← Back to Game
Privacy Policy
Last Updated: January 9, 2026
Quick Summary: X's and O's is a free browser game that respects your privacy. We don't collect personal information, don't use analytics, don't show ads, and don't sell your data. We do log technical information (IP address, browser type, device platform) and perform basic browser fingerprinting solely for security, abuse prevention, and game functionality. All data is used only to operate the service and is never shared with third parties for advertising or tracking.
1. Introduction
Welcome to X's and O's ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website exesnohs.com and play our game.
By accessing or using X's and O's, you agree to this Privacy Policy. If you do not agree with this policy, please do not use our service.
2. Information We Collect
2.1 Information You Provide
When you use our platform, you may provide:
- Communications: Messages you send through forms or support channels (ex: email)
2.2 Automatically Collected Information
When you visit our website, we automatically collect certain technical information:
- IP Address: Your device's Internet Protocol address, which is logged and used for security monitoring, rate limiting, and abuse prevention
- Browser Information: Your complete User-Agent string, including browser type, version, and rendering engine
- Device Information: Your device platform and operating system (Windows, Mac, iOS, Android, Linux, etc.) extracted from the User-Agent
- Language Preferences: Your preferred language settings from browser headers
- Access Times: Timestamps of when you access our service
- Request Data: Technical information about your HTTP requests, including URLs accessed, request methods, and headers
- Screen Resolution: Your device's screen dimensions (if provided by your browser)
2.3 Browser Fingerprinting
We perform basic browser fingerprinting by collecting and analyzing:
- Browser name and version number
- Operating system and platform
- Screen resolution and color depth
- Timezone and language settings
- Installed fonts and plugins (where available)
This fingerprinting is used for:
- Preventing automated bots and abuse
- Ensuring proper game rendering and functionality
- Detecting suspicious activity and security threats
We do NOT use fingerprinting for: Cross-site tracking or advertising.
2.4 Server Logs
Our servers automatically log valid requests, including:
- IP addresses
- Timestamps of each request
- URLs and endpoints accessed
- HTTP methods (GET, POST, etc.)
- Response status codes (200, 404, 500, etc.)
- User-Agent strings
- Referrer information (if provided)
- Request and response sizes
These logs are retained for up to 30 days for security monitoring, debugging, and abuse prevention. Logs are stored securely and are not shared with third parties.
2.5 Game Data
If you play the game, we may temporarily store:
- Game scores and statistics
- Gameplay actions and choices
- File metadata if you interact with game features
2.6 Local Storage Data
We use browser localStorage (a client-side storage mechanism) to store information directly on your device, including:
- Game Preferences: Your gameplay settings, preferences, and configuration options
- Game Results: Your scores, achievements, and game history
- Progress Data: Information about your current game state and progress
Important details about localStorage:
- This data is stored locally on your device only and is not transmitted to our servers
- The data persists even after you close your browser (unless you clear your browser data)
- You can delete this data at any time through your browser settings (Clear browsing data → Cookies and site data)
- No personal information is stored in localStorage
- This data is not accessible to other websites
2.7 Information We Do NOT Collect
We want to be clear about what we don't collect:
- We do NOT require or collect personal information (name, email, phone number, etc.)
- We do NOT require account creation
- We do NOT track your activity across other websites
- We do NOT use analytics services (Google Analytics, etc.)
- We do NOT collect location data beyond what's inherent in your IP address
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve the game functionality
- Game Experience: To save your preferences, scores, and game progress using localStorage
- Security: To protect against fraud, abuse, and security threats
- Rate Limiting: To prevent spam and denial-of-service attacks (limited to 1,000 requests per IP per 5 minutes)
- Technical Operations: To monitor and analyze technical performance
- Legal Compliance: To comply with applicable laws and regulations
4. Data Storage and Retention
4.1 Storage Location
Your data is stored on our secure servers. We implement appropriate technical and organizational security measures including:
- HTTPS encryption for all data transmission
- HTTP Strict Transport Security (HSTS)
- Content Security Policy (CSP) headers
- Secure session management
- Input validation and sanitization
- Protection against common web vulnerabilities (XSS, SQL injection, etc.)
4.2 Retention Period
- Session Data: Deleted when your session expires or you close your browser
- Logs and Technical Data: Retained for up to 30 days for security and debugging purposes
- Game Data: Retained only during active gameplay sessions
- localStorage Data: Persists on your device indefinitely until you manually clear it through your browser settings
5. Cookies and Tracking Technologies
5.1 Cookies
This site does not use cookies. The site uses basic browser fingerprinting techniques for:
- Client IDs: Used to identify your browser session anonymously
5.2 localStorage
We sometimes use browser localStorage to store game-related data on your device:
- Game Preferences: Your settings and configuration choices
- Game Results: Your scores and achievements
- Progress Data: Your current game state
Unlike cookies, localStorage data is never sent to our servers automatically. It remains on your device and can only be accessed by our website.
5.3 What We Do NOT Use
- Third-party tracking cookies
- Advertising cookies
- Analytics cookies
- Cross-site tracking technologies
You can have your browser clear localStorage, but this may cause you to lose your game preferences and progress.
6. Third-Party Services
We do NOT share your data with third parties for advertising or analytics purposes.
The only third-party involvement is:
- Hosting Provider: Our servers are hosted by a third-party infrastructure provider bound by strict confidentiality agreements
- SSL/TLS Certificates: We use certificate authorities to provide secure HTTPS connections
7. Your Rights and Choices
Depending on your location, you may have certain rights regarding your data:
- Access: Request information about data we have collected
- Deletion: Request deletion of your data (note: since we don't collect personal information, there is minimal data to delete)
- Clear localStorage: Delete your locally stored game preferences, scores, and progress at any time through your browser settings:
- Chrome/Edge: Settings → Privacy and security → Clear browsing data → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
- Safari: Preferences → Privacy → Manage Website Data → Remove for exesnohs.com
- Opt-Out: Stop using the service at any time
- Do Not Track: Our service doesn't track users, so Do Not Track signals are already honored
8. Children's Privacy
Our service is available to users of all ages. We do not knowingly collect personal information from children under 13. Since our game doesn't require registration or collect personal information, it is safe for children to use under parental supervision.
If you believe we have inadvertently collected personal information from a child, please contact us immediately.
9. International Data Transfers
Our servers may be located in different countries. By using our service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
10. Security
We take security seriously and implement industry-standard measures:
- HTTPS/TLS encryption for all communications
- Regular security audits and updates
- Input validation and sanitization
- Protection against common attacks (XSS, CSRF, SQL injection, path traversal, etc.)
- Rate limiting and abuse prevention
- Secure session management with Redis
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of the service after changes constitutes acceptance of the updated policy.
For significant changes, we may provide additional notice on our website.
12. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), our legal basis for collecting and using your information depends on the data and context:
- Legitimate Interests: We process technical data for security, fraud prevention, and service improvement
- Consent: By using our service, you consent to our use of cookies and data collection as described
- Legal Obligations: We may process data to comply with legal requirements
13. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed (we do NOT sell or disclose)
- Right to request deletion of personal information
- Right to opt-out of sale of personal information (not applicable as we don't sell data)
- Right to non-discrimination for exercising privacy rights
14. Contact
15. Consent
By using X's and O's, you hereby consent to this Privacy Policy and agree to its terms.