Security and privacy
Security
Allowed domains
This setting allows you to control which domains are permitted to embed your puzzles. By default, the field is left blank, which means there are no restrictions—any website can embed your puzzles. To limit embedding to specific domains, simply enter the allowed domain names in this field. This is useful if you want to restrict access to your content or ensure it only appears on authorized platforms.

To whitelist your own domains:
- Add both your top-level domain and any subdomains where the puzzles will be embedded. For example, if your main domain is
example.comand your site is served fromwww.example.com, you'll need to add bothexample.comandwww.example.comto the whitelist. - Enter multiple domains as space-separated values.
- To allow all subdomains of a domain, use the wildcard
*. For example, to whitelist all subdomains ofexample.com, use*.example.com
Series landing page
This setting controls whether solvers can access the puzzles or pickers directly in their browsers, outside of the iframe. By default, this setting is disabled, which means solvers can load the puzzles directly. To restrict access to iframe-only loading, enable this setting and provide the URL of your website's puzzle page. This URL will be used to verify that the puzzles are being accessed from the correct location.

If you do not set the Allowed Domains and Series Landing Page settings, any other rogue websites, content syndication portals and mobile apps will be able to embed your puzzles or link to/open them directly. All such loads will count against your game views limit and are billable. We strongly recommend enabling the Allowed Domains and Series Landing Page settings before you launch.
Privacy
These settings let you control how much data is collected and stored when people play your puzzles. They also help you meet privacy laws like GDPR and CCPA if your organization needs to follow strict privacy rules.
These two settings control different aspects of privacy and data storage:
- Don't allow cookies: Controls whether cookies are stored for user identification
- Save progress in browser: Controls whether puzzle progress is saved on players' devices
Most websites can use the default settings, but these options can be helpful for schools, healthcare sites, government organizations, or any environment where privacy is a priority.
Don't allow cookies
This setting prevents cookies from being stored while users play any puzzle in this series, for greater privacy. By default, this setting is disabled, which means cookies are allowed for user identification and tracking.
When to change this: Turn this on if you need maximum privacy or if you're running ad units and don't want to track users.
When enabled:
- No cookies are stored for user identification
- The Save button in the hamburger menu is hidden for users
Save progress in browser
This setting controls whether the browser stores puzzle progress locally. By default, this setting is enabled, which means players can return to puzzles later and continue where they left off. If disabled, progress will not be restored after a page refresh.
When to change this: Turn this off if you want players to start fresh each time (like in schools with shared computers).
When disabled:
- No puzzle progress is saved to the browser's local storage
- Players lose their progress if they refresh the page
These settings affect how your puzzles work and what data is saved. Changing them might mean players lose their progress or can't save their work. Make sure you understand what each setting does before changing it.
Recommended settings
Default Mode
- Don't allow cookies: Off
- Save progress in browser: On
Players can save their progress and return to puzzles later. Their progress is stored in both cookies and browser storage, so they can continue where they left off even after closing and reopening the browser.
Use cases: News sites, entertainment blogs, educational platforms
High Privacy Mode
- Don't allow cookies: On
- Save progress in browser: Off
Players get a completely fresh start each time they open a puzzle. No cookies are stored, and no progress is saved locally.
Use cases: Schools with shared computers, libraries, healthcare sites, government organizations, ad units, temporary campaigns