Back to home

Privacy Policy

Last Updated: June 2026 Version: 1.1

This Privacy Policy explains how Brainstretch handles personal information when you use the public website, guest demos, and account-backed puzzle play.

Who We Are

Eyal Lapid is the data controller responsible for Brainstretch.

Information We Process

Public visitors and guest demos

When you browse public pages or play a guest demo, Brainstretch processes basic request and security data needed to deliver the service, protect the site, and troubleshoot reliability. This may include IP address, request timestamps, browser and device information, visited pages, referring URLs, and server logs.

Guest demo play does not create an account and is not saved as durable account progress. Demo state may exist temporarily in the active browser session so the game can run.

Brainstretch may also use first-party, privacy-friendly visitor analytics for public pages and guest demos, such as self-hosted Umami. Visitor analytics may process page URLs, referrers, approximate region or country derived from request data, browser, operating system, device type, visit timestamps, and basic event counts. We do not use visitor analytics for cross-site tracking, third-party advertising, or selling personal information.

Account-backed play

If you create an account, Brainstretch may store:

  • account identifiers such as your email address;
  • profile names and profile preferences;
  • saved progress, game history, race or challenge state, scores, and gameplay events;
  • display preferences and game settings;
  • support, privacy, security, or account-related communications;
  • security logs needed to protect accounts and the service.

Brainstretch also derives internal product analytics from account and gameplay records, such as active-user counts, signup counts, plays by game or state, per-game completion and win rates, race activity, and entitlement summaries. These analytics are used in aggregate for operations and product quality; they are not used for third-party advertising.

Payments

Brainstretch does not currently sell paid subscriptions, premium packs, or in-app purchases. If paid features launch, we may process billing metadata through a payment provider or app store. We do not plan to store full payment card details ourselves.

How We Use Information

We use information to:

  • operate Brainstretch and deliver public pages, guest demos, and account-backed play;
  • authenticate accounts and protect sign-in sessions;
  • save progress, profiles, preferences, races, history, and game state;
  • prevent abuse, cheating, automated misuse, and service disruption;
  • debug errors, monitor reliability, and keep the service secure;
  • measure public-page and guest-demo usage with privacy-friendly visitor analytics;
  • understand internal aggregate product analytics and improve game quality;
  • respond to support, privacy, security, and legal requests.

Legal bases

Where GDPR-style legal bases apply, we process personal information based on:

  • Contract: to provide account-backed play, saved progress, profiles, and requested features;
  • Legitimate interests: to secure the service, prevent abuse, improve reliability, measure privacy-friendly visitor analytics, and understand internal aggregate product analytics;
  • Consent: where consent is required for optional features or storage;
  • Legal obligations: to comply with applicable law, enforce rights, and respond to valid legal requests.

Providing account information is optional, but if you do not provide account information we cannot create an account, save durable progress, or provide account-backed features. Guest demo play remains available only where Brainstretch makes a demo available without an account.

Information Sharing

We do not sell your personal information. We do not currently use third-party advertising cookies or ad networks.

We may share limited information with service providers that help us operate Brainstretch:

  • hosting and infrastructure providers;
  • transactional email providers for sign-in and account messages;
  • observability, error monitoring, and security tools;
  • payment processors or app stores if paid features launch;
  • professional advisers or authorities when required by law or necessary to protect rights and safety.

See the Sub-processors page for current provider details.

Service providers may process information in countries outside your own. We use contractual and technical safeguards appropriate to the provider and processing activity.

International transfers

Brainstretch is operated from Israel and may use infrastructure or service providers in the European Union, United States, Israel, or other locations. When personal information is transferred internationally, we rely on appropriate safeguards such as data processing agreements, standard contractual clauses, provider security commitments, or other lawful transfer mechanisms.

Retention

We keep information only as long as reasonably necessary:

  • account data is retained while your account is active;
  • saved progress, preferences, profiles, and game history are deleted or anonymized within 30 days after account deletion is completed, except where retention is needed for security, integrity, dispute resolution, or legal reasons;
  • application and request logs are kept on a 90-day rolling retention period for reliability and troubleshooting;
  • security and abuse-prevention logs may be retained for up to 24 months when needed to investigate incidents, protect accounts, prevent cheating, or defend legal rights;
  • aggregate or anonymized statistics may be retained because they no longer identify you;
  • backup copies may persist for up to 90 days before rotation.

Your Rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.

You can delete your account from settings. For other requests, contact privacy@brainstretch.ing. We aim to respond within 30 days.

We may need to verify your identity before fulfilling a rights request.

You may also contact your local data protection authority.

Cookies, Browser Storage, and Visitor Analytics

Brainstretch uses essential first-party cookies for secure sessions, sign-in, and form protection. Brainstretch may use localStorage for display preferences such as theme and for analytics privacy choices, such as disabling visitor analytics in the current browser. See the Cookie Policy for details.

AI

Brainstretch does not currently use AI for game generation, gameplay decisions, generated puzzles, scoring, ranking, personalization, recommendations, opponent behavior, ads, content moderation decisions, user support decisions, or other automated user decisions. See the AI Disclosure for current and future AI transparency.

Security

We use technical and organizational measures intended to protect personal information, including HTTPS, access controls, secure authentication flows, monitoring, and regular updates. No service can guarantee perfect security. If you believe you found a vulnerability, contact security@brainstretch.ing.

If a personal data breach occurs, we will investigate, take appropriate remedial steps, and notify affected users or regulators when legally required.

Children

Brainstretch is for users 18 and older. We do not knowingly collect personal information from anyone under 18.

Changes

We may update this Privacy Policy as Brainstretch evolves. Material changes will be posted on this page and, where appropriate, communicated through the service or by email.

Contact

For privacy questions or rights requests, contact privacy@brainstretch.ing.