations view of stored gifts for support and abuse checks. That view leaves out recipient emails, private link tokens and payment secrets. Operator sign-ins and gift claims are written to an audit log. The operator may keep private database backups for recovery. There isn't a self-serve way to delete a gift yet, and a formal retention and deletion policy hasn't been published.