๐ŸŽฎ Wibble.ggโ„ข
About this notice. This privacy notice is written and published by the people who run Wibble (we are the operator of wibble.gg). We wrote it ourselves to describe โ€” as accurately and plainly as we can โ€” exactly what data we collect and how we use it. It is the notice we currently operate under. It has not been reviewed by a lawyer and is not legal advice; we expect to have it reviewed by qualified counsel and will update it if needed. It carries an effective date and version below, and we keep prior versions on record.

๐Ÿ”’ Wibble privacy & data notice

Effective 17 June 2026 ยท v1.0 (operator-authored) ยท Family-safe (ages 6+) ยท No ads ยท No tracking ยท One essential cookie

In a nutshell

Wibble is a family-safe games arcade for ages 6 and up. We keep the data we collect to the minimum we need to run your account, save your scores, and keep the arcade safe and fast. We do not show ads, run behavioural ad-tracking, sell or rent personal data, build advertising profiles of children, or use third-party tracking cookies. We use one essential sign-in cookie and nothing else. The few statistics we keep to understand and improve Wibble are anonymous, aggregate counts that are never linked to you or your child.

1. Who we are and how to contact us

Wibble (the “arcade,” “we,” “us”) is the service at wibble.gg, run by the people who operate it. For privacy and data questions, and to request a copy or deletion of your data, email privacy@wibble.gg or use the Contact form. For safety and abuse reports, use the in-game Report button (open a player's row in your Friends list and pick a reason) or email privacy@wibble.gg with “Safety” in the subject. For general support, use the in-app Help & Feedback form on any page.

2. What we collect

We only collect what we need. Account data (when you create an account): a username (shown publicly subject to your settings), an email address (to sign you in, recover your account, and send essential account emails), a password (stored only as a secure, salted PBKDF2 hash โ€” we never store, see, or email your actual password), a birth year (a neutral age signal โ€” see Section 5), your comfort and parental settings (whether profile/chat/multiplayer/leaderboard are on or off, and whether a grown-up PIN is set โ€” the PIN is stored only as a secure hash), optional profile details (a short bio, an avatar emoji, cosmetic picks โ€” free-text is filtered to remove contact details and bad language), and, if you turn it on, optional two-factor authentication settings (the 2FA secret never leaves our server and is never included in your data export). Gameplay data: your scores, levels and best runs, wins and games-played, streaks, the friends and blocks you create, and things you choose to send (multiplayer chat, a game idea, or a Help & Feedback message). Chat and submitted text are automatically filtered to hide contact details (emails, links, phone numbers) and star out bad language. Multiplayer is invite-only over a room code โ€” there is no stranger matchmaking. Guests who play without an account give us no personal data at all โ€” no account, no cookie, no stored IP, and no per-player identifier; a guest's scores stay on their own device until they choose to sign in.

3. Anonymous, aggregate analytics (no cookies, no identifiers)

To understand how Wibble is used and keep it fast, we keep simple anonymous totals โ€” never a record of any one person. These are daily counts of how many times each page was viewed and a coarse bucket for where visits came from (for example “a search engine”); anonymous performance timings (Core Web Vitals) kept as running sums; coarse country and city tallies where our content-delivery network provides those signals (a city is only ever a town or city label such as “London, GB” โ€” never a street, an address or a GPS position โ€” and small places are hidden behind a minimum-count threshold so no one can be singled out); and aggregate play- and session-length sums. Where measurable, we also keep a few more anonymous totals to see how the arcade is doing on different devices and to make it better: a coarse device, browser and operating-system bucket (for example “phone” or “Chrome”), worked out for a moment from the technical details your browser sends with every web request and then thrown away โ€” that raw browser detail is never stored, only the bucket is counted; your browser's main language (for example “en”); if you arrived from a marketing link, the campaign labels in that link (so we can see which links bring people in); simple counts of in-app actions from a short, fixed list (for example “a game was started”), kept only as running totals โ€” never as a record of what any one player did, or in what order; two separate tallies of which pages people tend to start on and which they tend to leave from (kept apart and never joined up into a journey for any visitor); and a live “how many people are playing right now” count that holds no identities and forgets itself within minutes. There is no cookie, no IP stored, and no per-person identifier behind any of these, and the counts are never cross-linked to each other or to you. For the geographic tallies your IP address is never read or stored โ€” only a coarse country or city label from a network header is counted, and small cells are suppressed below a safe threshold.

4. What we do NOT collect or do

No third-party advertising or ad-network trackers, anywhere. No behavioural ad-tracking and no cross-site tracking โ€” nothing on Wibble follows you around the web. No selling or renting of personal data. No advertising profiles, and no profiling of children. No analytics, advertising, or third-party cookies (see the Cookie Notice). No precise location โ€” no street address and no GPS; only coarse, aggregate country and city tallies (small places hidden behind a minimum-count threshold). We do read your IP address transiently at sign-up, login, and when you submit feedback โ€” solely to limit abuse and spam โ€” but we do not store it against your account or use it to build a profile.

5. Cookies

Wibble uses exactly one cookie, and it is strictly necessary to sign you in and keep you signed in. It is named session, holds only a random sign-in token (not your name, email, or password), and is set HttpOnly, SameSite=Lax, and Secure on HTTPS connections. It is issued only when you log in or sign up, and it clears when you log out. Guests do not get this cookie at all. Because the only cookie is essential to provide the service you asked for, Wibble does not show a cookie-consent banner โ€” none is required. Full details are in our Cookie Notice.

6. Why we use your data, and our legal bases

We use account and gameplay data to create and run your account, sign you in, recover access, apply your comfort and parental settings, and run the games, leaderboards and social features you use โ€” our intended legal basis for this is performance of the contract to provide the arcade you signed up for. We use security and anti-abuse measures (including transient IP use for rate-limiting) and our chat/content filtering to keep the arcade safe โ€” our intended basis is our legitimate interest in a safe service, and legal obligation where it applies. We keep anonymous aggregate analytics under our legitimate interest in understanding and improving the service (the data is anonymous and aggregate). These bases are the ones we intend to rely on; we are not relying on consent for the core service, which is why we do not branch our age rules by country (see Section 5 of the For-counsel list below).

7. Children's privacy

Wibble is built for families, ages 6 and up, and is designed with children's-privacy rules in mind (such as COPPA in the US, GDPR/GDPR-K in the EU, the UK Children's Code, Quebec's Law 25, and California's design-code requirements). Accounts are for ages 13 and up. We ask for a birth year once on a neutral age screen, and we use it only to check eligibility: if it shows you are under 13, we do not create an account and we do not store any personal data for you โ€” instead, you can keep playing every game as a guest (guests give us no personal data). A grown-up can create and manage an account for a younger child. High-privacy defaults: every account starts with its social and exposure features switched OFF โ€” public profile, chat, multiplayer and the public leaderboard are all off until a grown-up turns them on, deliberately, behind a PIN-protected parental-controls area (the PIN is stored only as a secure hash). Chat is filtered, multiplayer is invite-only over a room code, crawlable public pages carry no free-text identity fields, and we never build a profile of a child. A grown-up managing a child's account can use the data tools in Section 8. We do not yet operate a verifiable-parental-consent flow that would let under-13s hold their own accounts โ€” that remains a future step we would design with qualified counsel; until then, accounts stay 13+ and younger players use full guest play.

8. Your rights and how to use them

Depending on where you live, you (or a parent/guardian acting for a child) may have the right to access the data we hold, receive a portable copy, correct it, delete it, restrict or object to certain processing, withdraw consent where we rely on it, and complain to a regulator (see Section 9). Self-serve tools in your account: Download my data gives you a one-click JSON export of your own account details (username, email, whether your email is verified, when the account was created, whether two-factor is on, your birth year, and any Plus status), your profile (including your scores, wins and streaks), your comfort/parental settings, and your friends and blocked lists. For your security it never includes secrets such as your password hash, 2FA secret, or parental PIN. Some things that name other people โ€” for example reports you have filed or game ideas you submitted โ€” are deliberately left out of this self-export; you can request those (or any other data we hold about you) by emailing privacy@wibble.gg. Delete my account is a password-confirmed, irreversible deletion: we re-ask for your password to confirm it's you, then permanently erase your account and the data tied to it (scores, results, climbs, friendships, blocks, reports you filed, reset tokens, and your feedback), end all your sessions, and clear your sign-in cookie. Community game ideas you submitted are kept for the community but are anonymised so they no longer link to you. You can also exercise any right by writing to privacy@wibble.gg.

9. Sharing, providers, transfers & complaints

We do not sell or rent personal data and do not share it with advertisers. We use a small number of service providers strictly to run Wibble โ€” cloud hosting, a managed PostgreSQL database, an email provider for essential account emails, and a content-delivery network that fronts the site and provides the coarse country/city signal (the IP is not stored). We may also disclose data where the law requires it or to protect the safety of users. Our hosting and database providers are US-based, so personal data is processed in the United States. If you have a concern, please contact us first at privacy@wibble.gg โ€” you also have the right to complain to a data-protection regulator (in the UK, the Information Commissioner's Office; in the EU/EEA, your local Data Protection Authority; in California, the California Privacy Protection Agency or the Attorney General).

10. Security

We protect your data with measures including passwords stored only as salted PBKDF2 hashes (never in plain text), optional two-factor authentication with the secret kept server-side and never exported, secure HttpOnly session cookies, rate-limiting and bot protections, and security headers including a Content-Security-Policy and HSTS on HTTPS. No service can promise perfect security, but we work to keep Wibble safe.

11. How long we keep data

We keep account and gameplay data while your account is active; when you delete your account (Section 8) it is erased as described there. Our anonymous aggregate analytics are pruned automatically so older rows (around 400 days) are removed, leaving only running totals. Security and abuse data is transient, and password-reset and email-verification tokens are single-use and expire quickly (reset links within roughly 30 minutes).

12. Changes to this notice

This notice carries an effective date and a version (below), and we keep prior versions on record. If we make a material change we will update the date and version and, where appropriate, tell players and the grown-ups who manage children's accounts before it takes effect, by a notice on the site and/or by email.

13. For grown-ups

If you're a parent or guardian: Wibble keeps data to a minimum. Accounts are for ages 13 and up โ€” younger children play as guests, who give us no personal data, and a grown-up can create and manage an account for them. Every account starts locked down โ€” public profile, chat, multiplayer and leaderboards are all off until you turn them on behind a PIN. There are no ads, no tracking cookies and no advertising profiles โ€” the only cookie keeps a signed-in player signed in. Chat is filtered and multiplayer is invite-only. You can download or delete an account's data at any time from the account menu, or email privacy@wibble.gg. See the For parents page for more.

14. For kids ๐ŸŒŸ

Hi! Here's what this page means in a few friendly words: Wibble keeps your stuff safe. We remember your name in the game, your scores, and your settings โ€” that's it. We don't show you ads, and we don't follow you around the internet. We use just one little cookie so the game remembers you're logged in. Your password is kept secret in a scrambled-up way that even we can't read. Chat hides things like your phone number or email so you stay safe, and only friends can play together โ€” never strangers. A grown-up can decide what you're allowed to do, and you can always ask a grown-up to show you or delete your stuff. Be kind, have fun, and never share your real address, school, or phone number with anyone online. ๐Ÿ’œ

โš ๏ธ For counsel โ€” still to confirm

This notice is operator-authored and has not been reviewed by a lawyer. A qualified, jurisdiction-licensed lawyer should still confirm, and may change: (1) the controller's legal name, address and place of establishment, and whether a DPO or an EU/UK Article 27 representative must be appointed and named; (2) the lawful-basis mapping per data category and region, and whether contract/legitimate-interest (rather than consent) holds for 13+ minors; (3) the international-transfer mechanism for EEA/UK data sent to the US (Data Privacy Framework, Standard Contractual Clauses, or the UK IDTA) or moving to EU-region hosting; (4) exact retention windows and the COPPA-required posted retention policy and written children's-data security program; (5) the named processor list, data-processing agreements and an Article 30 record; (6) whether the coarse country/city tallies are actually recording on the live wibble.gg domain before relying on it; and (7) whether and how a verifiable-parental-consent flow would be built if under-13 accounts are ever offered. (8) The newer aggregate analytics signals โ€” device/browser/operating-system buckets, browser language, marketing-campaign labels, in-app action counts, the entry/exit page tallies and the live active-now count, described in Section 3 (DRAFT): these are intended to stay within the same posture as the existing analytics โ€” no per-visitor identifier, no IP read or stored for analytics, bounded keys, k-anonymity floors, and, critically, each signal kept as a flat tally that is never cross-tabbed or paired with another (entry and exit are never joined into a journey; in-app actions are population counts, not per-player sequences). This no-pairing rule is what keeps the “we never build a profile of a child” promise true, so counsel should confirm it holds end-to-end. Counsel to also confirm that any externally-supplied campaign label is sanitised, length-capped and k-anonymity-floored so no identifier can be smuggled in; that this disclosure ships coupled with the feature (the live page must not describe collection that isn't yet happening); and a one-line Article 30 / DPIA record. (9) The aggregate click-density (“heatmap”) signal is deliberately NOT described on this live page and is NOT live โ€” “recording where children tap,” even in coarse aggregate, is the item most likely to draw scrutiny on a 6+ service; it is held for separate counsel review (see the fuller DRAFT policy) and should not be enabled without sign-off. Requirements vary by jurisdiction and change over time. This notice is not legal advice.

Cookie notice ยท Terms of service ยท โ† Back to the parents page

Effective 17 June 2026 ยท version 1.0 ยท operator-authored, not reviewed by a lawyer ยท not legal advice.