Privacy Policy
Last updated: March 12, 2026
The Original Snake (“we,” “us,” or “our”) is a free browser-based game operated by Marcelo Otero Zamora, an individual based in the United States. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using The Original Snake, you consent to the practices described here.
1. Information We Collect
We are designed with privacy in mind and collect only the minimum data necessary to operate the game and leaderboard.
a) Leaderboard Data
When you submit a score, we collect:
- Nickname — a name you choose (3-12 characters). No email, account, or real name is required.
- Score and difficulty — your game score and the difficulty mode played.
- Timestamp — the date and time of submission.
- Country — a country-level location (e.g., “US”) derived from your IP address by our hosting provider (Vercel). This is stored as a two-letter country code and displayed as a flag emoji next to your name on the leaderboard. No city, region, or precise location is collected or stored.
Leaderboard entries are stored on Upstash Redis (a cloud database service) and displayed publicly. Daily and weekly entries expire automatically; all-time entries are retained indefinitely.
b) Analytics Data
We use PostHog for anonymous usage analytics configured in cookieless, memory-only mode. This means:
- No cookies are set by our analytics.
- No data is persisted to your browser between sessions.
- No cross-site tracking occurs.
Analytics events include page views, game actions (start, end, score), difficulty changes, share clicks, and Core Web Vitals performance metrics. After submitting a nickname to the leaderboard, your chosen nickname may be used as a session identifier within PostHog for that session only.
c) IP Addresses
When you submit a score, your IP address is used temporarily for rate limiting (to prevent abuse) and to determine your country-level location (see “Country” above). The IP address itself is stored in a short-lived cache that expires within seconds and is not logged or retained long-term. Only the two-letter country code is retained with your leaderboard entry.
d) Local Storage
We store the following data locally in your browser using localStorage. This data never leaves your device:
- Your personal high score
- Sound preference (on/off)
- Your last-used leaderboard nickname
- Your ad consent choice (accepted or declined)
- Whether you dismissed the install prompt
2. Cookies
Our site does not set cookies for analytics or tracking. PostHog analytics runs entirely in memory with no cookies or persistent identifiers.
However, if you accept cookies via our consent banner, Google AdSense (our advertising partner) may set cookies on your device to serve and measure advertisements. These are third-party cookies governed by Google’s privacy policies. If you decline cookies, no advertising cookies will be set.
3. Third-Party Services
We use the following third-party services:
- Google AdSense — serves advertisements. Google may use cookies to personalize ads. You can manage your ad preferences at Google Ad Settings. See Google’s Privacy Policy.
- PostHog — anonymous analytics in cookieless mode. See PostHog’s Privacy Policy.
- Upstash Redis — cloud database for leaderboard storage. See Upstash’s Privacy Policy.
- Vercel — hosting and content delivery. See Vercel’s Privacy Policy.
We have data processing agreements in place with each service provider to ensure your data is handled in compliance with applicable data protection laws.
4. How We Use Your Data
- Display your nickname, score, and country flag on public leaderboards.
- Prevent abuse through rate limiting.
- Understand aggregate usage patterns to improve the game.
- Serve advertisements (with your consent).
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
5. Data Retention
- Daily leaderboard: entries expire after 24 hours.
- Weekly leaderboard: entries expire after 7 days.
- All-time leaderboard: entries are retained indefinitely.
- Analytics data: retained according to PostHog’s data retention policies.
- IP addresses: used only for rate limiting and not stored beyond a few seconds.
6. Children’s Privacy
The Original Snake is a general-audience game. We do not knowingly collect personal information from children under the age of 13. The only personal data submitted is a self-chosen nickname for the leaderboard, which does not require or request any identifying information. If you believe a child under 13 has submitted personal information, please contact us and we will promptly delete it.
7. Your Rights
All Users
You may at any time:
- Clear your local browser data (high score, nickname, preferences) by clearing your browser’s localStorage.
- Decline advertising cookies via our consent banner, or revoke consent by clearing your browser data.
- Request deletion of your leaderboard entries by contacting us.
European Economic Area (GDPR)
If you are located in the EEA, you have the right to access, rectify, erase, restrict processing of, and port your personal data, as well as the right to object to processing. Our legal basis for processing leaderboard data is your consent (you choose to submit a score). For analytics, our legal basis is legitimate interest in understanding aggregate usage. To exercise your rights, contact us at the email below.
California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion of your personal information, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at the email below.
8. Security
We use industry-standard measures to protect your data, including HTTPS encryption, server-side secret management, and HMAC-signed session tokens for leaderboard submissions. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. International Data Transfers
All third-party services we use (Google, PostHog, Upstash, Vercel) are based in the United States. If you are visiting from outside the US, your data may be transferred to and processed in the US. These transfers are safeguarded by Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework, as implemented by each service provider.
10. Right to Complain
If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed in violation of applicable law.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law, including within 72 hours where required by the GDPR.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. Continued use of The Original Snake after changes are posted constitutes acceptance of the revised policy.
13. Contact
For privacy-related questions, data deletion requests, or to exercise your rights, contact us at: privacy@theoriginalsnake.com