← Play Tumble Tally

Privacy, in plain terms

Tumble Tally is a free game from Dayplay Games, a brand of Winter Watermelon. You can play without an account, and analytics can be turned off at any time.

Optional leaderboards

Play anonymously, or choose a player name for shared Dayplay Games leaderboards. A first-party cookie remembers your name; an optional password lets you log in on other devices. We store a salted password hash, not a plaintext password, and an optional email kept privately with your player account. There is no password reset. Results post only when playing with a name. An account email is optional, private, unverified, and separate from game-update subscriptions. Change or remove it at the player page. Delete your player and scores at Manage your player. Daily results expire after 14 days and weekly results after up to three weeks; names without scores expire 30 days after creation. Browser-reported scores are for casual competition, with no prizes.

Optional leaderboards

Play anonymously, or choose a player name for shared Dayplay Games leaderboards. A first-party cookie remembers your name across our games. An optional password supports other devices; we store a salted password hash. Account email is optional and password reset is not available. Completed results post only when playing with a name. An account email is optional, private, unverified, and separate from game-update subscriptions. Change or remove it at the player page. Delete your player and scores at Manage your player. Daily results last 14 days and weekly results up to three weeks; names without scores expire 30 days after creation. Browser-reported scores are for casual competition, with no prizes.

Your scores stay here

This browser saves one free-play best, one Honeycomb best, up to 35 daily bests, your daily streak (a count and the last UTC date you finished a daily board), which of the sixteen goals you have met, your sound and motion preferences, and which version of the first-time guide this browser was given, whether the one-time power-up tip has been shown, and whether the first-visit tutorial has been shown. An unfinished run is not saved. “Clear local scores” removes those records. Records do not sync across devices. A copied challenge contains your score, mode, rounds cleared, rules version and, for daily runs, a UTC date. It contains no player name.

How analytics work

When product analytics are allowed, we also use Google Analytics, based in the United States, to measure visits and named product actions. It uses first-party browser and session cookies, processes connection information such as IP addresses to provide the service, and receives fixed page routes, approved campaign labels and the referring site hostname. We do not send form contents, uploaded files, email addresses or private workspace addresses. Advertising signals and personalization are disabled. The same regional consent, browser privacy signals and turn-off control apply to both analytics services; turning analytics off stops Google collection and removes its cookies. Google analytics event data is retained for up to 14 months. Anonymous totals are not sent to Google.

Outside the EU/EEA, UK and Switzerland, product analytics (PostHog, based in the United States) are on by default to help us improve the game; use the button above to turn them off at any time. Global Privacy Control and Do Not Track are honored automatically and always win, even if you allowed analytics earlier in this browser.

In the EU/EEA, UK and Switzerland, and wherever we cannot tell your location, we ask first with a small floating card in the corner of the screen that never blocks play. Without your permission we keep only anonymous daily totals (page visits, game starts, finishes and retries, all without a player ID) in Cloudflare D1 (EU jurisdiction). Those totals carry no browser ID, IP address, user agent or referrer, are kept for up to 90 days, and are never sent to PostHog. “Turn off analytics” above stops those too.

If analytics are on, PostHog receives a random browser ID and session ID, which board you are on (daily, free play or Honeycomb), and controlled milestones: starting a game (and whether its board came from a daily link, a shared board or neither), the game’s first drop, first pop and first chain, clearing a first round, which power-up you buy, leaving the page mid-run, finishing, starting over, entering full screen and choosing to copy a score. Scores, rounds cleared, moves taken, play time and active play time (time the page is on screen, with long pauses counted as a short fixed amount) are grouped into ranges. If analytics start while a game is already underway, that game is counted only from that moment; nothing from before is sent, including its score and rounds so far. A first game also carries which version of the first-time guide it had (the plain game, rings on helpful columns, or a practice drop), and a practice drop reports how it ended. A new, same-day or later-day return label helps us understand repeat play. Events include approximate country from the service edge when available, otherwise an explicit unknown; event IP is masked.

Only approved Dayplay Games, GitHub playtest and shared-score campaign labels are admitted. Original first-touch and current-tab labels stay separate. Coarse browser, operating-system and device types and an available referring site hostname help us understand discovery. No key presses, pointer paths, exact scores, arbitrary URLs, referrer paths, typed text or raw errors are sent. There is no session recording (replay is opt-in only and not currently offered), no device fingerprinting, no advertising and no sale of data. The purpose is product improvement only.

For Dayplay Games testing

Hosting and network providers receive the connection information needed to serve requests, including your IP address in their own logs; that is separate from the controls above, which mask IP in analytics events and disable analytics geolocation.

Change your choice

Use the button under “How analytics work” above. Turning analytics off clears the stored measurement ID, attribution, activation and return-day keys, stops new PostHog events, and stops anonymous daily totals from the next page load, including in any other open tab of this game. Previously delivered events and totals remain. Allowing analytics again creates a new ID. Your local scores and preferences are separate and stay intact either way.

Embedded play keeps no analytics at all.

If browser storage is blocked, choices and records last only on this page. Closing or reloading it loses them.

Questions

Write to hello@dayplaygames.com with a privacy question. Please avoid sensitive information. Updated October 1, 2026.