Cookies and device storage

“Local storage” stays until you clear your browser data. “Session storage” is removed when you close the tab. You can delete any of it in your browser’s settings at any time; the games and the sites keep working.

The “Do we ask first?” column states our position. Items that are strictly necessary for something you asked for, or that only keep a choice you made on your own device, are used without a prompt. Items that identify your browser to our servers are used only after the age screen and your explicit choice to share.

Portal (play.gamefoundry.ai)

NameWhereWhat it is forHow longDo we ask first?
__Host-gf_playerCookie (HttpOnly, Secure, SameSite=Lax)Keeps you signed in. Holds a random token; our database holds only its hash.30 days, renewed while you stay active, never beyond 90 days from sign-in. Set only after you sign in; removed when you sign out.No. Strictly necessary for the sign-in you asked for.
gf:client-idLocal storageA random ID that links the sessions you choose to share, so we can tell whether people come back. It is sent to our server with shared sessions and with a release-bound playtest form.Until you clear itYes. Created only after the age screen and when you choose “Share & play” or submit the playtest form.
gf:gallery-sortLocal storageRemembers the sort order you picked for the game list.Until you clear itNo. A preference that never leaves your device.
gf:portal-feedbackLocal storageA copy of feedback you send (game, release, rating, note, seconds played, browser details, screen size, time), kept so nothing is lost if delivery fails. Up to 50 entries.Until you clear it, even after deliveryNo. Written only when you press send; stays on your device.
gf:game-progress:<game>:<key>Local storageSaved progress, best scores and settings for Hungry Hole, Zigzag Roller and Blade Spin. The Portal runs games in a sandboxed frame that cannot reach storage itself, so it keeps these values for them. Stays on your device.Until you clear itNo. Needed to remember the progress you made.
gf:portal-session:<id>Session storageThe play session you started (game, exact release and a short-lived session token), so the play page can continue it after a reload and send the playtest form you choose to submit.Until you close the tab or end the sessionNo. Needed to run the session you asked for.
dashboardPasswordSession storageOnly on the team dashboard page: the access key a team member types to unlock it, so it need not be retyped on that page. Visitors never see or set it.Until you close the tabNo. Needed to unlock the page you opened.
gf:summary-cacheSession storageA two-minute cache of the aggregate play counts shown on game cards.Until you close the tabNo. No personal data.
gf:age-resultSession storageRemembers for this tab whether the age screen was passed, so it is not repeated on every game.Until you close the tabNo. Needed to apply the age rules.

Slices (slices.gamefoundry.ai)

Slices stores its keys in local storage under the prefix gf:slices:. Games in Slices run in the same origin as the app, so the games’ own storage also lives here (see below).

NameWhereWhat it is forHow longDo we ask first?
gf:slices:browser-idLocal storageA random browser ID created on first load and kept on your device. It is sent to our server (as a salted one-way hash together with the session) only if you choose “Share play signal”.Until you clear itThe ID is not sent unless you choose to share after the age screen.
gf:slices:consentLocal storageRemembers whether you chose “Share play signal” or “Feedback only”.Until you clear itNo. It records your own choice.
gf:slices:play:<game>Local storageRemembers the last play session and a replay count for a game.Until you clear itNo. Stays on your device.
gf:slices:pending-eventsLocal storageEvents and feedback waiting to be delivered, so they can be retried (at most 600). Used only if you chose to share, or pressed send on feedback.Until delivered or clearedFollows your sharing choice.

Storage the games themselves use

Where a game runs in the same origin as the app (Slices), it may save its own progress in local storage: for example best scores, a “seen the tutorial” flag, sound and theme settings, difficulty, and in the Sudoku games a name you type. These items stay on your device and are not sent to us by the game. The key names are chosen by each game, so they are not listed here one by one. In the Portal, games run in a sandboxed frame and cannot use storage directly; the three games listed above save through the Portal. A few multiplayer games run with same-origin access and may keep their own settings, and a lobby profile with a name you choose, in the Portal’s storage on your device.

Third parties

When you open the Portal sign-in dialog, Cloudflare Turnstile loads from challenges.cloudflare.com to check you are not a bot. This is a request to Cloudflare as described in the privacy notice. We do not know of any other third-party request made by the Portal or Slices pages.

Your control

To remove everything stored by a site, clear its data in your browser settings. To remove what our servers hold, use /your-data.html.