Stored on your device
Daily progress, wins, streaks, guess distribution, completed dates, your analytics choice, and a random anonymous player ID are stored in browser local storage. The player ID is a UUID generated from secure random bytes; it contains no name, email, device fingerprint, or account data. Clearing site data removes the ID and local history, so Lexora creates a new ID on your next visit.
Server-validated state
Each game request sends the anonymous player ID in a first-party request header. The server derives a one-way keyed binding for signed game-state tokens so one browser cannot reuse another browser’s token. The raw ID is not placed in puzzle URLs, public puzzle data, signed tokens, or the analytics database.
Anonymous game events
The Lexora server may count start, complete, fail, share, and tip events by game, event UTC date, puzzle Edition date, Edition number, and content version. The database stores aggregate counts and event deduplication IDs, not the anonymous player ID, guesses, traced paths, or player profiles.
Optional Google Analytics
Google Analytics loads only after you select “Allow analytics.” When allowed, Lexora measures page visits and broad game actions such as selecting, starting, completing, failing, sharing, or using a tip. The standard web tag may process device and browser details, approximate location, session information, and a first-party Analytics identifier. Lexora does not send its anonymous player ID, puzzle guesses, answers, traced paths, names, or email addresses to Google Analytics.
You can reopen “Analytics choices” in any page footer and select “No thanks.” Advertising storage, ad user data, ad personalization, and Google signals remain disabled in this integration.
No cross-device synchronization
Because the current version has no login system, each browser or app installation has a different player ID and statistics are not synchronized between devices. Lexora does not sell individual puzzle activity or use it to create personal gameplay profiles.