Privacy Policy

Last updated: February 26, 2026

Overview

Word Search Generator ("we," "us," or "our") is operated by AAALM. This Privacy Policy explains how we collect, use, and protect your information when you use our service at wordsearch.aaalm.io (the "Service").

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

Information We Collect

Account Information

When you sign in with Google, we receive and store the following from your Google account:

  • Email address
  • Display name
  • Profile photo URL
  • Google account identifier

We do not receive or store your Google password. Authentication is handled entirely by Google via OAuth 2.0.

Puzzle Data

When you create word search puzzles, we store the puzzle content including themes, word lists, grid layouts, clue text, and your solving progress (e.g., which words you've found and completion timestamps).

Payment Information

Payments are processed by Stripe. We do not receive or store your credit card number, bank account details, or other payment credentials. We do receive confirmation of successful payments, the amount paid, and a Stripe transaction identifier, which we store for our records.

Usage Data

We log internal service usage data such as API call counts and token usage for cost tracking and service monitoring. This data is used for internal operational purposes only and is not shared externally.

How We Use Your Information

  • To authenticate you and maintain your session
  • To create, store, and display your word search puzzles
  • To manage your credit balance and process purchases
  • To generate AI-powered words and clues for your puzzles using OpenAI
  • To enable puzzle sharing via public share links
  • To monitor and maintain service performance and costs
  • To provide customer support

Third-Party Services

We use the following third-party services:

Cookies and Sessions

We use cookies solely for authentication session management (NextAuth.js session cookies). We do not use advertising cookies, tracking cookies, or analytics cookies. The session cookie is essential for the Service to function and allows you to stay signed in.

Data Sharing

We do not sell, rent, or trade your personal information. We share data only with the third-party service providers listed above, solely for the purposes of operating the Service. We may disclose information if required by law or to protect our rights.

When you generate a share link for a puzzle, anyone with that link can view and play that specific puzzle. Shared puzzles do not expose your name, email, or other account information to viewers.

Data Security

We take reasonable measures to protect your data, including row-level security policies on our database (ensuring users can only access their own data), encrypted connections (HTTPS), and secure authentication via OAuth 2.0. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Data Retention

We retain your account information and puzzle data for as long as your account is active. If you wish to delete your account and associated data, please contact us at the email below. We will process deletion requests within 30 days.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Request a portable copy of your data

To exercise any of these rights, please contact us using the information below.

Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: support@aaalm.io