AhaMate

Privacy in plain words

AhaMate is built for children and the adults around them, so the rule is simple: no child profiles, and as little technical data as a website can get away with.

What we never collect

What stays on your device

Your settings (language, sound, text size) and a short local log of game events are stored in your browser’s local storage so the game remembers them. You can clear them with your browser’s “clear site data”.

What we count

To learn whether the game works, our server counts events such as first move attempted, trap created, grown-up attempted (solved / trapped), play again clicked. Each event carries: the event name, the puzzle id and outcome, the game language, device class (phone / tablet / desktop), your browser’s language and screen size, the page path (never the part after #, where a shared trap lives), and — if you arrived through a partner link — the partner label we put in that link (a random token also identifies which shared trap was opened; it is not tied to a person). We use self-hosted Umami on our own server: no cookies, no third party. Umami turns your IP address and browser type into a visit id for counting (the salt behind it rotates regularly, so the id does not identify you over time); the IP address itself is not stored in the analytics database, but the browser and operating system family and an approximate location (country, city) derived from it are. Like any web server, ours keeps standard access logs (IP address, time, page) for about two weeks for security, then they are deleted. We do not build profiles across sites or sessions.

Challenge links

If you share a trap with someone, the link contains only the puzzle id, the language and a random token — never a name. After 30 days the link is marked as expired (the puzzle itself stays playable).

Who we are

AhaMate is made by ShapeLoop OÜ, Estonia. Questions: hello@ahamate.app. If anything here changes, this page changes first.