Skip to content
Legal

The short answer: we don't want your students' data.

Plain language first, with the full document one toggle away — because your data protection officer needs that version and you don't.

Effective 18 September 2026
In one line
Players are never identified unless you ask them to be
No student accounts exist. Registration fields are yours to choose.
Money
Subscriptions pay for this
No ads, no data business — and at least 10% of profits go to charity.
Where
Your region, your choice
Europe or the United States — set per account, separately for files and data.
Cookies
Functional only
Functional storage only: your browser remembers that you're signed in. No third-party tracking.
1

Who we are and what this covers

Puzzel.org is built and run by Daan Weustenraad in the Netherlands. This policy covers the website, the activities you build and the play screens your players see — and it is written to comply with the GDPR.

Questions or requests: daan@puzzel.org — answered by the person who built it.
Complaints can also go to the data protection authority in your country.
Schools: we act on your instructions, and a ready-to-sign processing agreement is on the vendor information page.
2

What we collect from you

An account needs a first name and an email address. Beyond that, we store what you make and how often it is used — nothing more than the platform needs to function.

First name and email address — to sign you in and reach you about your account.
The activities you create — stored so you can reopen, share and delete them.
Usage data — how often your activities are played, which also powers your results.
Functional cookies only — your active session, controllable in your browser.
3

What we collect from your players

Nothing, unless you switch it on. Registration fields are optional and chosen by you — and there is no automated decision-making or profiling, on anyone.

No player accounts — a link or QR code is enough.
Only the registration fields you enabled reach the results report.
No advertising identifiers and no third-party trackers on the play screen.
4

Where your data lives

Data is stored with Google Firebase, with SendGrid handling account email. You choose your storage region — Europe or the United States — separately for uploaded files and account data. Transfers outside the EEA are covered by standard contractual clauses.

Google Firebase — authentication and storage of your data.
SendGrid — account and platform email, nothing you didn't sign up for.
Legal authorities — only when required by law.
5

Your rights

Everything the GDPR gives you, without a form maze: ask and it happens. Most of it you can do yourself from your dashboard.

Access, correct or export your personal data.
Delete your data — or your whole account, right from the dashboard.
Restrict or object to processing, and withdraw consent at any time.
Not happy with how we handled it? Lodge a complaint with your supervisory authority.
6

Google Classroom

Only when a teacher connects Google Classroom and assigns an activity with grades. Students then sign in with their school Google account, so their score can reach their own submission — and that score, calculated on our servers, is the only thing we send back to Google.

From the teacher: their Google account, the classes they teach, and permission to create assignments and set grades. No rosters, no other coursework.
From a student on an assignment: the Google account they sign in with, to check they are in the class.
Removed when the teacher stops syncing or deletes the activity; disconnecting revokes Puzzel.org's access at Google.
7

AI assistants (ChatGPT, Claude)

Only when you connect an AI assistant to your Puzzel.org account yourself. It is off until you do. A connected assistant can make activities in your account and list, read, change and copy the ones you have; it never receives student results, registrations or anything a student typed.

What the assistant receives: the names, content and settings of your own activities, and the names of your folders. What you type to the assistant is handled by the company that provides it, under its own terms.
What we receive and store: the content the assistant sends to make or change an activity, a picture you give it for an activity (copied into your own storage), and which assistant you connected, what you allowed and when it was last used. Its access keys are stored only as one-way hashes.
Disconnect it at any time under Connected apps in your dashboard: its access ends at once, and the record of the connection goes with it.
Something here still unclear? Ask instead — legal pages that need a follow-up email are badly written.