Privacy
The short version: no ads, no third-party analytics or tracking scripts, and nobody needs an account to play a gift. Here is what the code actually does.
What gets stored
Gifts live in a Cloudflare D1 database: the title, concept or brief, recipient and sender names, your note, the game's HTML, an optional reserved name and, where a flow asks for it, a recipient email address. Each gift keeps its latest five revisions; older snapshots are discarded as new ones arrive. Exports leave out the email address, private link tokens and payment data. Gift content is never committed to a public code repository.
Every gift has private links: a management link for the creator, a read-only preview link and, after a test payment, a recipient link. Anyone holding a link can open it, so share them deliberately. Reserved names are guessable and aren't secret.
Quotas and traffic limits
To enforce daily draft and build allowances, the app stores a SHA-256 hash of your IP address combined with the current UTC day, not the raw address. Cloudflare's rate limiters count requests per IP address to slow abuse. The Worker's own logs are sampled (about one request in ten) with query strings redacted, and error diagnostics record a stage and error category, never your brief.
Cookies and browser storage
pg_creator is an HttpOnly cookie set when the site saves a gift you made in that browser, or when you claim one. It holds a random token, stored only as a hash on our side, so the My gifts page can list the gifts made in that browser. It lasts a year, isn't an email login and doesn't follow you to another device. pg_operator is an HttpOnly session cookie for the site operator only, valid for 12 hours. The homepage also keeps the key of an in-progress build in your tab's session storage so a reload can recover it.
Who else processes data
- Cloudflare hosts the site, the database and the logs. When in-site generation is switched on, your brief is sent to Cloudflare Workers AI through an AI Gateway with request logging disabled, and Cloudflare Workflows keeps the build job's state, including the brief, for up to a day. Generation is currently paused.
- Stripe runs checkout in test mode only. Card details go to Stripe's hosted page, not to us. We store the checkout session ID, amount and payment status, and send Stripe only the gift's internal ID and a generic product name.
- Resend sends email. Delivery is off by default and, when on, can only reach Resend's test inbox (delivered@resend.dev). No recipient is emailed.
Inside the games
Games run in a sandboxed frame with network access blocked, so a game can't send what you type or do anywhere.
Operator access and retention
The site operator can sign in to an operations view of stored gifts for support and abuse checks. That view leaves out recipient emails, private link tokens and payment secrets. Operator sign-ins and gift claims are written to an audit log. The operator may keep private database backups for recovery. There isn't a self-serve way to delete a gift yet, and a formal retention and deletion policy hasn't been published.