Skip to content
Boxscore

Privacy Policy

Last updated September 19, 2026

Boxscore is a free daily sports puzzle site made by one person. This page explains, in plain language, what information the site handles when you play, what other people can see, and how to get your data removed.

The short version

  • You can play every game without an account. Your stats and streaks stay in your own browser.
  • Finishing a daily puzzle can post your result to a public leaderboard under a display name. Guests get a random name like “user4821”.
  • Accounts are optional and handled by a third-party sign-in provider.
  • There are no ads and no data sales. The site counts visits with its own cookie-free analytics (see “Analytics” below); nothing is sent to an outside analytics or advertising company.

What is stored in your browser

The site saves the following in your browser’s local storage. It stays on your device unless a feature below sends it to the server:

  • Your stats for each game: games played, wins, streaks, your last result, and share text.
  • Progress on a daily puzzle you haven’t finished, so a refresh doesn’t reset it.
  • Which archive puzzles you’ve finished in each game (the puzzle number and a short result like “125/150”), so the archive can show what you’ve solved. As a guest this never leaves your browser; if you’re signed in it’s also saved to your account (see “Accounts” below).
  • A random guest ID and a random guest name (like “user4821”), used to attribute your leaderboard results if you’re not signed in.
  • If you sign in, a note of which account this browser last synced with, so one person’s progress isn’t mixed into another’s on a shared computer.

You can clear all of this at any time from your browser’s site-data settings. Doing so resets your local streaks and gives you a new random guest identity.

The public leaderboard

When you finish a daily puzzle, your result may be sent to the server automatically and shown on the leaderboard (you don’t need to click anything). For each game we keep one row per player: your personal best. Each row contains:

  • the game, your score, the human-readable result (like “142/150”), and the puzzle day;
  • your display name;
  • a random guest ID, or your account ID if you’re signed in (never shown publicly).

To check that a result is genuine, your browser sends the moves you made (for example, which sport you put each country in) along with the result. The server replays them and stores only the resulting score, not the moves. Guests can’t choose a name, and an account name that looks inappropriate is replaced with “Player”.

Publicly visible: your display name, your result, the puzzle day, and whether you played as a guest. Guests appear under their random name. If you’re signed in, your display name is your account username, or your first name if you haven’t set a username. If you don’t want your first name on the leaderboard, set a username in your account settings first.

Accounts

Creating an account is optional. Sign-in is provided by Clerk, which collects the details you give it (such as an email address or the profile information from a social login you choose) and uses cookies to keep you signed in. I never see or store your password.

If you sign in, the site’s database keeps, keyed to your account ID, so it follows you between devices: your per-game stats and streaks, which daily and archive puzzles you’ve finished (puzzle number and short result), and your leaderboard rows (above). It also keeps a copy of your email address from Clerk. That copy exists only so your data can be matched to you if I ever change sign-in providers (a new provider would give your account a new ID). It is never shown publicly and never used for marketing or shared with anyone.

Hosting and other services

  • Hosting. The site is hosted on Vercel, which, like most hosts, automatically logs requests (IP address, browser type, and the page requested) to run and secure the service.
  • Database. Leaderboard rows and account data (stats, finished puzzles, email) are stored in a managed Postgres database from Neon.
  • Player photos and team logos. These load directly from the leagues’ and clubs’ own servers (for example MLB, NBA, NHL, ESPN, and Transfermarkt image hosts). If one of those photos isn’t available, the site looks up the player’s picture on Wikipedia (the player’s name is sent to Wikipedia’s public API by the site’s server, not by you) and your browser then loads it from Wikimedia. When your browser fetches any of these images, those servers can see your IP address and browser details, just as they would if you visited their sites. The site’s fonts are self-hosted and don’t contact Google when you visit.

Shared result links

When you press Share, the text includes a link to a page for that puzzle. The link carries your result in its address (for example the score and the colour grid) but not your name or any account information. Anyone who has the link can see that result.

Analytics

To understand which games people play and whether the site works, it records a small, anonymous event when you load a page, finish a puzzle, press Share, or install the site to your home screen. Each event contains:

  • the page (with any numbers, like a puzzle number, removed — for example “an archive puzzle in The Player Stack”), which game, sport and mode (daily, archive or unlimited) it was;
  • for a finished puzzle, whether it was solved;
  • whether you arrived from a shared link or from the home screen (the “ref” in the address), if you did;
  • the time, and an anonymous daily visitor code (next paragraph).

The visitor code is a scrambled fingerprint of your IP address, browser, and today’s date, made with a secret key. It lets the site count how many different visitors there were on a given day, and it changes every day, so nobody can be followed from one day to the next. Your IP address and browser details are used only to make the code and are not stored. The analytics use no cookies and nothing in your browser’s storage, and they are kept on the site’s own database, not sent to any outside analytics company. Events are kept for up to about 13 months.

Do Not Track: the site honours the “Do Not Track” and “Global Privacy Control” browser signals. If either is on, no analytics event is recorded at all. Automated traffic (search-engine crawlers, link previews, monitoring tools) is also not counted.

Preventing abuse

To stop scripts from flooding the leaderboard, the site counts how many results each address submits per hour. It does this with a salted hash of your IP address rather than the address itself, and the counters are deleted after a day or so. A hash like this is pseudonymous, not fully anonymous.

What I don't do

I don’t sell or rent your information, show ads, or build advertising profiles. The site doesn’t use third-party analytics or tracking scripts. The only analytics is the first-party, cookie-free kind described above. If that ever changes, this page will be updated first.

Keeping and deleting your data

Local data lives only in your browser (see above). Leaderboard rows and synced account data (stats, finished puzzles, and your email address) are kept until you ask for them to be removed. Note that deleting your account with Clerk does not automatically remove any of that from the site’s database, so please contact me if you want it deleted too. For a guest entry, tell me the display name and result shown and I’ll remove it.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of the personal information held about you. Ask using the contact below and I’ll respond as soon as I can.

Children

Boxscore isn’t directed at children under 13, and I don’t knowingly collect personal information from them. If you believe a child has created an account or a leaderboard entry, contact me and I’ll remove it.

Security

Data is transmitted over HTTPS and stored with reputable providers. No system is perfectly secure, so I can’t guarantee absolute security, but I keep what the site stores to a minimum on purpose.

Changes to this policy

If I change this policy I’ll update the date at the top. Continuing to use the site after a change means you accept the updated policy.

Contact

Questions, or want something deleted? Message @austinkrance on X.