Privacy policy
Signal Escape · Last updated 8 August 2026
Canonical copy: signalescape.com/privacy. The same policy is bundled with the game, so it is readable offline and in the browser build.
This is written to be read, not to be complied with. If anything here is unclear or turns out to be wrong, email hi@mgoyal.com and it gets fixed.
The short version
Signal Escape has no accounts, no ads, no trackers, no analytics SDK, and nothing to sell. It is free and there is no business model, so there is no reason to collect anything — and it doesn't.
Your progress is stored on your own device. It is never uploaded.
The game sends four counters about which levels people find hard, tagged with a random id so we can tell three people stuck three times apart from a hundred people who quit once. You can turn them off in Settings, and the game is identical either way.
The website sends two: that a page was opened, and whether Play was pressed. Those need no cookie and are always on. It also offers Google Analytics, which does need one — so it is off until you accept it, and if you decline it never loads at all.
The game sets no cookie, ever. The one cookie described here belongs to the website, and only to someone who said yes to it.
What is stored on your device
In your browser's localStorage, under two keys:
| Key | What it holds |
|---|---|
se.progress |
Which levels you've solved, one working solution per solved level, which level you're on, and which help cards you've dismissed |
se.settings |
Theme, colourblind mode, reduce motion, sound, vibration, tick speed, and your analytics preference |
se.anon |
A random id used to group your own events together. See below |
This never leaves your device. There is no account and no sync in this version, so there is nowhere for it to go.
To erase all of it: Settings → Reset progress, or clear site data for this site in your browser. Both remove everything the game has stored. Nothing survives, on your device or anywhere else.
What is sent, if you leave analytics on
Four events, and only these four:
| Event | Fields |
|---|---|
level_started |
level number |
level_solved |
level number, number of attempts this session |
level_abandoned |
level number, number of attempts this session |
hint_used |
level number, which of the three hint stages |
Every event also carries eight fields describing the build, not you:
| Field | What it is | Why it is there |
|---|---|---|
game |
Always signal-escape |
One analytics project may hold more than one game |
version |
e.g. 1.0.2 |
Tell a problem with a release apart from a problem with a level |
build |
The commit it was built from | The same, precisely |
environment |
local, preview or production |
Keep our own testing out of the numbers |
platform |
web |
So a future phone version can be compared against it |
distribution |
web or itch |
Which listing you opened the game from. The itch copy runs in a frame where the browser may refuse storage, so its numbers mean something different |
layout |
narrow or wide |
Whether the phone layout loses more players than the desktop one |
locale |
Your browser's language, e.g. en-GB |
Whether translating the game is worth doing, and into what |
The id
Each event carries a random id stored on your device under se.anon, so your own events can be grouped together over time.
Being plain about this, because it is the part that matters: a stable id is what makes this personal data under GDPR and similar rules, and it is what both app stores call a Device ID. An earlier version of this game used an id that was thrown away on every page load — which was more private and close to useless, because a hundred abandonments could equally be three people stuck three times or a hundred people quitting once, and those call for opposite fixes.
What it is not: it is a random number with nothing attached. It is not derived from anything about you or your device, so it cannot be recalculated, matched against any other service, or used to recognise you anywhere else. Clearing site data ends it permanently — the next visit mints a new one and there is no way to connect the two.
There are no accounts in this version. If accounts are added later, signing in would replace that id with your account id and display name, and this policy will say so before it happens.
What is never sent
- Your name, email, or any account — there are none
- Your solutions or the schedules you tried
- Your IP address. Every request on the internet necessarily carries one, so we explicitly instruct our processor not to store it — this is enforced in the code, not left to a default
- Any device fingerprint
- Anything you type, and anything about how you solved a level
- Your screen size, timezone, or browser user-agent string — each would narrow a fingerprint and none answers a question worth asking
- Anything at all, if you turn analytics off
Why it exists
One question: which of the 50 levels do people give up on. That is the difference between improving the game and guessing at it. Nothing here is monetised, sold, shared, or used for advertising.
The processor
Events go to PostHog, which stores them on our behalf. We send them with person profiles disabled, so PostHog does not build a profile from them either.
Turning it off
Settings → Anonymous stats → Off. It takes effect immediately, before any further event is sent, and the game plays exactly the same. If a build ships without an analytics key configured, nothing is sent regardless of this setting.
The website, which is a separate thing
signalescape.com is the page that describes the game. The game itself is at play.signalescape.com, and everything above is about the game.
The website sends two events: that a page was opened, and whether the Play button was pressed. That is the only question a landing page has — whether the people who read it go and play.
| Event | Fields |
|---|---|
$pageview |
the page address |
play_clicked |
which of the two Play links was used |
The random id that ties those two events together is made when the page loads and is gone when you close the tab, so a second visit is a new id and there is nothing to link the two. No cookie, nothing stored, nothing to switch off.
The website also uses Cloudflare Web Analytics, which counts page views and where visits came from. It sets no cookie, stores nothing in your browser, and builds no identifier for you — it cannot tell one visitor from another, only how many there were. Like the two events above, it is always on, because there is nothing about it to ask permission for.
And Google Search Console, to see which searches the site appears in. That reads Google's own records of search results and never runs anything in your browser.
Google Analytics, and the cookie it needs
Google Analytics is off until you accept it. If you decline, or simply never answer, the page makes no request to Google at all — the script is never fetched, and no cookie is created. Nothing else on the site changes.
If you accept, Google Analytics loads and sets its _ga cookies, which is what lets it tell a returning visit from a new one. The advertising half of Google's consent settings stays refused either way, including for you, so nothing here becomes an advertising signal.
This is a change from an earlier version of this policy, and it is worth being plain about why. The site previously ran Google Analytics in a cookieless mode and claimed no cookies at all, which was true. What it did not say — because it was not known until the reports were checked — is that Google discards that kind of cookieless data unless the property also has a large volume of consented traffic to model it against. This site had none, so the reports were empty and always would have been. The choice was a real cookie with a real question in front of it, or an analytics install that quietly measured nothing. This policy describes the first.
To change your mind: the Cookies button in the site footer reopens the question at any time. Choosing Decline there also deletes the _ga cookies that were already set. Clearing site data for signalescape.com in your browser does the same thing, and also forgets that you were ever asked.
Your answer is remembered in localStorage under se.consent, on your device, so you are asked once rather than on every visit. That single value is the only thing the website stores when you decline.
Browser "do not track" and content blockers stop all of it — Google, Cloudflare and the two events alike — and the page works identically either way.
The game at play.signalescape.com has no Google on it at all. Everything in this section is about the website that describes the game.
What the game does not do
- No advertising, and no ad networks
- No advertising or ad-personalisation signals anywhere. Google's ad consent settings are refused on the website even for a visitor who accepts analytics
- No cookies on the game at all. The website has one — Google Analytics — and only for someone who accepted it, which is the single exception on either host and the only thing on either that a banner is asked about
- No social login, no email collection, no newsletter
- No selling or sharing of anything with anyone
- No location, camera, microphone, contacts, or files
- No required network connection. After first load the game works fully offline; every network call it can make is optional and fails silently
Children
The game is suitable for all ages and collects no personal information from anyone, including children. There is no account to create and no way to enter personal data.
Your rights
The counters are tied to a random id and nothing else — no name, no email, no account — so we have no way to find your data on request, and neither has anyone else. The id is the only handle that exists, and it lives on your device.
What you can do at any time, without asking: turn analytics off, and erase everything the game has stored — including that id — by clearing site data for this site in your browser.
If you are in the EU/UK, the lawful basis for the anonymous counters is legitimate interest in improving the game, and you can withdraw at any time using the setting above.
Changes
Material changes will be noted here with a new date, and in the game's changelog. The date at the top of this page is the one to check, and the build id in the game's Settings says exactly which version of it you are running.
Contact
Email hi@mgoyal.com.
← Signal Escape